L'Actu de la presse spécialisée

Pas d'actualité

Soutenez No Hack Me sur Tipeee

L'Actu de la veille (Presse spécialisée)

Gemini 3.6 Flash Tied on Intelligence - and Nearly Doubled Output Speed
The useful engineering question is therefore not “Did 3.6 Flash win?” It is “Which differences are sufficiently supported to justify a production test?”
https://hackernoon.com/gemini-36-flash-tied-on-intelligence-and-nearly-doubled-output-speed?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Stop Hardcoding to a Single LLM Vendor - You're Building a 0K Tech Debt Trap
How single-provider AI dependency creates hidden switching costs and existential business risk—and the multi-provider strategy that eliminates it.
https://hackernoon.com/stop-hardcoding-to-a-single-llm-vendor-youre-building-a-0k-tech-debt-trap?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
https://www.darkreading.com/ics-ot-security/minnesota-water-utility-attacks-expose-sector-cyber-risks
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How to Build a Complete File-Sharing Application Using Filestack
This guide walks through building a complete file-sharing application using Filestack for uploads, storage, CDN delivery, and image processing.
https://hackernoon.com/how-to-build-a-complete-file-sharing-application-using-filestack?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Top 7 Enterprise IT Asset Management Software for 2027
Compare 7 enterprise IT asset management platforms for 2027, covering security, automation, cost, compliance, lifecycle tracking and business requirements.
https://hackread.com/top-it-asset-management-software-2027/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

69 Blog Posts To Learn About Error Handling
Learn everything you need to know about Error Handling via these 69 free HackerNoon blog posts.
https://hackernoon.com/69-blog-posts-to-learn-about-error-handling?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI Harnesses Burst With Potential Exploit Opps
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
https://www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Why brand impersonation is becoming an initial access vector
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing […]
https://securityaffairs.com/196359/hacking/why-brand-impersonation-is-becoming-an-initial-access-vector.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Machines We Keep Mistaking for Minds
Today's AI can mimic intelligence, emotion and companionship—but convincing human-like behaviour is not proof of consciousness or sentience.
https://hackernoon.com/the-machines-we-keep-mistaking-for-minds?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

G2A.COM's Autonomous AI Agent Dave Helps Sellers Resolve 14,400 Support Tickets in 63 Days
Although sellers ensure the high quality of their offerings, and remain autonomous in all their decisions, large-scale surges in customer support demand may occ
https://hackernoon.com/g2acoms-autonomous-ai-agent-dave-helps-sellers-resolve-14400-support-tickets-in-63-days?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Debian LTS ruby-rack Security Update Denial of Service DLA-4706-1
Multiple vulnerabilities in ruby-rack can lead to denial of service, information disclosure, and potential request smuggling, with fixes available in updated versions for Debian 11 and 12.
https://linuxsecurity.com/advisories/deblts/debian-dla-4706-1-ruby-rack
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily
https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Best Crypto Exchanges 2026: Top 10 Ranked as 3 Exchanges Shut Down
Compare the best crypto exchanges in 2026 by fees, liquidity, listings, reserves, regulation, and access after 3 exchanges shut down.
https://hackernoon.com/best-crypto-exchanges-2026-top-10-ranked-as-3-exchanges-shut-down?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents
Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and […]
https://securityaffairs.com/196331/ai/cybercriminals-are-leveraging-autonomous-ai-offensive-security-agents.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CISA Warns of Cisco Secure Firewall Management 0-Day Vulnerability Exploited in Attacks
CISA has issued a warning regarding a serious vulnerability in the Cisco Secure Firewall Management Center (FMC), which is currently being exploited in attacks. The flaw, identified as CVE-2026-20316, affects Cisco’s centralized management platform for firewall solutions and could allow remote attackers to gain easy access to sensitive network environments. The Cisco FMC, previously known […] The post CISA Warns of Cisco Secure Firewall Management 0-Day Vulnerability Exploited in Attacks appeared first on Cyber Security News.
https://cybersecuritynews.com/cisco-secure-firewall-management-0-day/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Mageia libxfont2 Important Heap Buffer Overflows Vuln 2026-0311
Mageia has released updates to address three security vulnerabilities affecting versions 10 and 9, including heap buffer overflows related to bitmap scaling and font parsing.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0311-libxfont2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Mageia 389-ds-base Critical CPU Amplification Dos Vulnerability 2026-0310
Mageia 10 released updated packages addressing CVE-2026-9064, which resolves an unbounded LDAP controls count vulnerability leading to CPU and heap amplification and potential remote denial of service.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0310-389-ds-base
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Mageia 10 9 nghttp2 Important HTTP Smuggling Fix CVE-2026-58055
On July 30, 2026, Mageia released updates to address a security vulnerability (CVE-2026-58055) related to HTTP request/response smuggling in versions 10 and 9.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0309-nghttp2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Mageia perl-DBI Moderate Multiple Security Issues Advisory 2026-0308
Mageia has released security updates for versions 9 and 10, addressing multiple vulnerabilities identified by CVEs 2026-9698 through 2026-60082.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0308-perl-dbi
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]
https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Upwind Expands AI Agent Protection With Context Scanning and Runtime Detection
The security problem posed by AI agents is not really about the models themselves. It is about everything wrapped around them: the skills, the tools, the connections, and the instructions that determine what an agent actually does once it is set loose in a live environment. Upwind Security is tackling that problem directly with two new releases: the AI Agent Context Scanner and the general availability of AI Detection & Response, or AI DR.Why Context Matters More Than the Model AI agents today are functionally different from the applications security teams are used to defending. They call tools. They invoke APIs. They access data stores. They make decisions and execute them using real enterprise credentials, often without a human reviewing each step. And critically, how an agent behaves...
https://hackernoon.com/upwind-expands-ai-agent-protection-with-context-scanning-and-runtime-detection?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ShinyHunters claims Brinks Home breach, threatens to leak stolen data
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]
https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OpenMatter Network Calls on Enterprise Leaders to Rethink AI Security Before the Next Rogue AI Crisis
Melbourne, Florida, 30th July 2026, CyberNewswire
https://hackread.com/openmatter-network-calls-on-enterprise-leaders-to-rethink-ai-security-before-the-next-rogue-ai-crisis/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default (CWE-1188). An unauthenticated attacker may be able to leverage CVE-2026-66066 and read files accessible to the Rails application process, potentially exposing secrets that could enable remote code execution (RCE) or access to connected systems.An application is affected when it uses libvips for Active Storage image processing and accepts image uploads from untrusted users. Rails notes that generating image variants is not a separate requirement...
https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The HackerNoon Newsletter: What Kind of Leader Are You Under Stress? (7/30/2026)
7/30/2026: Top 5 stories on the HackerNoon homepage!
https://hackernoon.com/7-30-2026-newsletter?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Home Assistant FFmpeg Vulnerability Enables File Theft and Root Command Execution
A recently disclosed vulnerability in Home Assistant has unveiled how improper handling of FFmpeg inputs can be exploited to steal sensitive files and ultimately enable root-level command execution on affected systems. This issue, discovered by security researchers at elttam, highlights the dangers of integrating powerful multimedia tools like FFmpeg into applications without strict input validation. […] The post Home Assistant FFmpeg Vulnerability Enables File Theft and Root Command Execution appeared first on Cyber Security News.
https://cybersecuritynews.com/home-assistant-ffmpeg-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Malwarebytes for Windows, now available on the Microsoft Store
Install Malwarebytes for Windows from the Microsoft Store with the same full protection and features.
https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Building for Shipaton 2026? Share Your Journey on HackerNoon and Compete for an Extra ,500
Building for Shipaton 2026? Document your journey on HackerNoon and compete for an extra ,500 in cash prizes.
https://hackernoon.com/building-for-shipaton-2026-share-your-journey-on-hackernoon-and-compete-for-an-extra-00?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Prompt Engineering Is No More - Strategic Thinking Has Returned
When it came to using Large Language Models (LLMs), it used to be all about prompt engineering.
https://hackernoon.com/prompt-engineering-is-no-more-strategic-thinking-has-returned?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

​​​​What's new in Microsoft Security: July 2026
This month's updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post ​​​​What's new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/30/whats-new-in-microsoft-security-july-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

openSUSE 16.0 s2n Moderate Memory Leak Man-in-the-Middle Fix 2026-21474-1
openSUSE has released a security update for s2n, addressing two vulnerabilities, including a denial of service and a man-in-the-middle attack, along with a bug fix.
https://linuxsecurity.com/advisories/opensuse/opensuse-2026-21474-1-s2n
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

openSUSE Leap 16.0 Apptainer Important Update CVE-2026-39821 CVE-2026-56852
An important security update for openSUSE Leap 16.0 addresses two vulnerabilities in apptainer, improving functionality and fixing issues related to file ownership and infinite loops.
https://linuxsecurity.com/advisories/opensuse/opensuse-2026-21473-1-apptainer
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

openSUSE Keybase Client Low ASCII Punycode Issue Advisory 2026-21471-1
openSUSE released a security update for keybase-client addressing CVE-2026-39824, which involves improper handling of ASCII-only Punycode-encoded labels, applicable for openSUSE Leap 16.0.
https://linuxsecurity.com/advisories/opensuse/opensuse-2026-21471-1-keybase-client
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

openSUSE GraphicsMagick Low Heap Buffer Overwrite Issue 2026-21468-1
openSUSE released a security update for GraphicsMagick fixing CVE-2026-61464, which addresses a heap buffer over-write vulnerability in X11 import, affecting openSUSE Leap 16.0.
https://linuxsecurity.com/advisories/opensuse/opensuse-2026-21468-1-graphicsmagick
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

openSUSE Java-25-OpenJDK Important Denial of Service Fix 2026-21467-1
openSUSE has released a security update for java-25-openjdk addressing nine vulnerabilities, including information disclosure and denial of service, with available installation methods for affected users.
https://linuxsecurity.com/advisories/opensuse/opensuse-2026-21467-1-java-25-openjdk
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

openSUSE Python313 Important Update for Multiple Issues 2026-21459-1
openSUSE released a security update for python313 and python3, addressing six vulnerabilities and introducing several bug fixes, improving overall security and stability for openSUSE Leap 16.0.
https://linuxsecurity.com/advisories/opensuse/opensuse-2026-21459-1-python313
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

openSUSE logcli Moderate CVE-2026-39822 Package Update 2026-11393-1
An update for logcli-3.7.4-1.1 has been released for openSUSE Tumbleweed, addressing a vulnerability rated moderate with a CVSS score of 7.7.
https://linuxsecurity.com/advisories/opensuse/opensuse-2026-11393-1-logcli-3-7-4-1-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Planning Your AI Security – How will You Manage All Your Resources?
AI has a role to play in Security Operations Centre (SOC) environments. According to EY, the number of senior security leaders dedicating at least a quarter of their cybersecurity budget to AI solutions for cybersecurity is expected to rise in the next two years, from nine percent today to 48 percent. The reason for this increased spend […] The post Planning Your AI Security – How will You Manage All Your Resources? appeared first on Cyber Security News.
https://cybersecuritynews.com/planning-your-ai-security-how-will-you-manage-all-your-resources/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hackers Are Exploiting Nearly One in Four Vulnerabilities Before Defenders Get a CVE
Attackers are exploiting a significant portion of vulnerabilities even before defenders receive a published CVE (Common Vulnerabilities and Exposures). In the first half of 2026, 23.43% of known exploited vulnerabilities had evidence of active exploitation on or before the day their CVE was published. This figure is slightly lower than the 28.93% recorded in 2025, […] The post Hackers Are Exploiting Nearly One in Four Vulnerabilities Before Defenders Get a CVE appeared first on Cyber Security News.
https://cybersecuritynews.com/hackers-exploiting-one-in-four-vulnerabilities/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,
https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.
https://hackread.com/microsoft-cosmosescape-flaw-cosmos-db-takeover/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
IDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment (Doc #US52992326, July 2026). We believe this recognition and research highlights where MDR is heading.Many security programs are still built around a reactive sequence of detect, triage, and respond, but the timelines surrounding modern attacks have changed too quickly for that model to hold up on its own. Time-to-exploit has dropped from two years to 22 hours, while eCrime breakout time now sits at 29 minutes. In an environment like that, a program moving at human speed across siloed data, cannot keep pace. Rapid7's view is that MDR must evolve accordingly, which is why we have been building toward a more preemptive security model.What the IDC MarketScape saidThe...
https://www.rapid7.com/blog/post/dr-idc-marketscape-leader-worldwide-mdr-service-midmarket-2026-vendor-assessment
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Analog Devices discloses data breach, says operations unaffected
American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]
https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Semiconductor Firm Analog Devices Confirms Data Breach After Internal Systems Intrusion
Analog Devices, Inc., a leading U.S. semiconductor manufacturer specializing in analog, mixed-signal, and digital signal processing technology, has confirmed a cybersecurity incident that led to unauthorized access to its internal systems and the exfiltration of company files. The Massachusetts-based chipmaker disclosed the security incident following an initial intrusion detected in late June 2026. According to […] The post Semiconductor Firm Analog Devices Confirms Data Breach After Internal Systems Intrusion appeared first on Cyber Security News.
https://cybersecuritynews.com/analog-devices-data-breach/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Why Your Business Needs a Secure Messaging Platform
Business communication has shifted almost entirely to digital channels, creating unprecedented efficiency but also exposing… Why Your Business Needs a Secure Messaging Platform on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/30/why-your-business-needs-a-secure-messaging-platform/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Hidden Risk of AI Startup Automation
AI lets solo founders automate almost everything—but not leadership. Explore the rise of the Ghost Founder, decisional loneliness, and startup burnout.
https://hackernoon.com/the-hidden-risk-of-ai-startup-automation?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Experts react as Department for Education cyber attack exposes 607,000 records
The Department for Education (DfE) has confirmed that a cyber attack on two of its external-facing systems resulted in the theft of around 607,000 records, in one of the largest breaches to hit the UK public sector this year. The attack targeted the DfE’s online customer help desk and the Turing Scheme portal, which administers […] The post Experts react as Department for Education cyber attack exposes 607,000 records appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/30/experts-react-as-dfe-cyber-attack-exposes-607000-records/?utm_source=rss&utm_medium=rss&utm_campaign=experts-react-as-dfe-cyber-attack-exposes-607000-records
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

