USN-8282-1 fixed vulnerabilities in Unbound. This update provides the
corresponding updates for CVE-2026-41292 in Ubuntu 18.04 LTS and Ubuntu
20.04 LTS and CVE-2026-42959, CVE-2026-42960 in Ubuntu 14.04 LTS, Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
Andr...
Scammers use fake takedown requests, countdown timers, and spoofed sign-in screens to steal Google logins from Chrome developers.
The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation.
Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, t...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows...
Le tribunal administratif d'Helsinki a annulé l'amende administrative de 1 100 000 € imposée à la Pharmacie Universitaire en raison de l'incertitude juridique concernant sa capacité à être sanctionnée en tant qu'entité publique.Par une décision du 1er juin 2026, le tribunal a invalidé la sanction pé...
It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)
It was discovered that the Linux kernel did...
Available for Android 12 and later, the anti-scam feature is baked into Google Dialer, which sends a silent “confirmation signal” to ensure whoever’s calling you is who they appear to be.
L'Autorité Nationale de Surveillance du Traitement des Données à Caractère Personnel (ANSPDCP) a publié une décision de sanction à l'encontre d'Unicredit Bank SA (comprenant le prononcé d'une amende de 62 714 lei, soit l'équivalent de 12 000 €) pour des manquements en lien avec la sécurité du traite...
L'autorité italienne de protection des données (GPDP) a publié une décision de sanction à l'encontre de l'Autorité sanitaire locale de Matera, comprenant le prononcé d'une amende de 8 600 €, pour des manquements en lien avec la sécurité des données personnelles suite à une cyberattaque par rançongic...
Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3.
Discover how Microsoft enables fast, secure AI development with MDASH and new security capabilities.
The post Microsoft Build 2026: Securing code, agents, and models across the development lifecycle appeared first on Microsoft Security Blog.
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could...
Top Pentagon cyber policy official Katherine Sutton said recent conflicts have emphasized the importance of cyber, and that the department can’t make old mistakes with AI security.
The post DOD wants to integrate cyber in all operations, and integrate security into AI appeared first on CyberScoop.
Microsoft is working to address a widespread service issue affecting the mail flow pipeline for Exchange Online customers across North America and Germany. [...]
EditorConfig could be made to crash if it opened a specially crafted file.
age could be made to crash or run programs as your login if it opened a specially crafted file.
The order – which Trump refrained from signing at the last minute, appears to make significant concessions to industry compared to earlier drafts.
The post Trump administration releases scaled-back AI executive order appeared first on CyberScoop.
EFF is on the front lines of the fight against tech-enabled tyranny, but we aren't alone. Our team depends on your help to fight back against the surveillance state.
JOIN EFF
People around the world are pushing back against the mass surveillance that undermines privacy and free expression for everyo...
On May 13th, 2026, we publicly disclosed a critical Authentication Bypass vulnerability in Burst Statistics, a WordPress plugin with 200,000 active installations. This vulnerability can be leveraged by unauthenticated attackers, with knowledge of an administrator username, to impersonate that admini...
As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control.
The post Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis appeared first on SecurityWeek.