BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures
Detectify has unveiled the Detectify MCP (Model Context Protocol) Server, a new integration layer that brings Detectify’s security testing engines directly into AI-driven development workflows, helping coding agents find and validate exploitable vulnerabilities and interpret attack surface data with...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in bypass of access checks, overwrite of files in unintended situations using the WORM vfs module, installing CA certificates over http without verification when auto-enrollme...
A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro’s Apex One platform has been exploited in zero-day attacks, the company confirmed. “TrendAI has observed at least one attempt to exploit this vulnerability in the wild,” Trend Micro noted, and credited the incident res...
Conifers has announced the launch of its agentic SOC, a unified AI platform designed to help security operations centers defend against cyber adversaries operating at machine speed. Built on the company’s CognitiveSOC platform, the new system connects threat intelligence, threat hunting, detection e...
Asim Viladi Oglu Manizada discovered that Samba incorrectly handled access
checks on reparse point operations. An attacker could possibly use this
issue to modify reparse point extended attributes on files that should have
been read-only. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.
(...
Nimbus Manticore has continued its operations during and after the US military campaign against Iran.
The post Iranian APT Targets Aviation, Software Companies With Updated Tools appeared first on SecurityWeek.
Sur LinkedIn, de nouvelles mesures de détection ont été déployées pour limiter la visibilité des publications générées par IA. Voici ce que ça va changer.
Le post AI Slop : LinkedIn part à la chasse aux contenus IA a été publié sur IT-Connect.
We found fake installers and plugins for ChatGPT, Claude, AutoTune, and other popular software that can give attackers full control over your device.
The data breach included names, dates-of-birth, postal addresses, and Social Security numbers, according to a state government listing.
Le FBI a émis une alerte de sécurité concernant Kali365, une plateforme de PhaaS utilisée pour compromettre des comptes Microsoft 365 sans voler d'identifiants.
Le post Microsoft 365 : le kit de phishing Kali365 pirate les comptes sans voler les mots de passe a été publié sur IT-Connect.
The principle of least privilege is a security approach that can protect your SMB — get a free guide to implementing it
Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network. [...]
IT teams often need to jump between monitoring dashboards, infrastructure tools, ticketing systems, and communication platforms during network incidents. This webinar explores how automation and AI-assisted workflows can help reduce manual coordination and improve incident response times. [...]
Reform UK leader alleges Moscow hacked his phone and leaked ÂŁ5M gift story, but security specialists await evidence
The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth.
The post 185,000 Likely Impacted by 7-Eleven Data Breach appeared first on SecurityWeek.
Every single day, hackers are finding new ways to crash websites and steal data.
But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop.
According to r...
Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met.
The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned...
Data belonging to about 185,000 people was exposed following a cyberattack on convenience store chain 7-Eleven that was later claimed by the ShinyHunters extortion gang, according to Have I Been Pwned. The exposed information includes email addresses, names, physical addresses, dates of birth, and p...
Suite à l’installation de la mise à jour KB5087537 sur Windows Server 2016, la recherche et la découverte des contrôleurs de domaine AD peuvent échouer.
Le post Un bug surprenant affecte Windows Server 2016 suite aux correctifs de mai 2026 a été publié sur IT-Connect.