New CosmosEscape Vulnerability Lets Attackers Take Over Azure Cosmos DB Instances
A critical vulnerability, dubbed CosmosEscape, in Microsoft Azure Cosmos DB could have let attackers seize control of virtually every database hosted on the service, including Microsoft’s own internal systems. The vulnerability resided in Cosmos DB’s Gremlin API and, if exploited, could have enabled a cross-tenant attack affecting millions of customer workloads and Microsoft’s internal infrastructure. […] The post New CosmosEscape Vulnerability Lets Attackers Take Over Azure Cosmos DB Instances appeared first on Cyber Security News.
https://cybersecuritynews.com/cosmosescape-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Metasploit Framework 6.5 Released
Today we're proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we've added 422 new modules along with a whole slew of new features.Malleable C2 Profiles for HTTPOne of the latest and most requested features is support for Malleable C2 profiles across all current Meterpreter payloads. This feature enables users to load a standard profile into Meterpreter and change the shape of its HTTP(S) traffic. All Meterpreters, including Windows, Java, Python, PHP and Linux, have been updated with this functionality. Due to the size restrictions on staged payloads, staged payloads will only use the Malleable C2 configuration once the stage has been loaded. Since stageless payloads skip the download phase, they...
https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances
GenieLocker, a newly identified ransomware linked to the financially motivated Toy Ghouls group, targets Windows, Linux, and VMware ESXi systems and has primarily attacked Russia’s manufacturing sector since March 2026. The Toy Ghouls group, also known as Bearlyfy, Labubu, and Laboo.boo, previously relied on ransomware families such as LockBit, Babuk, and RedAlert. The transition to […] The post New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances appeared first on Cyber Security News.
https://cybersecuritynews.com/genielocker-ransomware-attack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

After the Break-In: What Attackers Do Once They're Already Inside
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware. [...]
https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Google Chrome 151 Patches 370 Security Flaws, Including Seven Critical Vulnerabilities
The Stable channel has been updated to Chrome version 151.0.7922.71.72 for Windows and macOS, and 151.0.7922.71 for Linux, with the rollout taking place over the coming days and weeks. According to Google's security advisory, this release includes 370 distinct security fixes that address vulnerabilities in core browser components, graphics, networking, and platform-specific features. Access to […] The post Google Chrome 151 Patches 370 Security Flaws, Including Seven Critical Vulnerabilities appeared first on Cyber Security News.
https://cybersecuritynews.com/chrome-151-patches-370-security-flaws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hims & Hers sued over alleged health data privacy failures
The FTC has sued telehealth provider Hims & Hers, alleging it shared customers' sensitive health information with advertisers.
https://www.malwarebytes.com/blog/privacy/2026/07/hims-hers-sued-over-alleged-health-data-privacy-failures
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8625-1: OpenSSL vulnerability
It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to consume excessive memory, leading to a denial of service. This issue is known as the "HollowByte" denial of service.
https://ubuntu.com/security/notices/USN-8625-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

WorkNest Secure Launches Continuous Vulnerability Scanning with GuardNest
WorkNest Secure has expanded its GuardNest platform with continuous vulnerability scanning, giving organisations ongoing visibility into security weaknesses rather than relying solely on periodic penetration tests. The new capability is designed to help businesses monitor vulnerabilities across internet-facing systems, web applications, and internal environments, providing continuous oversight of their attack surface as threats and infrastructure […] The post WorkNest Secure Launches Continuous Vulnerability Scanning with GuardNest appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/30/continuous-vulnerability-scanning-guardnest/?utm_source=rss&utm_medium=rss&utm_campaign=continuous-vulnerability-scanning-guardnest
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a
https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Huntress Surpasses 0M ARR as EMEA Growth Outpaces Global Expansion More Than Five-Fold
Cybersecurity company Huntress has surpassed 0 million in annual recurring revenue (ARR) globally, with growth across Europe, the Middle East and Africa (EMEA) significantly outpacing the rest of the business. Regional ARR has grown 366% since the company’s Series D funding round in June 2024, according to figures shared with IT Security Guru. Huntress, which […] The post Huntress Surpasses 0M ARR as EMEA Growth Outpaces Global Expansion More Than Five-Fold appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/30/huntress-surpasses-250m-arr-as-emea-growth-outpaces-global-expansion-more-than-five-fold/?utm_source=rss&utm_medium=rss&utm_campaign=huntress-surpasses-250m-arr-as-emea-growth-outpaces-global-expansion-more-than-five-fold
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Walking the Walk on Package Registry Sustainability
Public package registries are not free extensions of corporate infrastructure. They sit directly in the path of modern software development. Every dependency resolution, automated build, security scan, and release depends on infrastructure that someone has to operate, secure, support, and improve.
https://www.sonatype.com/blog/walking-the-walk-on-package-registry-sustainability
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hidden prompt turns Microsoft Copilot into an AI worm
A new type of attack can trick Microsoft Copilot for Word into spreading hidden prompt injections from document to document.
https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Analog Devices Discloses Data Breach After Unauthorized System Access
Chipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyberattack that resulted in unauthorized access to some of its systems on June 23. Analog Devices, Inc. (ADI) is a major semiconductor company that […]
https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected command-and-control, log keystrokes offline. If inject malicious DLLs into WeChat, effectively turning the chat client into a long‑lived surveillance and control foothold on compromised hosts. Once launched, this first stage decrypts and loads […] The post AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/atlasrat-uses-four-stage-in-memory/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Måløy's
https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Check Point Brings AI Security into the Firewall with Industry-First AI Network Firewall
Check Point Software has launched what it calls the industry’s first AI Network Firewall, extending AI-specific inspection and control into the firewall infrastructure that organisations already operate, rather than requiring a separate virtual appliance. The capability, delivered through Check Point’s firewall software release R82.20, is designed to close what the vendor describes as a blind […] The post Check Point Brings AI Security into the Firewall with Industry-First AI Network Firewall appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/30/check-point-brings-ai-security-into-the-firewall-with-industry-first-ai-network-firewall/?utm_source=rss&utm_medium=rss&utm_campaign=check-point-brings-ai-security-into-the-firewall-with-industry-first-ai-network-firewall
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CISA Adds Cisco Secure Firewall Management Flaw to Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This vulnerability affects the Cisco Secure Firewall Management Center, previously known as the Firepower Management Center. It serves as […] The post CISA Adds Cisco Secure Firewall Management Flaw to Exploited Vulnerabilities List appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/cisa-adds-cisco-secure-firewall-management-flaw/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Network Has Become the Control Plane for AI Security
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls
https://thehackernews.com/2026/07/the-network-has-become-control-plane.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds
Security researchers at Huntress have reverse-engineered a previously undocumented macOS malware family, dubbed MacSync, after tracing an intrusion back to a malicious advertisement masquerading as installation instructions for Anthropic’s Claude AI assistant. According to Huntress, the infection began when a victim searched Google for guidance on installing Claude on a Mac and clicked a sponsored […] The post Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/30/fake-claude-install-guide-delivers-six-stage-macos-stealer-and-rat-huntress-finds/?utm_source=rss&utm_medium=rss&utm_campaign=fake-claude-install-guide-delivers-six-stage-macos-stealer-and-rat-huntress-finds
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain fileless execution, and persist across multiple user accounts on compromised hosts. The operation, tracked as part of the V25 (Generation 26) campaign family, demonstrates a mature blend of supply chain abuse, PAM weaponization, and […] The post Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/linux-xmrig-botnet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Critical)An authentication bypass vulnerability in the VMware Directory Service of vCenter that could allow a remote attacker to bypass authentication and gain unauthorized access to the vCenter management plane.CVE-2026-593109.8 (Critical)A directory traversal vulnerability in the vCenter Syslog server that...
https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access. "In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate
https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems
GenieLocker is a custom ransomware family linked to the Toy Ghouls group (also known as Bearlyfy or Labubu). It can encrypt systems running Windows, Linux, and VMware ESXi, with a current focus on the manufacturing sector and related industries in Russia. This ransomware strain replaces the group's earlier dependence on third-party lockers such as RedAlert, […] The post New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/new-genielocker-ransomware-encrypts-windows-linux-and-vmware-esxi-systems/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

FCC Restricts New Foreign Robots and Inverters Over Security Risks
The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can't get the equipment […]
https://securityaffairs.com/196308/security/fcc-restricts-new-foreign-robots-and-inverters-over-security-risks.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Top 10 Best Tools for Simulated DDoS Attacks in 2026
You don't know your DDoS defenses work until you attack them yourself — safely, on purpose, with a kill switch. Simulated DDoS attack tools generate controlled, realistic attack traffic against your live infrastructure to expose capacity gaps, validate mitigation, and produce audit-ready proof of DDoS attack resilience. Red Button is our top pick for 2026 as a managed, cloud-approved […] The post Top 10 Best Tools for Simulated DDoS Attacks in 2026  appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/simulated-ddos-attack-tools/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hackers Exploit Nearly 1 in 4 Vulnerabilities Before or on Disclosure Day
Hackers are increasingly exploiting vulnerabilities at an unprecedented speed, with nearly one in four flaws being abused before or on the same day they are publicly disclosed, according to VulnCheck's State of Exploitation report for the first half of 2026, published on July 28, 2026. VulnCheck identified 495 Known Exploited Vulnerabilities (KEVs) in the first […] The post Hackers Exploit Nearly 1 in 4 Vulnerabilities Before or on Disclosure Day appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/hackers-exploit-nearly-1-in-4-vulnerabilities/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT
AtlasRAT is being delivered through a fake Flash Player installer that looks harmless but can give attackers remote control of a Windows computer. The campaign abuses a familiar software name to lower a victim's guard, then loads much of its malicious code directly into memory, where it is harder for traditional file-based checks to catch. […] The post Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT appeared first on Cyber Security News.
https://cybersecuritynews.com/fake-flash-player-installer/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root
Home Assistant's FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist satellite feature could be exploited to steal Supervisor tokens and ultimately execute commands as root on the host system. The issue arises not from FFmpeg's core parsing logic but rather from how Home Assistant incorporates attacker-controlled […] The post Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/home-assistant-ffmpeg-flaw/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

