[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> USN-8310-1: Linux kernel (Azure) vulnerabilities
It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in t...
> USN-8309-1: libssh2 vulnerability
It was discovered that libssh2 incorrectly handled username and password length values during SSH password authentication. A remote attacker could possibly use this issue to cause a denial of service.
> MyPillow must decide whether to be firm or soft as ransomware crims demand pay
Guess they could deny the alleged intrusion … like the 2020 election results
> USN-8167-2: xdg-dbus-proxy vulnerability
USN-8167-1 fixed a vulnerability in xdg-dbus-proxy. This update provides the corresponding update for Ubuntu 20.04 LTS. Original advisory details: It was discovered that xdg-dbus-proxy incorrectly handled eavesdropping in policy rules. A local attacker could possibly use this issue to intercept...
> USN-8308-1: Dnsmasq vulnerability
It was discovered that Dnsmasq incorrectly handled BOOTREPLY packets when configured with the --dhcp-split-relay option. A remote attacker could use this issue to cause Dnsmasq to crash, resulting in a denial of service, or possibly execute arbitrary code.
> What is TOTP? Everything you need to know about time-based one-time passwords
TOTP generates secure 2FA codes that expire in seconds. Learn about how it works and its benefits over other 2FA methods.
> The Hidden Ransomware Economy Running on Exposed Databases
A 5-year study on the Ransomware Economy found that 30,515 exposed databases were hit by ransom attacks, causing massive damage despite victims never paying. Database extortion doesn’t look like the ransomware stories that usually grab headlines. There’s no slick branding, no leak-site countdown, no...
> USN-8307-1: ONNX vulnerability
It was discovered that ONNX did not properly validate paths when extracting tar archives during model downloads. An attacker could possibly use this issue to overwrite arbitrary files on the system.
> Internet Starts to Return in Iran After 3-Month Blackout
Some internet connectivity is returning in Iran after nearly 90 days offline, web monitoring groups say. But it isn’t clear if the reconnection is permanent.
> What is HOTP? A guide to HMAC-based one-time passwords
Learn what an HMAC-based one-time password (HOTP) is, how it works, and how it differs from other OTP authentication methods.
> Well-architected best practices for software supply chain security
There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Inspector team, the Open Source Security Foundation, and others, the affected packag...
> Datatilsynet - autorité norvégienne
Les autorités de protection des données des pays nordiques ont publié une déclaration commune suite à leur réunion annuelle des 21 et 22 mai 2026 à Stockholm, définissant leurs axes de coopération prioritaires.Les discussions ont été marquées par le contexte géopolitique et l'émergence de nouveaux r...
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) a publié une mise à jour des méthodologies de référence MR-001 et MR-003, adaptant le cadre des recherches en santé aux évolutions du secteur.Cette révision, datée du 26 mai 2026, vise à simplifier les démarches pour les acteurs public...
> FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required
So, you've enabled multi-factor authentication. You've taught your staff never to type their passwords into dodgy-looking login pages. Surely your Microsoft 365 accounts are safe now? Well, think again. Read more in my article on the Hot for Security blog.
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre d'un vidéaste, comprenant le prononcé d'une amende de 500 €, pour l'utilisation de l'image d'une personne dans une vidéo publiée en ligne sans base légale. Cette affaire débute par une plainte déposée...
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre d'AMADEUS IT GROUP, S.A. (comprenant le prononcé d'une amende de 14 400 000 €) pour des manquements en lien avec l'information des personnes concernées et la base juridique d'un traitement de données à...
> Slackware 15.0 Mozilla-Thunderbird Important Security Fix 2026-146-01
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
> NAIH - autorité hongroise
L'Autorité nationale hongroise de la protection des données et de la liberté d'information (NAIH) a publié une décision de sanction à l'encontre de Mediaworks Hungary Zrt., comprenant le prononcé d'une amende de 50 000 000 forints (environ 127 000 €), pour des manquements en lien avec la publication...
> Ubuntu 26.04 LTS Samba Critical Update Denial of Service USN-8306-1
Several security issues were fixed in Samba.
> WinGet : gérer vos applications en ligne de commande sous Windows
Avec ce tutoriel, apprenez à utiliser WinGet sur Windows pour installer, désinstaller, mettre à jour et gérer les applications directement en ligne de commande. Le post WinGet : gérer vos applications en ligne de commande sous Windows a été publié sur IT-Connect.