[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de TELCOM BUSINESS SOLUTIONS S.L. (comprenant le prononcé d'une amende de 25 000 €) pour des manquements en lien avec l'utilisation de données biométriques pour la vérification d'identité et l'absence...
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a publié une décision de sanction à l'encontre de l'entreprise individuelle Sicra Press, comprenant le prononcé d'une amende de 2 000 €, pour des manquements en lien avec la gestion des demandes d'exercice de droits et le défaut de coopération av...
> CISA warns of active attacks exploiting Android, Linux bugs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. [...]
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a publié une décision de sanction à l'encontre de la municipalité de Cogoleto, comprenant le prononcé d'une amende de 4 000 €, pour des manquements liés à l'utilisation de caméras-piétons par sa police locale. Cette affaire débute par un signalem...
> Digital Forensics Round-Up, June 03 2026
Read the latest DFIR news – DFIR well-being study results, agentic AI forensic blind spots, the latest ADF tools, deepfake image analysis workflows, and more.
> Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on the same phone could ask for the signed-in user's token and get it, then read email, open files, browse the...
> Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
Researchers follow in Nightmare Eclipse’s footsteps, flipping off Redmond in favor of insta-leaks
> Microsoft responds to security challenges facing code, AI agents, and models
Microsoft has introduced a series of security tools and capabilities focused on AI-driven vulnerability discovery, AI agents, and AI models. The updates include a multi-agent vulnerability discovery system, new controls for managing and securing AI agents, data protection capabilities, and tools des...
> The worst hacks and breaches of 2026 (so far)
From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026.
> What 345 Days of Untested Exposure Looks Like at a Bank
A two-week penetration test can leave roughly 345 days of real-world exposure unvalidated. Sprocket Security explores why continuous testing is becoming critical as attack surfaces constantly change. [...]
> USN-8380-1: Twisted vulnerability
It was discovered that Twisted incorrectly handled DNS name decompression. A remote attacker could possibly use this issue to cause Twisted to consume excessive resources, leading to a denial of service.
> USN-8379-1: urllib3 vulnerabilities
It was discovered that urllib3 incorrectly handled cross-origin redirects in ProxyManager. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-44431) It was discovered that urllib3 incorrectly handled decompression of specially crafted responses. A remote atta...
> Russia’s FSB Says Foreign Spies Infected Officials’ Phones With Malware
Russia’s FSB claims foreign intelligence planted malware on senior officials’ phones to intercept calls and activate cameras. No technical evidence, no country named. On June 2, 2026, Russia’s Federal Security Service (FSB) published a statement claiming it had uncovered and documented a large-scale...
> Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases. Tracked as CVE-2026-23479, the flaw was introduced in Red...
> Continuing Scans for swagger.json, (Wed, Jun 3rd)
Enterprise applications often still use complex standards like SOAP for web services. The big advantage of SOAP is its tight and extensive standards, which enable interoperability across an enterprise governed by web services. The disadvantage of SOAP: First, while it is de facto usually used over H...
> USN-8378-1: libwww-perl vulnerability
It was discovered that libwww-perl incorrectly handled redirects. A remote attacker could possibly use this issue to obtain sensitive information by causing Authorization headers to be sent to a different host.
> Infosecurity Europe: Vulnerability Management Innovator Konvu Wins Cyber Startup Award
Inaugural Infosecurity Europe Cyber Startup Award Winner Impresses Panel with Ability Help Prioritize Vulnerabilities in AI era
> Ubuntu 20.04 LTS nginx Security Advisory for Critical DoS Vulnerabilities
Several security issues were fixed in nginx.
> Ubuntu 20.04 LTS MySQL Important Security Issues USN-8363-2
Several security issues were fixed in MySQL.
> Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, because official project sites tend to rank highest and appear near the top of the results. After landing on...