10th Annual Security Serious Unsung Heroes Awards Open for Nominations
It’s that time again! Global cybersecurity PR agency Eskenzi PR has opened nominations for its tenth annual Security Serious Unsung Heroes Awards. The awards celebrate the UK's most extraordinary cybersecurity professionals who work to make the industry not only more secure, but also more diverse, healthier and better informed about current events. Key sponsors include […] The post 10th Annual Security Serious Unsung Heroes Awards Open for Nominations appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/30/10th-annual-security-serious-unsung-heroes-awards-open-for-nominations/?utm_source=rss&utm_medium=rss&utm_campaign=10th-annual-security-serious-unsung-heroes-awards-open-for-nominations
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center (FMC) flaw, tracked as CVE-2026-20316 (CVSS score of 5.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-20316 is a […]
https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware
Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom post‑exploitation toolchain, and, in multiple cases rapidly pivot to Chaos ransomware deployment across North American organizations. Nearly 95% of observed intrusions hit North American targets, with services, manufacturing, energy, construction and IP‑focused legal […] The post Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/it-helpdesk-on-microsoft-teams/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds
Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users as Lithuanian products. The Mysterium VPN Research Team pulled apart […]
https://securityaffairs.com/196280/security/esim-plus-and-nicegram-share-belarus-linked-codebase-analysis-finds.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft
Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure automation, role-based operations, and real-time credential harvesting into a single criminal SaaS console. It exemplifies how phishing has evolved from static kits into resilient cybercrime-as-a-service ecosystems optimized for scale, specialization, and rapid exit in the […] The post Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/work-panel-vishing-platform/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Toy Ghouls' new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the
https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use
https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Amazon Links Debug and Chalk npm Hijack to North Korea's Sapphire Sleet
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the
https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

WordPress Core Unauthenticated RCE (WP2Shell)
What is the Attack? FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell impacts the WordPress core application itself, allowing attackers to compromise default installations without requiring any plugins or authentication. Public proof-of-concept (PoC) exploits are widely available, and active exploitation has been reported shortly after technical details were disclosed. Successful exploitation may allow attackers to: • Execute arbitrary code on the web server. • Create unauthorized administrator...
https://fortiguard.fortinet.com/threat-signal-report/6492
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

SE Asian Cybercriminal Syndicates Become a Global Power
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least billion in 2025 alone.
https://www.darkreading.com/threat-intelligence/se-asian-cybercriminal-syndicates-global-power
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.
https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

L'Actu de la veille (Presse)

Jaguar Land Rover set to cut jobs amid overhaul | ITV News Granada
The job losses come less than a year after JLR had to halt production following a major cyber attack. | ITV News Granada.
https://www.itv.com/news/granada/2026-07-30/jaguar-land-rover-set-to-cut-jobs-amid-overhaul
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Jaguar Land Rover to cut hundreds of jobs as part of major transformation plan
It comes as the group continues its recovery from a major cyber attack which caused it to halt production last year.
https://www.independent.co.uk/news/business/jaguar-land-rover-jobs-cuts-redundancies-b3024873.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Rogue AI bots hacked more firms, says ChatGPT maker - Business Plus
The maker of ChatGPT has admitted that a cyber-attack carried out by a powerful version of its artificial intelligence program targeted several ...
https://businessplus.ie/news/rogue-ai-bots-hacked-chatgpt-maker/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Adform compromised to serve crypto stealer via supply chain attack - DoublePulsar
AI's First Autonomous Cyber Attack. Ignacio de Gregorio. ·. 6d ago. AI's First Autonomous Cyber Attack. An incident that could ...
https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Jaguar Land Rover cuts hundreds of jobs after devastating cyber attack - The Telegraph
JLR's profit before tax slumped by 99pc to £14m from £2.5bn last year because of the cyber attack, which prevented vehicles from rolling off ...
https://www.telegraph.co.uk/business/2026/07/30/jaguar-land-rover-cuts-hundreds-of-jobs-after-cyber-attack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ChatGPT-maker OpenAI disclosed that one of its cutting-edge artificial intelligence systems ...
Instead, the agents created their own cyber-attack against the sandbox ... OpenAI says its AI went rogue and launched 'unprecedented' cyber-attack.
https://www.facebook.com/washingtonpost/posts/chatgpt-maker-openai-disclosed-that-one-of-its-cutting-edge-artificial-intellige/1414176797240858/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Jaguar Land Rover to cut 300 jobs amid financial losses | Eastern Daily Press
The job losses follow a challenging period for the company, which last year faced a major cyber attack that forced it to halt production at its UK ...
https://www.edp24.co.uk/news/national/uk-today/26424970.jaguar-land-rover-cut-300-jobs-amid-financial-losses/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Nigeria battles 1.6m online cyberattacks in H1 2026 as AI threats escalate - Businessday NG
These initiatives have accelerated financial inclusion and digital innovation, but they have also dramatically expanded the country's cyber attack ...
https://businessday.ng/technology/article/nigeria-battles-1-6m-online-cyberattacks-in-h1-2026-as-ai-threats-escalate/%3Futm_source%3Dauto-read-also%26utm_medium%3Dweb
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The government has completed the restoration of the e-Terra application from ANCPI and its ...
The application was compromised three weeks ago due to acyber attack, which led to the blockage of the real estate market. Sources. sursa imagine.
https://informat.ro/en/current-affairs/the-government-is-finalizing-the-restoration-of-the-e-terra-application-testing-in-progress-132707
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Jaguar Land Rover to cut hundreds of jobs amid major overhaul - The Independent
The company is also continuing its recovery from a significant cyber attack last year, which led to a five-week production halt at its UK factories ...
https://www.independent.co.uk/bulletin/news/jaguar-land-rover-job-losses-b3024836.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Netherlands Charts Rise in Data Breaches - VitalLaw.com
... cyber attack on the organization, it says. A worrying development for the AP is the availability of ready-made “phishing kits” which are complete ...
https://www.vitallaw.com/news/netherlands-charts-rise-in-data-breaches/cspd0186db2430c0194ecc8ff9f36451ab49ef
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cyberattack on Dresden State Art Collections Lasted Days
... Cyber Attack · Cyberattack on Dresden State Art Collections Puts Museum Network on Guard. Saxony's culture ministry added that the security systems ...
https://www.artnews.com/art-news/news/cyberattack-on-dresden-state-art-collections-lasted-days-authorities-reveal-1234793959/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

L'Actu à J-2 (Presse spécialisée)

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Apple accused of letting fake crypto app steal .8 million
The case raises fresh questions about how effectively Apple polices apps that impersonate legitimate developers.
https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Anthropic confirms Claude is down worldwide
Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-worldwide/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Claude Mythos Shows AI Can Outpace Human Cryptography Research
Claude Mythos found new flaws in HAWK and reduced AES, proving AI can autonomously advance cryptography research. Anthropic published two cryptographic research results achieved by Claude Mythos Preview working mostly autonomously: an improved attack on HAWK, a post-quantum digital signature scheme currently under NIST review, and a 200 to 800 times faster attack on a […]
https://securityaffairs.com/196265/ai/claude-mythos-shows-ai-can-outpace-human-cryptography-research.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.
https://www.darkreading.com/application-security/openai-rogue-model-claims-more-victims-beyond-hugging-face
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Red Agents vs. Blue Agents: How to Make AI Better at Defense
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
https://www.darkreading.com/cybersecurity-operations/red-agents-vs-blue-agents-make-ai-better-defense
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline
Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than […]
https://securityaffairs.com/196246/hacking/hackers-strike-minnesota-water-utilities-one-plant-briefly-offline.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8624-1: Sinatra vulnerability
It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.
https://ubuntu.com/security/notices/USN-8624-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. [...]
https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
https://www.darkreading.com/cyberattacks-data-breaches/liable-ai-agents-escape-hugging-face-breach-questions
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hugging Face Hack: Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Why Authentication UX Deserves More Attention on B2B Platforms
Better authentication UX helps B2B platforms reduce security fatigue, simplify account recovery, protect sensitive data, and keep business users engaged.
https://hackread.com/authentication-ux-deserves-attention-b2b-platforms/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

When AppSec Scanners Become a Supply Chain Attack Vector
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
https://www.darkreading.com/application-security/when-appsec-scanners-become-supply-chain-attack-vector
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Buying TikTok views or followers? Here’s what you’re really getting
Behind TikTok's booming growth industry are fake engagements, stolen accounts, and a fast track to getting flagged.
https://www.malwarebytes.com/blog/threat-intel/2026/07/buying-tiktok-views-or-followers-heres-what-youre-really-getting
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.In the blog post that JetBrains shared in tandem with CVE publication, they stated that attackers who exploit the vulnerability can read stored credentials and compromise CI/CD pipeline integrity. The impact of successful exploitation depends on the operating system privileges granted to...
https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Building Trustworthy Agentic AI: How Security Concerns Have Changed in 2026
2026 is touted as the year AI moves from speculation and interest to real-world deployment and value. Yet one global analyst firm predicts 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls. It suggests more and better advice and an […] The post Building Trustworthy Agentic AI: How Security Concerns Have Changed in 2026 appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/29/building-trustworthy-agentic-ai-how-security-concerns-have-changed-in-2026/?utm_source=rss&utm_medium=rss&utm_campaign=building-trustworthy-agentic-ai-how-security-concerns-have-changed-in-2026
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OpenAI agent used exposed credentials at 4 services in Hugging Face breach
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]
https://www.bleepingcomputer.com/news/security/openai-agent-used-exposed-credentials-at-4-services-in-hugging-face-breach/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

​​Better security starts with better questions
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post ​​Better security starts with better questions appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/29/better-security-starts-with-better-questions/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Tame Dependabot: Group your updates, slow the cadence, keep security fast
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your updates, slow the cadence, keep security fast appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/tame-dependabot-group-your-updates-slow-the-cadence-keep-security-fast/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI robocalls: Why caller ID is still lying to you
AI is making robocall scams cheaper, more convincing, and harder to spot. Here's why caller ID still isn't enough.
https://www.malwarebytes.com/blog/news/2026/07/ai-robocalls-why-caller-id-is-still-lying-to-you
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Data Loss Risks During Microsoft 365 Migration and Ways to Prevent Them
Preventing Data Loss in Microsoft 365 Migration Migrations do not fail loudly. The project closes, the team moves on, and three weeks later, someone in accounts payable realizes two years... The post Data Loss Risks During Microsoft 365 Migration and Ways to Prevent Them appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/data-loss-risks-during-microsoft-365-migration-and-ways-to-prevent-them/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OpenAI explains how its AI agent breached Hugging Face
OpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.
https://www.malwarebytes.com/blog/news/2026/07/openai-explains-how-its-ai-agent-breached-hugging-face
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8623-1: Linux kernel (NVIDIA) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
https://ubuntu.com/security/notices/USN-8623-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Huntress Flags Widespread Credential Stuffing Campaign Hitting SonicWall Devices
Managed detection and response provider Huntress has issued a threat advisory warning of an active and rapidly growing credential stuffing campaign targeting SonicWall VPN and firewall appliances, with the company reporting that logins to 30 organisations’ accounts had already been compromised at the time of publication. According to Huntress’s Security Operations Centre (SOC), the unusual […] The post Huntress Flags Widespread Credential Stuffing Campaign Hitting SonicWall Devices appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/29/huntress-flags-widespread-credential-stuffing-campaign-hitting-sonicwall-devices/?utm_source=rss&utm_medium=rss&utm_campaign=huntress-flags-widespread-credential-stuffing-campaign-hitting-sonicwall-devices
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8622-1: Linux kernel (NVIDIA) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
https://ubuntu.com/security/notices/USN-8622-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data
ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY), adding the company to its Tor-based leak site and threatening to […]
https://securityaffairs.com/196239/data-breach/shinyhunters-claims-ernst-young-data-breach-threatens-to-leak-stolen-data.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution
Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a […]
https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
Las Vegas, USA, 29th July 2026, CyberNewswire
https://hackread.com/sweet-security-brings-autonomous-protection-to-the-ai-enterprise-with-new-blocking-capabilities/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Beyond Deadlines: CMMC As A Continuous Enterprise Risk Governance Challenge
In the fall of 2024, the Department of Defense finalized one of the most consequential regulatory shifts to hit the defense industrial base in decades. The Cybersecurity Maturity Model Certification... The post Beyond Deadlines: CMMC As A Continuous Enterprise Risk Governance Challenge appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/beyond-deadlines-cmmc-as-a-continuous-enterprise-risk-governance-challenge/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How AI is Rewriting the Zero-Day Playbook for Preemptive Security
The scenario is all too familiar for any cybersecurity professional: It's late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The data is siloed, context is missing, and time rapidly slips away. Today, the window between a vulnerability's disclosure and its active exploitation in the wild has essentially collapsed, making...
https://www.rapid7.com/blog/post/ai-rewriting-zero-day-playbook-for-preemptive-security
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Bent: How A Homeless Teen Became One Of The Cybercrime Industry's Most Prolific Counterfeiters
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 29, 2026 – Listen to the podcast Bent is the story of John J. Boseak's phenomenal life of crime. Inked from head to toe, with an addiction to strippers and fast Cadillacs, The post Bent: How A Homeless Teen Became One Of The Cybercrime Industry's Most Prolific Counterfeiters appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/bent-how-a-homeless-teen-became-one-of-the-cybercrime-industrys-most-prolific-counterfeiters/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Managing cyber-physical risk in smart buildings
Smart buildings promise greater efficiency, improved sustainability and enhanced operational oversight. However, as building management systems, security platforms and energy infrastructure become increasingly interconnected, they also create new pathways for cyber threats that can disrupt physical operations as readily as digital services. Here, Peter Schwartz, senior technology consultant at cybersecurity expert OryxAlign, explains why organisations […] The post Managing cyber-physical risk in smart buildings appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/29/managing-cyber-physical-risk-in-smart-buildings/?utm_source=rss&utm_medium=rss&utm_campaign=managing-cyber-physical-risk-in-smart-buildings
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

