> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several significant threats. A security researcher has identified a KVM guest-host escape flaw in Firecracker MicroVMs, potentially impacting AWS environments. Dell has released patches for 18 critical vulnerabilities in its Container Storage Modules (CSM), which could allow attackers to gain unauthorized access to storage and Kubernetes systems. Additionally, the hacking group ShinyHunters has exploited a zero-day vulnerability in PeopleSoft, raising alarms about increased risks for enterprises using the Oracle software. Organizations are advised to implement stringent security measures in response to these emerging threats.
|
// AI-powered summary generated at 04:00
De multiples vulnérabilités ont été découvertes dans GLPI. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
Une vulnérabilité a été découverte dans les produits Ivanti. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
GitHub Actions workflows are vulnerable to pwn requests, script injection, and compromised credentials. Here's what's going wrong and what's changing.
Une vulnérabilité a été découverte dans Apache Kafka. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Le Vieux Campeur a été victime d'une cyberattaque d'ampleur le 2 juin 2026, mais ses équipes techniques, épaulées par des experts en cyberdéfense, ont immédiatement mis en œuvre des mesures de confinement et de sécurisation pour en limiter l'impact et rétablir ses services. L'incident a été déclaré...
A couple of weeks ago, I wrote about Copy-Fail (CVE-2026-31431) and how Red Hat OpenShift’s defense-in-depth approach prevented container escape despite a vulnerable kernel. I spent time actively trying to break out of an OpenShift container, achieved root inside the pod almost immediately, and stil...
Police described the incident as a large-scale disclosure of sensitive personal information that posed a threat to both the affected individuals and the institutions they serve. The data was allegedly posted on multiple internet platforms.
The escalated threat posed by the defect showcases how quickly a seemingly mild vulnerability can turn into an urgent warning.
The post Attackers are exploiting Palo Alto Networks defect that initially flew under the radar appeared first on CyberScoop.
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites. [...]
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystem:
- Packet sockets;
(CVE-2026-31504)
TeamPCP? Or copycat malware dev?
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma." [...]
The Spanish National Police has arrested an individual for leaking sensitive information related to members of various key state organizations, including the National Cybersecurity Institute (INCIBE). [...]
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.
NIST’s National Vulnerability Database (NVD) backlog mushroomed from 13,000 unprocessed security vulnerabilities in February 2024 to more than 27,000 by the end of 2025, “undermining the NVD’s utility and public trust," according to an inspector general report.
New kernel packages are available for Slackware 15.0 and -current to fix security issues.
The system could be compromised under certain conditions.
The former Colorado election clerk struck an unrepentant pose in her first interview after her prison sentence was commuted by Colorado Governor Jared Polis.
The post Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight appeared first on CyberScoop.
Hacking voting machines is so 2017. Phishing, impersonation pose the real election risks