[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). [...]
> AI security needs a shift from models to systems, researchers argue
Enterprises cannot secure AI agents by making the underlying models more robust and must instead enforce security controls at the system level around them, researchers behind a paper published this month argued, warning that traditional AI-security approaches are increasingly...
> Advanced SQLite Queries: Free On-Demand Course From Belkasoft
Register for Belkasoft’s free on-demand SQLite training course to build practical DFIR database analysis skills, validate tool extractions, and earn 6 CPE credits.
> Oncology Institute Discloses Data Breach
The affected third-party vendor has not been named, but one possible candidate is TriZetto. The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek.
> Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Gh...
> CNDP - autorité marocaine
La Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP) marocaine et la Commission de Protection des Données du Nigéria (NDPC) ont signé un mémorandum d'entente pour promouvoir la coopération bilatérale.L'accord, signé le 22 mai 2026 à Abidjan par les dirigeants...
> UOOU - autorité tchèque
L'ancienne présidente de l'autorité tchèque de protection des données (ÚOOÚ) revient, dans une entrevue, sur les moments clés de son mandat exercé entre 2015 et 2020 et sur les défis actuels et futurs en matière de protection des données.L'ancienne présidente évoque une sanction de 3 600 000 CZK (en...
> As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free
As AI coding assistants accelerate software development, one OWASP-backed open-source project is arguing that dependency security tooling still arrives too late to be truly useful. CVE Lite CLI, a JavaScript and TypeScript dependency vulnerability scanner focused on local l...
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. (comprenant le prononcé d'une amende de 150 000 €) pour des manquements en lien avec la sécurité des données personnelles. Cette affaire débute par la notifi...
> AEPD - autorité espagnole
L'Agence espagnole de protection des données (AEPD) a publié une décision déclarant une infraction à l'encontre la Mairie de Madrid pour des manquements en lien avec la gestion de deux violations de données. Cette affaire débute par la notification de ces deux violations par l'entité elle-même, caus...
> US states step up cyber defenses to protect local communities
U.S. state governments are taking on a larger role in cybersecurity to help protect local communities and essential services. Many states are building state-led cyber defense programs, including cybersecurity clinics, regional security operations centers (RSOCs), and state cyber corps programs to re...
> ANSPDCP - autorité roumaine
L'Autorité nationale de surveillance du traitement des données à caractère personnel de Roumanie (ANSPDCP) a publié un bilan de ses activités pour les quatre premiers mois de 2026, accompagné d'une synthèse de jurisprudences récentes confirmant ses décisions de sanction.De janvier à avril 2026, l'au...
> AZOP - autorité croate
L'Agence croate pour la protection des données personnelles (AZOP) dresse un bilan de huit années d'application du RGPD, soulignant ses actions de contrôle et d'accompagnement.L'autorité constate une hausse de plus de 50 % des plaintes l'année dernière, principalement liées à la difficulté pour les...
> The Alert Firehose Finally Meets Its Match
Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually using it to catch threats earlier, triage faster, and chase fewer false positives...
> 266,000 Affected by Data Breach at Radiology Associates of Richmond
Threat actors stole files containing names and protected health information from the healthcare organization’s systems. The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on SecurityWeek.
> USN-8300-1: ngtcp2 vulnerability
Zou Dikai discovered that ngtcp2 serialized peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog was enabled, a remote attacker could possibly use this issue to execute arbitrary code.
> Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.  The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek.
> Laravel-Lang Packages Poisoned for Malware Delivery
Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek.
> The AI Era Is Creating a Bug Hunting Arms Race
As attackers ramp up their AI exploit development, the search for software vulnerabilities is changing rapidly.
> Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning
A zero-click attack targeting iPhones on iOS 16 hijacked WhatsApp accounts without linked devices, warnings, or user interaction. There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for...