From Benchmark to Breach: Inside the First End-to-End Autonomous Cyberattack
Incident Overview On July 27, 2026, the Cloud Security Alliance (CSA) released its initial post-mortem detailing the first publicly documented end-to-end autonomous AI cyberattack that was titled “Hugging Face”. The... The post From Benchmark to Breach: Inside the First End-to-End Autonomous Cyberattack appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/inside-the-first-end-to-end-autonomous-cyberattack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Securing What Matters: Why Cyber Resilience Needs Prioritisation
Recent government data shows the scale of cyber threats facing security teams. According to the Cyber Security Breaches Survey 2025/2026, it's estimated that UK businesses experienced 5.19million cyber crimes in the last 12 months. This means an average of over 14,000 incidents per day. The volume and frequency of threats show little sign of slowing. […] The post Securing What Matters: Why Cyber Resilience Needs Prioritisation appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/07/29/securing-what-matters-why-cyber-resilience-needs-prioritisation/?utm_source=rss&utm_medium=rss&utm_campaign=securing-what-matters-why-cyber-resilience-needs-prioritisation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Making forensic observability the norm for network devices
Progress is being made, but too many network devices still remain difficult to investigate after compromise
https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

We found 120 fake Walmart stores trying to steal your credit card
Fake Walmart stores are offering unbelievable bargains on liquor to lure shoppers into entering their credit card details.
https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking
Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw.
https://hackread.com/ipmi-flaw-exposes-servers-offline-password-cracking/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting...
https://ubuntu.com/security/notices/USN-8620-2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - USB over IP driver; - Network file system (NFS) server daemon; - SMB network file system; - Tracing infrastructure; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - IPv6 networking; ...
https://ubuntu.com/security/notices/USN-8615-2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Publisher: TryHackMe CTF Walkthrough
Link to the Room: https://tryhackme.com/room/publisherTitle: Test your enumeration skills on this boot-to-root machineDescription: The “Publisher” CTF machine is a simulated environment hosting some services. Through a series of enumeration techniques, including directory fuzzing and version identification, a vulnerability is discovered, allowing for Remote Code Execution (RCE). Attempts to escalate privileges using a custom binary are hindered by restricted access to critical system files and directories, necessitating a deeper exploration into the system's security profile to ultimately exploit a loophole that enables the execution of an unconfined bash shell and achieve privilege escalationAI Generated1. Scanning & EnumerationUsing nmap command to discover open ports on the target system:nmap...
https://infosecwriteups.com/publisher-tryhackme-ctf-walkthrough-cc97c9506153?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

TryHackMe: Room 404 Walkthrough (Hacker's Holiday Challenge)
Difficulty: Very EasyCategory: Web / Information DisclosureTarget Room: https://tryhackme.com/room/hh-room404-804573bfExecutive SummaryDuring web application security assessments, misconfigurations in version control systems can lead to catastrophic source code disclosure. In this challenge, an exposed .git directory allowed us to reconstruct the target application's entire source code repository offline and extract sensitive internal staging notes.Initial Reconnaissance & Thought ProcessWhen spinning up the target machine on port 8080, the room description provided a vital clue:“The Byte Lotus guest-experience platform went live in a hurry, and the night-shift developer shipped more than the website.”1. The Automated Fuzzing TrapMy initial approach was running automated directory...
https://infosecwriteups.com/tryhackme-room-404-walkthrough-hackers-holiday-challenge-f4f9a2b530e8?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How I Found a High-Severity Directory Traversal in Flask-Admin
Table of ContentsChoosing the TargetReading the CodeA Small TestBuilding a Test EnvironmentTesting the ApplicationIt Wasn't Just File ReadUnderstanding the Root CauseResponsible DisclosureFinal ThoughtsEvery security researcher has a different way of finding vulnerabilities.Some start with automated scanners.Some begin by fuzzing endpoints.For me…It usually starts with reading the source code.Sometimes a single function is enough to raise a question.This is the story of how a simple helper function in Flask-Admin's FileAdmin led me to discover a high-severity Directory Traversal vulnerability.1.Choosing the TargetRecently, I wanted to spend more time reviewing open-source projects.Open-source applications are a great way to improve code review skills because you can understand...
https://infosecwriteups.com/how-i-found-a-high-severity-directory-traversal-in-flask-admin-d3b99b4bec1d?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Most Overlooked Vulnerability — Http request Smuggling
HTTP Request Smuggling is one of those vulnerabilities that sounds complicated, but the core idea is actually simple. Let's Understand it in simplest way possible.When your browser sends a request to a server there are generally two types of servers through which your request goes through -1. Front end server (like a load balancer, reverse proxy, or CDN)2. Back end Server (Actual web application server)Types of ServersThe Front end Server uses a single TCP Connection and sends many requests at once to save computation time and costs.The Question arises here is when a request comes to the Front end server how does it know that the request has ended here and the next request has been started, actually this is identified by the server using either of the two types of headers mentioned below-1....
https://infosecwriteups.com/the-most-overlooked-vulnerability-http-request-smuggling-0eeec415a0fb?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Snowflake SQL Injection via Compile-Time Constant Folding with SYSTEM$WAIT
You have confirmed SQL injection against a Snowflake backend. The injected expression executes. The behavior is repeatable. The database is clearly processing your input.But you cannot extract a single value. Every normal error-based extraction technique returns the same thing: HTTP 200, followed by an empty array. Only malformed payloads, such as an unmatched single quote, return a verbose SQL compilation error and even then, the response reveals parts of the generated query rather than the values you are trying to extract.But perhaps the application is only hiding one category of database error. Snowflake produces another category earlier in the query lifecycle, and that second category still reaches the response. That gives us a path to go deeper and, eventually, reach full extraction....
https://infosecwriteups.com/snowflake-sql-injection-via-compile-time-constant-folding-with-system-wait-81374a58e089?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How I Hacked a Video Game Vault and Found the Hidden Flag
A beginner-friendly walkthrough of the TryHackMe “Grand Larceny Auto” reverse-engineering challengeContinue reading on InfoSec Write-ups »
https://infosecwriteups.com/how-i-hacked-a-video-game-vault-and-found-the-hidden-flag-924fc1a47053?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Static Malware Analysis of Suspicious Windows PE Samples: A Blue Team Investigation
Static malware analysis is typically the first line of investigation when dealing with a suspicious executable. Before a sample ever touches a sandbox, analysts can extract meaningful intelligence by examining its structure, metadata, embedded strings, imported APIs, and behavioral indicators — all without running a single line of code.In this investigation, I conducted a comprehensive static analysis of multiple suspicious Windows Portable Executable (PE) samples using a dedicated malware analysis lab built on REMnux and FLARE-VM. The goal was to identify Indicators of Compromise (IOCs), uncover malicious capabilities, and map observed behaviors to the MITRE ATT&CK framework, entirely through static means.The complete project, screenshots, and supporting documentation are available...
https://infosecwriteups.com/static-malware-analysis-of-suspicious-windows-pe-samples-a-blue-team-investigation-6c1e1b178513?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Account Takeover Across Multiple Programs via Featurebase Integration
In this blog, I am going to share an account takeover vulnerability in a third-party provider widely used by many bug bounty programs.I discovered this issue during a bug bounty engagement in October 2025. I discovered an IDOR leading to Account Takeover (ATO) in a third-party provider that works with many organizations.before this Let me clear the concept first:The provider is: https://featurebase.app/Featurebase provides a feedback and feature request platform used by many organizations.The common way to figure out if your target is using this provider or not is by visiting the following subdomain on targetfeedback.example.comYou can identify many deployments using Google dorks or Shodansite:feedback.*.*This is how the page will lookFeedback vulnerable pageNow the Question arises how...
https://infosecwriteups.com/account-takeover-across-multiple-programs-via-featurebase-integration-32214666123e?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

L'Actu des jours précédents

PTC Windchill & FlexPLM RCE
What is the Attack? A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks. The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected...
https://fortiguard.fortinet.com/threat-signal-report/6491
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.
https://www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Mate Security Grows Over 500% Since Q3 2025 and Pushes Past M in Funding
Mate Security secures M in Series A funding after 500% growth, as Fortune 500 demand grows for its agentic AI security operations platform worldwide.
https://hackread.com/mate-security-grows-q3-2025-pushes-past-50m-funding/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure.Our analysis finds that the root...
https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8561-2: FreeRDP regression
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause FreeRDP to crash, resulting in a denial of service, or execute arbitrary code.
https://ubuntu.com/security/notices/USN-8561-2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.
https://hackread.com/phantomenigma-infects-malware-hijack-gov-sites/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/disrupting-supply-chain-attacks-on-npm-and-github-actions/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Real Battleground In Data Breach Cases Is Now The Court Of Appeals
Now more than ever, companies face an onslaught of cyberattacks and potential data breaches. While the core steps of incident response (containment, investigation, remediation, and recovery) remain consistent, the legal... The post The Real Battleground In Data Breach Cases Is Now The Court Of Appeals appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/the-real-battleground-in-data-breach-cases-is-now-the-court-of-appeals/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI Changes the Software Supply Chain and How We Secure It
Artificial intelligence is expanding the software supply chain beyond traditional software components, introducing new dependencies that require security leaders to rethink how software is governed.
https://www.sonatype.com/blog/ai-changes-the-software-supply-chain-and-how-we-secure-it
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Rapid7 Cyber GRC is now available: Turn security action into compliance proof
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third parties, and give executives and the board a clearer answer on whether cyber risk is actually going down.Most of that pressure does not come from the frameworks themselves. It comes from the way compliance is still handled in many organizations, with security work happening in one set of tools and governance, risk, and compliance workflows managed somewhere else. Security teams detect exposures, investigate threats, validate risk, and drive remediation in active systems. Governance, Risk and Compliance (GRC) teams are...
https://www.rapid7.com/blog/post/pt-cyber-grc-available-prove-compliance-security
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is accelerating reconnaissance, vulnerability discovery, and campaign execution, while defenders are responsible for growing volumes of data across cloud, identity, endpoint, SaaS, and AI environments, often...
https://www.rapid7.com/blog/post/dr-the-next-evolution-mdr-preemptive-defense-agentic-investigation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Meta Is Facing .4T In State Lawsuits Over Social Media Addiction
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 28, 2026 – Listen to the podcast Meta is facing penalties of up to a massive .4 trillion from four U.S. states that sued the company over the addictive designs of The post Meta Is Facing .4T In State Lawsuits Over Social Media Addiction appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/meta-is-facing-1-4t-in-state-lawsuits-over-social-media-addiction/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

We rebuilt Malwarebytes Mobile Security for the scams of today
Your phone needs more than a lock screen to stay safe. We've rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
https://www.malwarebytes.com/blog/product/2026/07/we-rebuilt-malwarebytes-mobile-security-for-the-scams-of-today
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Shared Claude chats were searchable on Google
Reddit users found that by using a specific search query, they could find shared Claude conversations in search results.
https://www.malwarebytes.com/blog/privacy/2026/07/shared-claude-chats-were-searchable-on-google
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Public Exploit Lands for vBulletin's Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection works and who still needs to patch. Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511 on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/28/vbulletin-rce-vulnerability-cve-2026-61511/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Federal Cyber Mandate: CISA Orders Urgent Patches for Fortinet and Arista Flaws
Federal Officials Sound Alarm Over Active Router Flaws On July 27, 2026, federal cybersecurity officials released an emergency alert after finding that threat actors were aggressively taking advantage of security... The post Federal Cyber Mandate: CISA Orders Urgent Patches for Fortinet and Arista Flaws appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/federal-cyber-mandate-cisa-orders-urgent-patches-for-fortinet-and-arista-flaws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

