[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (22 articles)

|

// AI-powered summary generated at 08:01

> Cybersecurity trends in SEC filings
In 2023, the Securities and Exchange Commission (SEC) required public companies to include a new section in their 10-K annual filings that is devoted to cybersecurity. This section is meant to address “cybersecurity risk management, strategy, governance and incidents.” I got c...
> The Gentlemen are coming for your files, and then your network
Ransomware operators have spent years refining the art of locking files. Now, some are working harder to get those lockers to every reachable system first. Microsoft’s recent warning of the Gentlemen ransomware revealed its operators using a self-propagating Go-based encryp...
> Chinese Hackers Exploit Iran War to Target Maritime and Energy Companies
ESET’s 2026 APT Activity Report suggests China-backed APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globe
> Charter Communications data breach affects 4.9 million accounts
The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned. [...]
> BTMOB RAT Gives Criminals a Point-and-Click Kit to Take Over Your Android Phone
BTMOB sells Android full-device takeover as a kit, no coding needed. It steals data, records screens, and hands attackers remote control for $5,000 lifetime. Most Android malware requires at least some technical competence to deploy, but the BTMOB doesn’t. The developers sell it with a built-in APK...
> AI-Generated npm Malware Leaks Its Own GitHub Token
Sloppy AI-generated npm infostealer leaked its own GitHub token, exposing the operator
> CVE-2026-46193 xfrm: ah: account for ESN high bits in async callbacks
Information published.
> CVE-2026-46174 x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache
Information published.
> Police arrest man following hack of Ajax football club
Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot for Security blog.
> CVE-2026-46184 sound: ua101: fix division by zero at probe
Information published.
> CVE-2026-46121 mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock
Information published.
> CVE-2026-46142 net: libwx: fix VF illegal register access
Information published.
> CVE-2026-46124 isofs: validate block number from NFS file handle in isofs_export_iget
Information published.
> CVE-2026-46106 eventfs: Hold eventfs_mutex and SRCU when remount walks events
Information published.
> CVE-2026-46181 RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()
Information published.
> CVE-2026-46178 RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()
Information published.
> CVE-2026-46144 RDMA/mana: Fix error unwind in mana_ib_create_qp_rss()
Information published.
> CVE-2026-46169 hfsplus: fix uninit-value by validating catalog record size
Information published.
> CVE-2026-46119 libceph: Fix slab-out-of-bounds access in auth message processing
Information published.
> CVE-2026-46130 dm-verity-fec: fix reading parity bytes split across blocks (take 3)
Information published.