[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Instagram Account Hijacks Expose the Security Risks of AI-Powered Support
Attackers exploited Meta’s AI support chatbot to reset Instagram passwords and hijack accounts without accessing victims’ email inboxes. Attackers abused Meta’s AI-powered support chatbot to reset Instagram passwords and hijack accounts without accessing victims’ email inboxes. The issue affected se...
> USN-8372-1: age vulnerability
It was discovered that age did not properly validate plugin names. An attacker could possibly use this issue to cause execution of an arbitrary program by supplying a crafted recipient or identity string.
> Russia claims foreign spy agencies hacked officials' phones
In a statement, Russia's Federal Security Service (FSB) said it had uncovered what it described as a "large-scale operation" involving malicious software installed on the mobile devices of senior Russian officials.
> Android : le patch de juin 2026 corrige une faille zero-day déjà exploitée
Les patchs de sécurité de juin 2026 pour Android corrigent 124 vulnérabilités, dont une faille de sécurité zero-day patchée par Google (CVE-2025-48595). Le post Android : le patch de juin 2026 corrige une faille zero-day déjà exploitée a été publié sur IT-Connect.
> Ubuntu 26.04 Luanti Important Code Execution Issues USN 8366-1
Several security issues were fixed in Luanti.
> Ubuntu 22.04 Tar-FS Important Security Flaws USN-8367-1
Several security issues were fixed in tar-fs.
> Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies
Software as a service (SaaS) providers building AI-powered applications on Amazon Bedrock AgentCore often need to serve multiple tenants with distinct security requirements from a shared infrastructure. Some tenants require cross-account access from their own Amazon Web Services (AWS) accounts, whil...
> Ubuntu 22.04 libeconf Critical Denial of Service Vulnerability USN-8368-1
libeconf could be made to crash if it received specially crafted input.
> Ubuntu 24 22 20 18 16 libapache-mod-jk Important DoS Vuln 8369-1
Apache Tomcat Connectors could allow local users to expose sensitive information or cause a denial of service.
> Instagram users locked out after Meta AI abused to steal accounts
Multiple Instagram users had their accounts hijacked after attackers convinced Meta's AI-powered support tools that they were the legitimate owners. [...]
> Password manager Dashlane says hackers stole some customers’ password vaults
The password manager giant said hackers were able to 'brute-force' its two-factor system, allowing them to access customer accounts and download their password vaults.
> Infosecurity Europe: NCSC Urges Immediate Action to Boost Resilience as Uncertainty Persists
NCSC director of operations, Paul Chichester, says it’s time to future-proof cybersecurity today
> ESET Security for Microsoft SharePoint Server version 13.0.15003.0 has been released
ESET Security for Microsoft SharePoint Server version 13.0.15003.0 has been released
> U.S. CISA adds Oracle WebLogic flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle WebLogic flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Palo Alto Networks PAN-OS flaw, tracked as CVE-2024-21182 (CVSS score of 7.5), to its Known Ex...
> Ubuntu 24.04 Apache Commons Lang Critical DoS USN-8364-1
Apache Commons Lang could be made to crash if it received specially crafted input.
> Ubuntu 25.10 Kernel Critical Privilege Escalation USN-8374-1
Several security issues were fixed in the Linux kernel.
> Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations. The post Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk appeared first on SecurityWeek...
> Infosecurity Europe: Cybersecurity Teams Which Don’t Leverage AI are "Doomed to Fail"
Humans still need to be part of cyber defense, but refusing to deploy AI is no longer optional against AI-enhanced cyber threats, warns Dataminr’s Joe Slowik
> Test ZimaCube 2 : un NAS tout-en-un pour votre Cloud personnel
Découvrez le ZimaCube 2, un boîtier tout-en-un performant pour self-hoster et créer votre cloud personnel, avec l'installation d'applications en 1-clic. Le post Test ZimaCube 2 : un NAS tout-en-un pour votre Cloud personnel a été publié sur IT-Connect.
> USN-8371-1: Linux kernel vulnerabilities
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could...