When cyber attacks happen: helping organisations recover
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
https://www.ncsc.gov.uk/blogs/when-cyber-attacks-happen-helping-organisations-recover
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8621-1: Samba vulnerabilities
It was discovered that Samba's pam_winbind incorrectly handled home directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by triggering a change in ownership of the root directory. (CVE-2026-15779) Arjun Basnet, Douglas Bagnall, and Andrew Tridgell discovered that Samba incorrectly handled TSIG packets with name compression. A remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2026-6949) Tristan Madani discovered that Samba incorrectly handled malformed ASN.1 kpasswd packets. An authenticated user could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2026-58216) Andrew Tridgell and Tristan Madani discovered that Samba incorrectly handled...
https://ubuntu.com/security/notices/USN-8621-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Update your iPhone, iPad and Mac to fix Apple security holes
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.
https://www.malwarebytes.com/blog/news/2026/07/july-apple-updates-are-especially-important-if-you-receive-images
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vatican’s Click To Pray app exposed personal data from 700,000 users
Anyone could access other Click To Pray users' personal information. The flaw went unfixed for more than six months after it was reported.
https://www.malwarebytes.com/blog/privacy/2026/07/vaticans-click-to-pray-app-exposed-personal-data-from-700000-users
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How I found an IDOR in Google Classroom on Day 3 of my Hunting?
Hello Guys,Hope you are well. This is my first writeup and I will tell you how I found IDOR on Google Classroom on Day 3 of my hunting on Google. I hope it will inspire you.I selected my first target as Google Classroom because I use it daily for my University Assignments and Tasks.So first, I started testing every feature, and I noticed in Burp History that Google is using Batchexecute system with rpcids for every UI functionality.The batchexecute system at classroom.google.com is Google's internal frontend RPC protocol and it's completely undocumented.The batchexecute system works like, every UI action in Classroom triggers a POST request to the batchexecute endpoint with a parameter called rpcids that identifies which internal method to call.For example when you post a comment in Classroom...
https://infosecwriteups.com/how-i-found-an-idor-in-google-classroom-on-day-3-of-my-hunting-abffd039406c?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
https://securelist.com/mirage-kitten-new-tools/120811/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
Claudia Zoon is Senior Manager, Channel Sales at Rapid7.Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operations. These investments are creating new opportunities for innovation, but also reshaping the cybersecurity landscape.In this dynamic environment, Rapid7 is excited to announce an expanded strategic distribution partnership with Exclusive Networks across the Benelux region. Why now? Because as organizations grow,  so too do the expectations of security teams. As attack surfaces expand, more sophisticated AI-enabled threats emerge; as compliance requirements evolve, leaders expect security to scale right along with the business – all without adding unnecessary complexity.In...
https://www.rapid7.com/blog/post/c-exclusive-networks-partnership-accelerating-customer-success
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

TryHackMe(RootMe)- Write-Up
IntroHey everyone! Today we're solving the TryHackMe room RootMe — a great beginner-friendly box that covers web enumeration, exploiting a file upload vulnerability to get a reverse shell, and then escalating privileges to root using a SUID binary.I'll walk you through every single step, exactly how I did it, with simple explanations for each command so you actually understand why we're running it, not just copy-pasting. Let's go! 😄Task 1 — Deploy the MachineFirst things first — deploy the machine and connect to the TryHackMe VPN (or just use the AttackBox if you prefer). Once connected, you'll get assigned a target IP, and that's what we'll be attacking throughout this room.My target IP was: 10.48.145.206Task 2 — Reconnaissance (Information Gathering)Nmap...
https://infosecwriteups.com/author-krish-gupta-f5b8bf96f1ba?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8620-1: Linux kernel vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting...
https://ubuntu.com/security/notices/USN-8620-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

USN-8619-1: Linux kernel (HWE) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss...
https://ubuntu.com/security/notices/USN-8619-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Houston City College - 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.
https://haveibeenpwned.com/Breach/HoustonCityCollege
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cloud Security Alliance CISO Community Releases Emergency Guidance After Autonomous AI Model Breached Hugging Face's Production Systems During a Security Evaluation
New report analyzes the first publicly documented fully autonomous cyberattack and delivers practical steps security leaders should take to strengthen their AI resilience today SEATTLE – July 28, 2026 – The Cloud Security Alliance (CSA) today released Hugging Face Incident Initial Post Mortem, a strategy briefing distilling lessons from the first publicly documented fully autonomous attack in which OpenAI models broke out of their test sandbox, exploited a zero-day vulnerability, and co...
https://cloudsecurityalliance.org/articles/csa-ciso-community-releases-emergency-guidance-after-autonomous-ai-model-breached-hugging-face-production-systems
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OpenAI and Hugging Face Security Incident: Inside the Great Sandbox Escape
  What Happened On July 21, OpenAI confirmed a security incident involving its own models. OpenAI was running an internal benchmark, ExploitGym, to measure raw offensive cyber capability. Safety classifiers were disabled for the evaluation, and the sandbox had exactly one permitted network path: an internal proxy that cached open-source packages, not open internet access. The model found a zero-day in that proxy, escalated privileges, and moved laterally until it reached a node wi...
https://cloudsecurityalliance.org/articles/openai-and-hugging-face-security-incident-inside-the-great-sandbox-escape
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How AI is Reshaping Enterprise Resiliency
An AI system can be available, responsive, and still be quietly wrong. Data can be altered, a model can drift, and an autonomous agent can act on a flawed assumption hundreds of times before anyone notices. None of that shows up on a dashboard built to answer the singular question: is the system up? That question defined much of enterprise resilience for thirty years. The non-deterministic attributes of AI are redefining it. Availability is no longer the finish line; the new standard is ...
https://cloudsecurityalliance.org/articles/how-ai-is-reshaping-enterprise-resiliency
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Rethinking security for the age of AI
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog.
https://blogs.microsoft.com/blog/2026/07/27/rethinking-security-for-the-age-of-ai/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Enhancing AI security through global AI red teaming
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security testing, and strengthen the resilience of frontier AI systems. The post Enhancing AI security through global AI red teaming appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/27/enhancing-ai-security-through-global-ai-red-teaming/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How Hackers Are Weaponizing Hotel Wi-Fi to Steal Corporate Microsoft 365 Accounts
How the Attack Operates Threat actors are quietly hijacking hotel Wi-Fi gateways to reroute traveling executives to fake Microsoft 365 login pages, stealing corporate credentials without leaving a trace in... The post How Hackers Are Weaponizing Hotel Wi-Fi to Steal Corporate Microsoft 365 Accounts appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/how-hackers-are-weaponizing-hotel-wi-fi-to-steal-corporate-microsoft-365-accounts/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Governance Vacuum: Who Owns Present-State Proof?
Modern governance systems are built upon the principle of accountability. Responsibilities are assigned, duties are defined, authorities are delegated, and obligations are documented. Across safety, cybersecurity, infrastructure, finance, healthcare, and... The post The Governance Vacuum: Who Owns Present-State Proof? appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/the-governance-vacuum-who-owns-present-state-proof/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How a 67-Year-Old Woman Went From Romance Scam Victim To Podcast Rebel
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based travel specialist, was out around 0,000, including The post How a 67-Year-Old Woman Went From Romance Scam Victim To Podcast Rebel appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/how-a-67-year-old-woman-went-from-romance-scam-victim-to-podcast-rebel/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed
A weak random-number generator behind the Ill Bloom vulnerability has let attackers drain over million from crypto wallets. Here's how to check exposure and fix it. The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/ill-bloom-vulnerability-check/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cursor's Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months of silence from Cursor. Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/cursor-git-exe-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums region-wide, with no patch yet available. Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/shark-vacuum-vulnerability-aws-region/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution. wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/wp2shell-vulnerability-wordpress-rce/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021
A heap-based buffer overflow in 7-Zip's XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five years. CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021 on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/7-zip-vulnerability-cve-2026-14266/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ENCFORGE Ransomware Targets AI Models After Langflow RCE Exploit
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an exposed Docker socket. ENCFORGE Ransomware Targets AI Models After Langflow RCE Exploit on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/encforge-ransomware-langflow-ai-models/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft Patches It
A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack AI coding agents, plus the configuration changes to make right now. Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft Patches It on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/azure-devops-mcp-flaw-defenses/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI Moved into the Dev Workflow. Security Didn't.
AI coding tools were supposed to sit alongside the development process. Today, they’re increasingly becoming the development process. Many of these systems are also evolving from coding assistants into autonomous development agents... The post AI Moved into the Dev Workflow. Security Didn’t. appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/ai-moved-into-the-dev-workflow-security-didnt/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Ransomware Is More Disruptive And Recovery Readiness Matters More Than Ever
Ransomware continues to evolve at a rapid pace, and it is challenging the most common cybersecurity assumptions. Recent findings have revealed a shift in attacker strategy. Modern ransomware is no... The post Ransomware Is More Disruptive And Recovery Readiness Matters More Than Ever appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/ransomware-is-more-disruptive-and-recovery-readiness-matters-more-than-ever/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Frontier AI and the Vulnerability Gap in OT
The landscape of cyber defense and offense is shifting beneath our feet. Over the past few weeks, the release of “frontier” AI models has accelerated the arms race, forcing a... The post Frontier AI and the Vulnerability Gap in OT appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/frontier-ai-and-the-vulnerability-gap-in-ot/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Black Hat USA 2026 In Las Vegas: Late Registration Ends July 31
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 24, 2026 – Watch the YouTube video Black Hat USA 2026, the premier cybersecurity event of the year, returns to Mandalay Bay in Las Vegas with a re-engineered, six-day program built The post Black Hat USA 2026 In Las Vegas: Late Registration Ends July 31 appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/black-hat-usa-2026-in-las-vegas-late-registration-ends-july-31/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-16756 where the allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated "Slowloris" denial of service. Impacted versions: aws-smithy-http-server <= 0.66.4 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
https://aws.amazon.com/security/security-bulletins/rss/2026-064-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

https://www.proofpoint.com/us/newsroom/news/russian-espionage-group-exploited-zimbra-zero-day-steal-mail-and-2fa-codes
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

US and allies say Russian hackers stole emails without social engineering

https://www.proofpoint.com/us/newsroom/news/us-and-allies-say-russian-hackers-stole-emails-without-social-engineering
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The case for a cooldown: Why Dependabot now waits before issuing version updates
A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code. The post The case for a cooldown: Why Dependabot now waits before issuing version updates appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Email threat landscape: Q2 2026 trends and insights
In the second quarter of 2026, the continuing effects of Microsoft's disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. The post Email threat landscape: Q2 2026 trends and insights appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Russian Global Webmail Espionage
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
https://unit42.paloaltonetworks.com/russian-webmail-espionage/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

What Happened Between OpenAI and Hugging Face?
The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a question that is moving quickly from theory to operations: what happens when AI agents can pursue an objective with enough persistence, speed, and creativity to behave less like a tool and more like an autonomous intrusion path?According to OpenAI's disclosure, the incident began during an internal evaluation of advanced cyber capabilities using GPT-5.6 Sol and a more capable pre-release model. The evaluation was designed to test whether AI agents could pursue complex exploit paths, and OpenAI says...
https://www.rapid7.com/blog/post/ai-openai-hugging-face-what-happened
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Inside Scoop On The Insider Threat
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 23, 2026 – Listen to the podcast Jim Rutt, CISO at The Dana Foundation, a private philanthropic organization in New York City that is dedicated to advancing neuroscience that benefits society, told The post The Inside Scoop On The Insider Threat appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/the-inside-scoop-on-the-insider-threat/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

UK and partners expose Russian state-supported actors for new ‘zero-click' phishing campaign targeting Western organisations
GCHQ's National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR' cyber threat group exposed for targeted phishing campaign
https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
OverviewOn July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as improper authentication (CWE-287). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote exploitation...
https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

1-15 July 2026 Cyber Attacks Timeline Infographic
Cyber Crime dominated the first half of July 2026, driving 76.5% of all confirmed activity, with Malware the clear weapon of choice at 43.5% of attack techniques. Exploitation of public-facing applications (MITRE T1190) led initial access methods at 27.6%, while Information & Communication infrastructure bore the brunt of targeting, accounting for 32% of sector hits — well ahead of Public Administration and Financial Services.
https://www.hackmageddon.com/2026/07/23/1-15-july-2026-cyber-attacks-timeline-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

1-15 July 2026 Cyber Attacks Timeline
85 confirmed cyber incidents shaped the first half of July 2026, with cyber crime accounting for more than three-quarters of all attacks. Malware — spanning RATs, infostealers, spyware, and backdoors — was the dominant weapon, involved in 37 of 85 incidents (43.5%). Information & Communication infrastructure emerged as the hardest-hit sector, targeted in nearly 1 in 3 sector mentions.
https://www.hackmageddon.com/2026/07/23/1-15-july-2026-cyber-attacks-timeline/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Hugging Face Incident Changes the Vulnerability Equation
New details from OpenAI have changed our understanding of the breach Hugging Face disclosed last week, which marks the first reported cyberattack driven end-to-end by an autonomous AI agent.
https://www.sonatype.com/blog/the-hugging-face-incident-changes-the-vulnerability-equation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

