[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (4 articles)

|

// AI-powered summary generated at 04:00

> Tata Electronics
Tata Electronics, a major electronics manufacturer and supplier to Apple and Tesla in India, confirmed it suffered a major cybersecurity incident. A ransomware group, identified as World Leaks, claimed to have stolen and leaked over 630 GB of confidential data, including technical specifications and...
> Glasgow School of Art
L'école d'art de Glasgow (GSA) a subi une perturbation informatique affectant ses étudiants et son personnel. Les utilisateurs ont été bloqués de leurs courriels et services en ligne. Bien que l'école ait qualifié cela de « perturbation informatique temporaire », ses employés ont été contraints de s...
> Laravel Lang packages hijacked to deploy credential-stealing malware
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]
> Teamplus (EVERY8D)
La plateforme EVERY8D, appartenant à l'entreprise interactive communications Teamplus, a été victime d'une attaque par logiciel de rançon entraînant une paralysie de ses services. Cette plateforme, qui gère plus d'un milliard de messages mensuels, est une infrastructure critique pour les systèmes d'...
> Comté de Chelan
Les systèmes réseau du comté de Chelan ont été piratés par un logiciel malveillant (malware) durant le week-end. Le comté a coupé son réseau, ses ordinateurs et son système téléphonique dans tous les départements par mesure de précaution. L'étendue exacte des dommages et la compromission de données...
> Debian Trixie Linux Privilege Escalation Denial of Service DSA-6295-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.90-1. Additionally this update includes a fix for a
> La Sauvegarde
L'association agenaise La Sauvegarde est touchée par une cyberattaque depuis le 24 mai 2026. Cette piraterie informatique a privé les employés de l'accès à leurs outils professionnels (boîtes mail, services internes, Internet), entraînant des retards dans les services essentiels, notamment le placem...
> Debian Trixie Linux Major Denial of Service Privilege Escalation DSA-6295-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.90-1. Additionally this update includes a fix for a
> npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally available on npm...
> CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack
Attackers began exploiting Drupal SQL injection flaw CVE-2026-9082 within 48 hours of patch release. Drupal issued a highly critical security patch on May 20 for CVE-2026-9082, a SQL injection vulnerability that allows unauthenticated attackers to compromise sites running PostgreSQL databases. The p...
> Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Soc...
> These special phone and app features can help protect you from spyware
Apple, Meta, and Google offer special security modes that provide your devices more secure against targeted spyware attacks. Here are how those modes work, what they do, and how to switch them on.
> Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. [...]
> Why pure extortion is replacing traditional ransomware
Ransomware gangs are shifting from encryption to pure extortion, focusing on stolen data, reputational pressure, and stealthier attacks. Ransomware groups are quietly changing strategy in 2026. Instead of encrypting systems and causing immediate disruption, many attackers are now focusing on pure ex...
> Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is an effort led...
> ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains
The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains appeared first on SecurityWeek.
> Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend
Or is it just life today, with AI constantly digging through code repositories in search of security holes?
> The FBI Wants ‘Near Real-Time’ Access to US License Plate Readers
Plus: Google publishes a live exploit for an unpatched flaw, the feds arrest two men accused of creating thousands of nonconsensual deepfake nudes, and more.
> Cyber actualités ZATAZ de la semaine du 19 au 23 mai 2026
Tour d’horizon cyber de la semaine : lookup, fuite de données, Telegram, McDonald’s France, VPN saisi, fausses promotions, fraudes publicitaires, menaces Linux, IA et accès initial en 2026.
> Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include - laravel-lang/lang laravel-lang/http-statuses lara...