> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several critical vulnerabilities and emerging threats. Dell has addressed multiple serious flaws in its PowerEdge servers, particularly a critical vulnerability (CVE-2026-86360) that allows for root access, urging customers to apply patches immediately. Similarly, a major flaw in Atlassian's Data Center products permits unauthenticated attackers to access sensitive files, requiring immediate user action. Additionally, Denmark reported a significant data breach exposing personal information of 8.8 million individuals. The ClingSTUN Linux backdoor is also a concern, exploiting IoT devices through public STUN servers. Lastly, new ClickFix attacks are leveraging browser cache to execute malicious payloads, indicating a shift in attack vectors. Organizations are advised to bolster their security measures in light of these threats.
|
// AI-powered summary generated at 08:01
Une vulnérabilité a été découverte dans Laravel. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans les produits NetApp. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
La société D&M, filiale de REXT Holdings (groupe RIZAP), a été victime d'une cyberattaque par ransomware via un accès non autorisé à travers un appareil VPN. L'attaque a infecté un serveur de partage de fichiers contenant des données FAX sous forme PDF, potentiellement exposant les informations pers...
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Une vulnérabilité a été découverte dans Microsoft Azure. Elle permet à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
La municipalité d'Adelmannsfelden a été victime d'une cyberattaque qui a paralysé l'administration pendant plusieurs semaines. L'attaque, survenue au début du mois de juin, a nécessité une intervention rapide de la municipalité, des prestataires informatiques et de l'agence de cybersécurité du Bade-...
Une vulnérabilité a été découverte dans Keycloak. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans les produits Mitel. Elles permettent à un attaquant de provoquer une élévation de privilèges.
A suspected Pakistan-linked hacking group has targeted Afghanistan's Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found.
Une vulnérabilité a été découverte dans Kaspersky Anti Targeted Attack Platform. Elle permet à un attaquant de provoquer un déni de service à distance.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
More than half of the attacks observed over the past year targeted educational institutions, particularly maritime universities and schools that train personnel for Russia's shipping, inland waterway and fishing industries.
Two security vulnerabilities have been discovered in Cyborg, the OpenStack component for management of hardware accelerators, which could result in incomplete access controls. For the stable distribution (trixie), these problems have been fixed in version 14.0.0-3+deb13u1.
Alistair Coles discovered that the s3api middleware of Swift, a distributed virtual object store, was susceptible to denial of service. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 2.35.1-0+deb13u2.
L'autorité allemande de protection des données (BfDI) a annoncé qu'elle sera compétente pour superviser l'application de la loi sur les données (Data Act) concernant les données à caractère personnel.Cette nouvelle compétence, qui entrera en vigueur le 30 mai 2026 avec la loi allemande sur l'applica...
Multiple vulnerabilities have been discovered in the Dovecot IMAP server which way result in denial of service, SQL injection or man-in-the-midddle attacks For the oldstable distribution (bookworm), these problems have been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u6.
CVE-2026-0257 lets attackers forge Palo Alto GlobalProtect auth cookies and bypass VPN login. Exploitation confirmed since May 17. Palo Alto Networks addressed the vulnerability CVE-2026-0257 on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer...
YARA-X&#;x26;#;39;s 1.17.0 release brings 5 improvements (several performance improvements) and 1 bugfix.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks  TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hund...
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. ShinyHunters Leaks Charter Communications Data, P...