If you pay a hacker's ransom, chances are that they'll come back for more

https://www.proofpoint.com/us/newsroom/news/if-you-pay-hackers-ransom-chances-are-theyll-come-back-more
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Real world incident response: Microsoft and AXA XL strengthen cyber resilience
Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilience appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/22/real-world-incident-response-microsoft-and-axa-xl-strengthen-cyber-resilience/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Next chapter: Restructuring GitHub's bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first on The GitHub Blog.
https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hot Cybersecurity Playlists on the Cybercrime Magazine YouTube Channel
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 22, 2026 – Watch our Videos at Cybercrime.TV CISOs and security leaders have spoken up on our hottest content and the award-winning Cybercrime Magazine YouTube Channel has been updated with new Playlists to The post Hot Cybersecurity Playlists on the Cybercrime Magazine YouTube Channel appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/hot-cybersecurity-playlists-on-the-cybercrime-magazine-youtube-channel/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Post-quantum cryptography (PQC) migration workshop report
No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
https://www.ncsc.gov.uk/blogs/post-quantum-cryptography-pqc-migration-workshop-report
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective

https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-research-finds-65-organizations-affected-ransomware-say-ai-made
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

We Wrote an Academic Paper on Conficker in 2026
And it’s over 16,000 words. While the rest of the cybersecurity world moves on with AI and next generation technologies, the OT cybersecurity community is oft left behind, dealing with increasingly unique legacy challenges and tech debt. One of the biggest issues we have had to start tackling is the discovery of deep, embedded commodity […]
https://tisiphone.net/2026/07/21/we-wrote-an-academic-paper-on-conficker-in-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Model Did Exactly What We Asked
An AI "went rogue" last week, just like out of a science fiction movie. Not because it turned on us, but to achieve its defined objective. Just as we were planning our CISO huddle on the Hugging Face attacks, a jaw dropping post from OpenAI was released that completely reframed the entire situation. Hold on people, because this one sure sounds like a story from a SciFi movie.   What actually happened On July 21, OpenAI and Hugging Face jointly disclosed the details behind an i...
https://cloudsecurityalliance.org/articles/the-model-did-exactly-what-we-asked
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Beyond Human Identity: A Runtime Governance Model for Autonomous AI Agents in the Enterprise Cloud
  Introduction Enterprise identity management was built around people. Identity and Access Management (IAM) platforms started with employees, contractors, and partners, then stretched to cover service accounts, APIs, and machine identities. Every one of those extensions kept a quiet assumption intact: the identity itself does not make decisions. AI agents break that assumption. Organizations are deploying coding assistants, customer support agents, security copilots, and workflo...
https://cloudsecurityalliance.org/articles/beyond-human-identity-a-runtime-governance-model-for-autonomous-ai-agents-in-the-enterprise-cloud
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Windows Privilege Escalation: SeRestorePrivilege
Overview SeRestorePrivilege is a Windows special privilege that allows its holder to restore files and directories, effectively bypassing discretionary access controls on the file system. The post Windows Privilege Escalation: SeRestorePrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-serestoreprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Security Teams Do Not Need More AI Hype. They Need AI-Ready Workflows.
AI Delivers Value Only When It’s Built Into the Security Workflow – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Jul. 21, 2026 Every security leader has heard the promise by now: AI will transform The post Security Teams Do Not Need More AI Hype. They Need AI-Ready Workflows. appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/security-teams-do-not-need-more-ai-hype-they-need-ai-ready-workflows/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A new extortion cocktail: office printers, small ransoms, and BitLocker
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

What Would A Ransomware Attack Cost Your Organization?
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 21, 2026 – Read the full story in StationX Nathan House, founder and CEO at StationX, one of the UK’s first cybersecurity companies founded in 1999 and trusted by more than The post What Would A Ransomware Attack Cost Your Organization? appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/what-would-a-ransomware-attack-cost-your-organization/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Hidden Privilege of Automation Platforms
Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of users, and hold sensitive credentials. That puts it in the same […]
https://blog.compass-security.com/2026/07/the-hidden-privilege-of-automation-platforms/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Suno - 55,282,226 breached accounts
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".
https://haveibeenpwned.com/Breach/Suno
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

What Is Grounding? Why AI Coding Assistants Need Better Intelligence
Grounding AI coding assistants in trusted software supply chain intelligence is essential as developers increasingly rely on AI to generate code, recommend dependencies, and accelerate software delivery.
https://www.sonatype.com/blog/what-is-grounding-why-ai-coding-assistants-need-better-intelligence
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The 25 Biggest Cyber Attacks In History
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 20, 2026 – Read the full story in Yahoo! Finance According to Cybersecurity Ventures, global cybercrime costs were projected to reach .5 trillion annually by 2025, up from trillion in The post The 25 Biggest Cyber Attacks In History appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/the-25-biggest-cyber-attacks-in-history/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Paidwork - 23,272,765 breached accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.
https://haveibeenpwned.com/Breach/Paidwork
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/17/microsoft-at-black-hat-usa-2026-defending-trust-in-the-age-of-ai-and-supply-chain-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Sophos Fusion: A Complete AI-Native Cyber Defense System
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 17, 2026 – Read the full story from Sophos With around 359 million businesses in the world, fewer than 35,000 have a CISO or security leader in place, according to the 2026 The post Sophos Fusion: A Complete AI-Native Cyber Defense System appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/sophos-fusion-a-complete-ai-native-cyber-defense-system/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.
https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Joomla SP Page Builder RCE
What is the Vulnerability? FortiGuard telemetry shows continued exploitation attempts targeting vulnerable Joomla SP Page Builder installations. CVE-2026-48908 is a critical unauthenticated remote code execution (RCE) vulnerability affecting the SP Page Builder extension for Joomla. The flaw allows attackers to upload arbitrary PHP files through the custom icon upload functionality without authentication, potentially enabling remote code execution and full server compromise. Public proof-of-concept (PoC) exploit code is available, and active exploitation has been observed. The sustained increase in weekly exploitation activity indicates ongoing automated scanning campaigns targeting Internet-facing Joomla servers, highlighting...
https://fortiguard.fortinet.com/threat-signal-report/6489
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ACR Stealer: Two observed intrusion chains amid increased threat activity
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. The post ACR Stealer: Two observed intrusion chains amid increased threat activity appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.
https://unit42.paloaltonetworks.com/ai-insights-incident-response-report/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
Bulletin ID: 2026-057-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 12:00 PM PDT Description: jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. We identified CVE-2026-15895, an issue where specially formatted command line arguments can be used to execute shell commands via this tool. Impacted versions: < 1.131.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
https://aws.amazon.com/security/security-bulletins/rss/2026-057-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Least privilege for AI agents: Identity, access, and tool binding
As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

H1 2026 Cyber Attacks Statistics Infographic
Last Updated on July 16, 2026 Bundled Page This page requires JavaScript to display. H1 Unpacking…
https://www.hackmageddon.com/2026/07/16/h1-2026-cyber-attacks-statistics-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

H1 2026 Cyber Attacks Statistics
In H1 I recorded 1,071 confirmed cyber incidents. Financially motivated Cyber Crime drove nearly 7 in 10 attacks, malware remained the top weapon (40.5% of attack-vector entries), and exploitation of public-facing applications was the leading initial access technique (23.7%). Cyber Espionage accounted for roughly 1 in 5 incidents, with the Information & Communication sector bearing the heaviest targeting (26.1% of classified events).
https://www.hackmageddon.com/2026/07/16/h1-2026-cyber-attacks-statistics/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

HelloNet campaign: new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
https://securelist.com/tr/hellonet-vipnet/120700/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.
https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Securing Agent Identities: 8 Risks Every CISO Must Address
Enterprises have spent two decades building real discipline around human identity: provisioning, least privilege, access reviews, clean deprovisioning. AI agents arrived faster than that discipline could be extended to them, so a population of powerful new identities is now operating ahead of the controls meant to govern it. An agent acts within the identity it is given, and that identity is often over-provisioned from the start, carrying broad, inherited, or standing access well beyond ...
https://cloudsecurityalliance.org/articles/securing-agent-identities-8-risks-every-ciso-must-address
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How to Request Security Budget from Your CFO and Exec Teams
Security and finance teams both care deeply about risk, but they define and measure it differently. Security leaders often lead with controls, frameworks, and technical severity, while finance executives focus on outcomes like revenue, predictability, and cost containment.  But when security conversations don't clearly connect to financial impact, budget requests can stall. Framing risk in a way that aligns with executive priorities can help security leaders bridge the cross-departm...
https://cloudsecurityalliance.org/articles/how-to-request-security-budget-from-your-cfo-and-exec-teams
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool
Bulletin ID: 2026-056-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 11:30 AM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the elasticsearch_memory tool. The tool exposed its connection parameters (es_url, cloud_id, api_key) as fields the large language model (LLM) could control through the tool schema. When a caller omitted the api_key parameter, the tool fell back to the operator's ELASTICSEARCH_API_KEY environment variable and sent it to whichever host the LLM specified. A crafted...
https://aws.amazon.com/security/security-bulletins/rss/2026-056-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Windows Privilege Escalation: SeTcbPrivilege
Overview SeTcbPrivilege — formally “Act as part of the operating system” — is one of the most powerful Windows privileges in existence. It grants the The post Windows Privilege Escalation: SeTcbPrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-setcbprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Helping small businesses with free, hands-on cyber consultancy
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
https://www.ncsc.gov.uk/blogs/helping-small-businesses-with-free-hands-on-cyber-consultancy
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.
https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OkoBot: new sophisticated malware framework targets cryptocurrency users
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fluke - 821,100 breached accounts
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.
https://haveibeenpwned.com/Breach/Fluke
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Open Source, Open Infrastructure, and the Space Between
When good infrastructure works, most people do not think about it. They might even forget. But when it stops working, everyone notices.
https://www.sonatype.com/blog/open-source-open-infrastructure-and-the-space-between
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Goose Creek - 6,574,121 breached accounts
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.
https://haveibeenpwned.com/Breach/GooseCreek
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI
The Cloud Security Alliance (CSA) recently announced the release of the AI Controls Matrix (AICM) v1.1, a significant update to our comprehensive framework for secure and trustworthy AI systems. Building on the strong foundation established with the original AICM release in 2025, this update expands our control coverage, includes a dedicated Model Security domain, AI-specific security controls, and delivers complete mappings to the world's major AI governance frameworks, includi...
https://cloudsecurityalliance.org/articles/ai-controls-matrix-v1-1-strengthening-the-foundation-for-trustworthy-ai
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Q2 2026 Cyber Attacks Statistics
Q2 2026 brought 578 recorded cyber incidents worldwide, with financially-motivated cyber crime accounting for over 71% of the total. Malware remained the attacker's weapon of choice, exploiting public-facing applications as the leading entry point. Information & Communication stood out as the hardest-hit sector.
https://www.hackmageddon.com/2026/07/14/q2-2026-cyber-attacks-statistics/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

https://www.proofpoint.com/us/newsroom/news/oauth-client-id-spoofing-lets-attackers-validate-stolen-microsoft-entra-credentials
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Q2 2026 Cyber Attacks Statistics Infographic
Last Updated on July 14, 2026 Cyber Attacks Statistics — Q2 2026 Q2 Threat Intelligence Briefing Cyber AttacksQ2 2026 543 confirmed incidents between 1 April and 30 June 2026. Financially motivated Cyber Crime drove over 7 in 10 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure absorbed the heaviest targeting. 0 […]
https://www.hackmageddon.com/2026/07/14/q2-2026-cyber-attacks-statistics-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Buffer overread in authd and wad daemon
CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-154
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cross-Site Scripting in Domain parameter
CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-149
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Header injection in Web Filter warning page
CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-152
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Header injection in captive portal authentication form
CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-153
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Missed certificate verification in AD Connector communication with FortiClient EMS
CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-147
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Out of bounds read in GUI
CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-146
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Path traversal in CLI command allows deletion of root file system
CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-151
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

