[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly poison its long-term mem...
> New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds. [...]
> DHS chief signals efforts to reshape CISA
In his first appearance before the panel since being confirmed in March, Mullin said that CISA probably needs “somewhere around” 2,800 employees, despite its ability to hire up to 3,400.
> xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity
Four people suing Elon Musk's AI firm under pseudonyms due to the risks of being identified may face a difficult choice: Reveal your real names, or drop the lawsuit.
> Ubuntu 26.04 LTS python-pip Moderate DoS Regression Fix USN-8344-3
A regression was fixed in pip.
> Cyber espionage campaign targeted stock exchange executive’s Outlook account
Attackers spent five months silently stealing emails from a stock exchange executive’s Outlook account in a suspected espionage operation. A threat actor quietly sat inside a senior executive’s Outlook account at a major global stock exchange for roughly 150 days, from October 2025 to March 2026. Br...
> We found this fake-invoice campaign while scammers were still building it
Invoices pretending to be from Amazon, PayPal, and others reveal how criminals use fear and phone calls to steal money and devices.
> Coralogix Raises $200M at $1.6B Valuation to Scale AI Observability Platform
Coralogix offers a full-stack observability platform that unifies logs, metrics, traces, security, and AI observability. The post Coralogix Raises $200M at $1.6B Valuation to Scale AI Observability Platform appeared first on SecurityWeek.
> Ubuntu 20.04 LTS GStreamer Base Significant DoS Attack Vulnerability Alert
GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file.
> Ultrahuman says hackers accessed customers’ wellness data via internal tool
The breach at wearable ring maker Ultrahuman stemmed from credentials stolen from a malware-infected employee laptop.
> Enforcing the First AS in BGP AS_PATHs
BGP is vulnerable to routing hijacks and path leaks that negatively impact traffic on the Internet. RPKI helps solve some of these problems, but for some forged paths, we need to rely on a simpler mechanism: First AS enforcement in BGP.
> Attackers Actively Exploiting Critical Vulnerability in Everest Forms Pro Plugin
On March 30th, 2026, we publicly disclosed a critical Remote Code Execution vulnerability in Everest Forms Pro, a WordPress plugin with an estimated 4,000 active installations. The post Attackers Actively Exploiting Critical Vulnerability in Everest Forms Pro Plugin appeared first on Wordfence.
> Knowledge Base Digest - May 2026
Known Issues FQDN policies do not work after a Firebox reboot Unable to create a new external interface VLAN configuration from the local Web UI of a cloud-managed Firebox Cannot remove groups with long names from AuthPoint group syncs Cannot remove groups with long names from Zero Trust policies F...
> USN-8382-1: Exim vulnerabilities
Timo Longin discovered that Exim incorrectly handled certain SMTP messages in PIPELINING/CHUNKING configurations. A remote attacker could possibly use this issue to perform SMTP smuggling. This issue only affected Ubuntu 14.04 LTS. (CVE-2023-51766) It was discovered that Exim incorrectly handled ce...
> Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT. "Before the victim ever reaches attacker-controlled infrastructure, the lure routes through...
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a adressé une demande d'informations au Centre National des Œuvres Salésiennes pour l'École concernant l'emploi de l'intelligence artificielle dans un cadre éducatif.Cette demande fait suite à des articles de presse rapportant le lancement par ce...
> AP - autorité néerlandaise
L'Autorité de protection des données néerlandaise (AP) a approuvé un protocole autorisant les entreprises du secteur du transport et de la logistique à partager des données concernant des chauffeurs impliqués dans des vols de cargaison.Face aux préjudices économiques importants causés par des vols d...
> Instagram is alerting users who were targeted by hackers during AI chatbot attacks
Hackers appeared to take over victims’ accounts even after Meta said it fixed its AI-powered support chatbot, which granted hackers access to victims’ accounts.
> AEPD - autorité espagnole
L'Agence espagnole de protection des données (AEPD) a publié une décision de sanction à l'encontre de DINOLIN, S.A. comprenant le prononcé d'une amende de 450 € pour des manquements en lien avec le non-respect d'une de ses décisions. Cette affaire débute par une plainte signalant le non-respect par...
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de TELCOM BUSINESS SOLUTIONS S.L. (comprenant le prononcé d'une amende de 25 000 €) pour des manquements en lien avec l'utilisation de données biométriques pour la vérification d'identité et l'absence...