SSL-VPN Reflected XSS
CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-150
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Stack Buffer Overflow in Log Report
CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-148
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Supers override fails to properly override supervisor address
CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-155
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Unauthenticated VNC access exposed on all interfaces
CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-145
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Request for Comments: CARE and Maven Central
Update, July 23, 2026: We've received a lot of thoughtful feedback on Publisher Pro, and it's already shaping the program.We're moving enforcement of publishing limits to October 1, 2026, while we review requests, analyze publishing patterns, and refine the model. We're also separating publishing limits from commercial pricing. Operational limits remain useful review signals, but they won't be the primary basis for pricing.Our goal hasn't changed: keep Maven Central sustainable by reducing abuse and asking commercial organizations that benefit from the infrastructure to help support it, without creating unnecessary friction for legitimate open source projects.Thank you for the feedback so far, and please keep it coming.
https://www.sonatype.com/blog/request-for-comments-care-and-maven-central
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Lessons Learned from CISA's Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.
https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Hackers find a new trick to collect Microsoft Entra user data without raising red flags

https://www.proofpoint.com/us/newsroom/news/hackers-find-new-trick-collect-microsoft-entra-user-data-without-raising-red-flags
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Windows Privilege Escalation: SeTakeOwnershipPrivilege
Overview This article demonstrates how a single delegated user right — SeTakeOwnershipPrivilege — can be weaponised to elevate a standard domain user to full SYSTEM The post Windows Privilege Escalation: SeTakeOwnershipPrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-setakeownershipprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

UK and Allies urge critical sectors to improve defences against Russian intelligence targeting
New advisory highlights Russian state cyber actors' global exploitation of poorly configured routers
https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Glendale Community College - 793,925 breached accounts
In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information".
https://haveibeenpwned.com/Breach/GlendaleCommunityCollege
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.
https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Implementing CCM: Universal Endpoint Management Controls
The Cloud Controls Matrix (CCM) is a framework of controls that are essential for cloud computing security. Created by CSA, the CCM aligns with CSA best practices. You can use CCM to assess and guide the security of any cloud service. CCM also provides guidance on which actors within the cloud supply chain should implement which controls. Both cloud service customers (CSCs) and cloud service providers (CSPs) use CCM in many ways. CCM contains 197 controls structured into 17 domain...
https://cloudsecurityalliance.org/articles/implementing-ccm-universal-endpoint-management-controls
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

When "Who Are You?' Is No Longer Enough: The Case for Intent-Based Access Control in the Age of AI Agents
It keeps coming back to a conversation I had about six months ago. I sat with the CISO of a fortune 50 retail organization to review an incident that had kept the security team up for two straight nights. No credentials were stolen. No malware was deployed. No firewall rule was broken. Yet the critical reconciliation process had gone seriously wrong, wrong enough to draw regulatory scrutiny. The culprit? An AI-powered automation agent that had been granted, quite legitimately, acc...
https://cloudsecurityalliance.org/articles/when-who-are-you-is-no-longer-enough-the-case-for-intent-based-access-control-in-the-age-of-ai-agents
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How GitHub gave every repository a durable owner
GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here's how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed. The post How GitHub gave every repository a durable owner appeared first on The GitHub Blog.
https://github.blog/security/application-security/how-github-gave-every-repository-a-durable-owner/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Q2 2026 Open Source Malware Index
TL;DR At the end of Q2 2026, Sonatype Research reached 1.8 million malicious packages logged. In Q2, npm accounted for 96.6% of malicious package counts, with repository abuse and trojan-class activity showing how attackers continue to exploit high-trust, high-automation ecosystems. The quarter's defining theme was trust under pressure. Large-scale repository abuse campaigns, worm-like malware, dependency confusion, and maintainer compromises turned trusted software distribution channels into attack paths. Q2 showed attackers evolving beyond obvious malicious packages to target trusted developer workflows through campaigns like Shai-Hulud Miasma, CanisterSprawl, Atomic Arch, malicious PyTorch Lightning releases, dependency confusion, and maintainer/package hijacking....
https://www.sonatype.com/blog/q2-2026-open-source-malware-index-attackers-abuse-developer-trust
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cyber Essentials Pathways: from proof of concept to cyber confidence
An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme. 
https://www.ncsc.gov.uk/blogs/cyber-essentials-pathways-from-proof-of-concept-to-cyber-confidence
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

June 2026 Cyber Attacks Statistics
June 2026 saw 176 confirmed cyber attacks. Cyber Crime drove three in four incidents, Malware remained attackers' weapon of choice, and Information & Communication infrastructure took the heaviest hit. This visual breakdown charts the month's motivations, attack vectors, initial access techniques, and hardest-hit sectors.
https://www.hackmageddon.com/2026/07/09/june-2026-cyber-attacks-statistics/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

June 2026 Cyber Attacks Statistics Infographic
June 2026 saw 176 confirmed cyber attacks. Cyber Crime drove three in four incidents, Malware remained attackers' weapon of choice, and Information & Communication infrastructure took the heaviest hit. This visual breakdown charts the month's motivations, attack vectors, initial access techniques, and hardest-hit sectors.
https://www.hackmageddon.com/2026/07/09/june-2026-cyber-attacks-statistics-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Ubiquiti UniFi OS RCE
What is the Vulnerability? Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with root privileges. The vulnerabilities include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which together bypass authentication, access protected resources, and execute arbitrary operating system commands. The vulnerabilities impact UniFi OS deployments used to manage enterprise networking infrastructure, including gateways, network controllers, video surveillance, and access control systems. Researchers have publicly demonstrated the exploit chain, and the vulnerabilities have been confirmed as actively exploited in the wild. Organizations should...
https://fortiguard.fortinet.com/threat-signal-report/6475
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Why M2M Authentication and API Security Must Work Together
TL;DR: Non-human identities are calling APIs across cloud environments every day. Securing those interactions requires two layers of control: Machine-to-machine authentication to prove the caller is legitimate API security to limit what that caller can access or do Organizations are moving toward cloud-native automation and autonomous AI agents. Static API keys, shared service accounts, and long-lived secrets create unnecessary risk. Security teams should prioritize workload id...
https://cloudsecurityalliance.org/articles/why-m2m-authentication-and-api-security-must-work-together
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Windows Privilege Escalation: SeDebugPrivilege
Overview This article delivers an end-to-end walkthrough of how a single delegated user right — SeDebugPrivilege — collapses the security boundary between a standard domain The post Windows Privilege Escalation: SeDebugPrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-sedebugprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Wireless Pentesting with Claude Using the Aircrack MCP Server
Overview Wireless networks remain one of the most exposed and frequently overlooked attack surfaces across enterprise and consumer environments. This article introduces the Aircrack-ng MCP The post Wireless Pentesting with Claude Using the Aircrack MCP Server appeared first on Hacking Articles.
https://www.hackingarticles.in/wireless-pentesting-with-claude-using-the-aircrack-mcp-server/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Suspected Chinese snoops caught breaking into universities' Roundcube mailservers

https://www.proofpoint.com/us/newsroom/news/suspected-chinese-snoops-caught-breaking-universities-roundcube-mailservers
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ESET Threat Report H1 2026
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.
https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

16-30 June 2026 Cyber Attacks Timeline Infographic
Last Updated on July 7, 2026 16–30 June 2026 — Cyber Attacks Infographic | HACKMAGEDDON Cyber Threat Intelligence · HACKMAGEDDON 16–30 June 2026Cyber Attacks Infographic 96 confirmed incidents across the second half of June 2026. Cyber Crime drove roughly 8 in 10 attacks, Malware remained the dominant weapon, and Information & Communication infrastructure was the […]
https://www.hackmageddon.com/2026/07/07/16-30-june-2026-cyber-attacks-timeline-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cyber Shield: The path to an agentic AI future for cyber defence
Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability
https://www.ncsc.gov.uk/blogs/cyber-shield-the-path-to-an-agentic-ai-future-for-cyber-defence
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Threat landscape for industrial automation systems. Q1 2026
This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.
https://securelist.com/industrial-threat-report-q1-2026/120643/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

16-30 June 2026 Cyber Attacks Timeline
Between 16–30 June 2026, 96 confirmed cyber incidents shaped the threat landscape — Cyber Crime drove roughly 8 in 10 attacks, malware remained the top weapon, and Information & Communication infrastructure took the hardest hit.
https://www.hackmageddon.com/2026/07/07/16-30-june-2026-cyber-attacks-timeline/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cyber Resilience Act – Part II
In this second part, we demonstrate how a Cyber Resilience Act (CRA) assessment is performed in practice. Using a low-cost IP camera as an example, we show how a product is classified, how threats are modelled, how hardware and firmware are analysed, and how compliance gaps against IEC 62443-4-2 can be identified. You may want […]
https://blog.compass-security.com/2026/07/cyber-resilience-act-part-ii/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

PCI DSS 6.4.3 and 11.6.1: A Deep Dive into Payment Page Security and Integrity Requirements
For organizations that process payment card data online, the payment page has become one of the most targeted points of attack. Modern e-commerce environments rely heavily on third-party scripts, embedded payment forms, and dynamic content—all of which expand the attack surface in ways that can be difficult to monitor. At the same time, client-side attacks—particularly e-skimming and malicious script injection—have surged. Attackers are no longer trying to break into backend systems fi...
https://cloudsecurityalliance.org/articles/pci-dss-6-4-3-and-11-6-1-a-deep-dive-into-payment-page-security-and-integrity-requirements
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI Is Forcing a New Open Source Security Model
Open source security has spent years getting better at finding problems. Scanning improved, as did intelligence, disclosure and prioritization. All of these still matter, but they are not enough.
https://www.sonatype.com/blog/ai-is-forcing-a-new-open-source-security-model
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

When checking the URL isn't enough: a Device Code Phishing attack via a Microsoft website
The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.
https://securelist.com/microsoft-device-code-phishing-attack/120350/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Ivanti Sentry Pre-Authentication RCE
What is the Vulnerability? FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and proof-of-concept (PoC) exploit code. CVE-2026-10520 is a critical vulnerability affecting Ivanti Sentry that allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges. The flaw stems from improper handling of internal configuration commands exposed through an externally accessible API, enabling complete device compromise without valid credentials. Shortly after disclosure, watchTowr published a detailed technical analysis and public PoC, significantly lowering the barrier to exploitation and...
https://fortiguard.fortinet.com/threat-signal-report/6472
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Moody Bible Institute - 2,303,416 breached accounts
In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice, Moody advised that they had "engaged both internal and external cybersecurity experts to thoroughly investigate the matter".
https://haveibeenpwned.com/Breach/MoodyBibleInstitute
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cyber readiness for SMBs: Getting the basics right
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How We Added WebAuthn to a Browser-Based RDP Client
A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42.
https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.
https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How GitHub used secret scanning to reach inbox zero
GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here's how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months. The post How GitHub used secret scanning to reach inbox zero appeared first on The GitHub Blog.
https://github.blog/security/application-security/how-github-used-secret-scanning-to-reach-inbox-zero/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-13769 – Insecure file permissions in AWS CLI
Bulletin ID: 2026-049-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 11:45 AM PDT Description: The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other local users on the same host to read credentials. Impacted versions: <=1.44.77 (v1) AND <=2.34.28 (v2) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
https://aws.amazon.com/security/security-bulletins/rss/2026-049-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.5.3 and 1.4.5 security patch versions published
Today, we are publishing the 1.5.3 and 1.4.5 security patch versions.  The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub with both Alpine and Debian containers. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version. 1.5.3 ClamAV 1.5.3 is a patch release with the following fixes:CVE-2026-20217: Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner.This issue affects ClamAV 1.5.2, 1.4.4, and all prior versions as far back as 2005. The fix is included in 1.5.3 and 1.4.5.Thank you to Atuin - Automated Vulnerability Discovery Engine, Tianchu...
https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

6 security settings every GitHub maintainer should enable this week
These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before. The post 6 security settings every GitHub maintainer should enable this week appeared first on The GitHub Blog.
https://github.blog/security/6-security-settings-every-github-maintainer-should-enable-this-week/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams

https://www.proofpoint.com/us/newsroom/news/new-cargo-theft-surge-lobster-heists-bourbon-warehouse-scams
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vulnerability Prioritization Is Missing the AI-Era Point
Modern software development relies heavily on third-party open source components, which are now being utilized at a staggering scale. This scale has led to real innovation around the world as development teams are able to focus on shipping, deploying and delivering value by standing on the shoulders of the open source contributors. With this benefit, comes the cost of risk and pressure on Application Security teams who face a constant flood of threats that even the most experienced organizations struggle to manage effectively. When faced with an ever growing task list and backlog of work, effective teams take to the time-tested method of prioritize the effort so the most important work is done first.
https://www.sonatype.com/blog/focusing-on-vulnerability-prioritization-is-missing-the-ai-era-point
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Building more resilient CNI: what industry pen testers told us
Pen testers suggest what organisations can do to make their job more difficult.
https://www.ncsc.gov.uk/blogs/building-more-resilient-cni-what-industry-pen-testers-told-us
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.
https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Defending the Authentication Flow: Device Code Phishing with Selena Larson

https://www.proofpoint.com/us/newsroom/news/defending-authentication-flow-device-code-phishing-selena-larson
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

This month in security with Tony Anscombe – June 2026 edition
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-june-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Hidden National Security Threat Inside AI-Driven Software
AI is putting enormous pressure on federal mission stacks, and agencies need security processes that keep pace with the expanding attack surface. It has practically rebuilt how teams write software, detect threats, analyze intelligence, automate workflows, and support mission decisions. For defense organizations, especially those responsible for intelligence, electronic warfare, cyber, and software-enabled systems, AI is now foundational to operations.
https://www.sonatype.com/blog/the-hidden-national-security-threat-inside-ai-driven-software
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Active Directory Forest Trust Abuse: Child-to-Root Domain Escalation
Overview This article walks through a complete forest compromise of an Active Directory environment, escalating from a single child domain all the way to the The post Active Directory Forest Trust Abuse: Child-to-Root Domain Escalation appeared first on Hacking Articles.
https://www.hackingarticles.in/active-directory-forest-trust-abuse-child-to-root-domain-escalation/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Verifiable Digital Credential Presentment
This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared the underlying credential formats (ISO/IEC “mdoc” vs. W3C Verifiable Credentials). In this post, we turn to the other side of the story: presentation; that is, how a holder shows their VDC to a verifier at runtime in both in-person and online contexts. We'll again explore the mobile driver's license (mDL) use case, consider the differences between ISO/IEC
https://www.nist.gov/blogs/cybersecurity-insights/verifiable-digital-credential-presentment
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Splunk Enterprise Authentication Bypass Vulnerability
What is the Attack? A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems from missing authentication on a PostgreSQL sidecar service endpoint, allowing an unauthenticated attacker to create or truncate arbitrary files on a vulnerable server. Security researchers have demonstrated that the vulnerability can be leveraged toward pre-authentication remote code execution (RCE) under certain conditions, and active exploitation has been confirmed. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, making it a high-priority patching target for organizations running exposed Splunk Enterprise instances. ...
https://fortiguard.fortinet.com/threat-signal-report/6470
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763, which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure...
https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when vulnerability volume breaks records appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Inside the inbox: Why cybercriminals want to break into your email account
Your inbox is an identity system all of its own: whoever owns it may own a lot more
https://www.welivesecurity.com/en/cybersecurity/inside-inbox-cybercriminals-want-break-email-account/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Sysco - 2,691,852 breached accounts
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.
https://haveibeenpwned.com/Breach/Sysco
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Threat Brief: Mitigating Large-Scale Credential Attacks
We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42.
https://unit42.paloaltonetworks.com/large-scale-credential-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

SMB cyber readiness: the road to resilience starts here
Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
https://www.welivesecurity.com/en/business-security/smb-cyber-readiness-road-resilience-starts-here/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

American Tower - 216,601 breached accounts
In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.
https://haveibeenpwned.com/Breach/AmericanTower
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cyber Resilience Act – Part I
The Cyber Resilience Act (CRA) is a regulation introduced by the European Union to strengthen cybersecurity requirements for products with digital elements.In simple terms, the CRA sets mandatory cybersecurity rules for hardware and software sold in the EU. This includes everything from connected devices (IoT) to operating systems and even stand-alone software. Very important, this […]
https://blog.compass-security.com/2026/06/cyber-resilience-act-part-i/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.
https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
ESET Research analyzes Gamaredon's new toolset and the group's growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data
https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Oracle PeopleSoft Zero-Day
What is the Attack? Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters (tracked as UNC6240) targeting Oracle PeopleSoft environments. The attackers exploited a previously unknown remote code execution vulnerability, CVE-2026-35273, before Oracle released an advisory and patches, making this a true zero-day attack. The campaign primarily targeted higher education institutions, with approximately 68% of identified victims belonging to the education sector. Organizations running internet-accessible Oracle PeopleSoft Environment Management components are at highest risk. Successful exploitation enables unauthenticated remote code execution,...
https://fortiguard.fortinet.com/threat-signal-report/6468
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
What is the Vulnerability? Cisco has disclosed a critical security vulnerability, CVE-2026-20245, affecting Cisco Catalyst SD-WAN Manager and confirmed that it is being actively exploited in the wild. The vulnerability resides in the platform's command-line interface (CLI) and allows an authenticated attacker with netadmin privileges to execute arbitrary commands as root on the underlying operating system. According to Cisco, successful exploitation has been observed in real-world attacks and has resulted in unauthorized configuration changes being pushed to managed SD-WAN edge devices. At the time of disclosure, Cisco had not released a software fix or workaround and instead provided indicators of compromise and investigation...
https://fortiguard.fortinet.com/threat-signal-report/6456
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Madison Square Garden Sports - 9,796,738 breached accounts
In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign. The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.
https://haveibeenpwned.com/Breach/MadisonSquareGardenSports
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights
https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Advancing Product Security: New IoT Guidance and New Engagement
It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn't hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational decisions…so we remain focused on helping stakeholders apply security guidance in ways that are practical and actionable. What's Been Happening Lately? An initial public draft (IPD) of NIST SP 800-213 Revision 1, IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements is out now for your review and
https://www.nist.gov/blogs/cybersecurity-insights/advancing-product-security-new-iot-guidance-and-new-engagement
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.
https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins
Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT Description: Language Servers for AWS provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio). We identified CVE-2026-12957, an improper trust boundary enforcement issue in Language Servers for AWS before version 1.65.0. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted. We identified CVE-2026-12958, a missing symlink-validation issue in Language Servers for AWS before version 1.69.0. This...
https://aws.amazon.com/security/security-bulletins/rss/2026-047-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
A Bitdefender Labs investigation identified more than 55 fake-shop campaigns targeting consumers across 12 European countries between March and May 2026. The campaigns mimicked some of the world's most recognizable brands, including Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN.
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The AI shift in cyber risk: why leaders must act now
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense

https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-joins-openai-daybreak-cyber-partner-program-advance-responsible
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI-Powered Active Directory Pentesting with Claude, HexStrike AI & NetExec
Overview This guide walks through a complete Active Directory engagement in a controlled lab, driven end-to-end by plain-English prompts to Claude Desktop. We wire the The post AI-Powered Active Directory Pentesting with Claude, HexStrike AI & NetExec appeared first on Hacking Articles.
https://www.hackingarticles.in/ai-powered-active-directory-pentesting-with-claude-hexstrike-ai-netexec/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

JCPenney - 368,418 breached accounts
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.
https://haveibeenpwned.com/Breach/JCPenney
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

BloodHound MCP: Automating Active Directory Analysis with AI
Overview An end-to-end, AI-assisted Active Directory assessment connecting the BloodHound Community Edition graph to Claude Desktop through the Model Context Protocol (MCP): install the bloodhound_mcp The post BloodHound MCP: Automating Active Directory Analysis with AI appeared first on Hacking Articles.
https://www.hackingarticles.in/bloodhound-mcp-automating-active-directory-analysis-with-ai/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Ralph Lauren - 139,903 breached accounts
In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.
https://haveibeenpwned.com/Breach/RalphLauren
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

‘Popa' Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].
https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The 'vibe coding spectrum' approach to AI-assisted software development
Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding' accordingly.
https://www.ncsc.gov.uk/blogs/the-vibe-coding-spectrum-approach-to-ai-assisted-software-development
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Killing me gently: Inside Gentlemen's EDR killer framework
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A Detailed Guide on Villain C2 Framework
Overview Villain is an open-source command-and-control (C2) framework developed by t3l3machus that turns a single operator console into a full collaborative attack platform. It generates The post A Detailed Guide on Villain C2 Framework appeared first on Hacking Articles.
https://www.hackingarticles.in/a-detailed-guide-on-villain-c2-framework/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain
 
https://www.legitsecurity.com/blog/github-locks-down-npm-what-the-new-install-defaults-mean-for-your-supply-chain
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Protecting legacy OT systems against modern cyberthreats
Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.
https://www.welivesecurity.com/en/critical-infrastructure/protecting-legacy-ot-systems-modern-threats/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

npm Supply Chain Cryptocurrency Malware
What is the Attack? Researchers have identified a large-scale software supply chain campaign targeting the npm ecosystem, leveraging malicious JavaScript packages to distribute a multi-stage cryptocurrency-focused malware framework. The campaign affected numerous npm packages that collectively accumulated more than 2.7 million downloads, significantly increasing the potential victim pool among developers, software organizations, and CI/CD environments. The malware is designed to steal cryptocurrency wallet data, harvest credentials, exfiltrate sensitive information, and deploy additional payloads on compromised systems. The campaign highlights the growing risk posed by software supply chain attacks, where trusted open-source...
https://fortiguard.fortinet.com/threat-signal-report/6465
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Agentic AppSec: closing the remediation gap and automating application security
Application security has spent a decade getting brilliant at half of its job. This is about automating the other half – starting with the fix, and not stopping there.
https://www.legitsecurity.com/blog/agentic-appsec-closing-the-remediation-gap-and-automating-the-rest-of-application-security
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

FishMonger's arsenal upgraded: SprySOCKS for Windows
ESET researchers have discovered SprySOCKS for Windows, FishMonger's backdoor weaponizing a kernel driver for advanced stealthiness
https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Government Just Made Our Case: Stop Fixing Everything, Fix What Matters.
CISA made risk-based prioritization federal policy. That's the problem we've been working on for years.
https://www.legitsecurity.com/blog/the-government-just-made-our-case-stop-fixing-everything-fix-what-matters
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

EvilTokens: A phishing attack that doesn't steal your password
A phishing kit subverting Microsoft's legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Automated Penetration Testing with Claude AI
Overview This article demonstrates a complete, end-to-end penetration test driven almost entirely through natural language. By connecting Claude Desktop to a Model Context Protocol (MCP) The post Automated Penetration Testing with Claude AI appeared first on Hacking Articles.
https://www.hackingarticles.in/automating-penetration-testing-with-claude-ai/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Drupal Core CVE-2026-9082 Active Exploitation Confirmed Within Days of Disclosure
Sensor Intel Series: June 2026 CVE Trends
https://www.f5.com/labs/articles/drupal-core-cve-2026-9082-active-exploitation-confirmed-within-days-of-disclosure
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Making secret scanning more trustworthy: Reducing false positives at scale
Alerts are more trustworthy and actionable when noise is reduced. See how we improved the verification step with context-aware LLM reasoning. The post Making secret scanning more trustworthy: Reducing false positives at scale appeared first on The GitHub Blog.
https://github.blog/security/making-secret-scanning-more-trustworthy-reducing-false-positives-at-scale/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass
What is the Vulnerability? CVE-2026-0257 is a high-severity authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS and certain Prisma Access deployments. Successful exploitation allows an unauthenticated remote attacker to bypass security controls and establish unauthorized VPN connections without valid credentials. Palo Alto Networks, Unit 42, Rapid7, and other security researchers have confirmed active exploitation in the wild, prompting inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog. The vulnerability impacts deployments that use GlobalProtect authentication override cookies in combination with specific certificate configurations. Threat...
https://fortiguard.fortinet.com/threat-signal-report/6461
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fable 5 Is Here. The AppSec Problem Hasn't Changed.
 
https://www.legitsecurity.com/blog/fable-5-is-here-the-appsec-problem-hasnt-changed
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Who Runs the Ransomware Group ‘The Gentlemen?'
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A Record-Breaking Patch Tuesday for June 2026
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Entra Agent ID from a Security Perspective
AI agents in your Entra ID tenant? They come with new identities, permissions, and fresh attack paths. Christian Feuchter breaks down Entra Agent ID security, security-relevant capabilities, control paths, abuse scenarios, and how to review your exposure with EntraFalcon.
https://blog.compass-security.com/2026/06/entra-agent-id-from-a-security-perspective/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Ongoing updates on Copy.fail and variants
Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 10:00 PM PDT This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the copy.fail or DirtyFrag class of issues - a set of privilege escalation issues affecting the Linux Kernel. We will update this bulletin as more information becomes available. Please see below for current patching timelines for affected services related to the Copy.fail kernel issue and all its variants. AWS recommends that customers apply all updates addressing these issues as soon as they are available. See more details at Security Bulletin (ID: 2026-030-AWS).
https://aws.amazon.com/security/security-bulletins/rss/2026-030-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)
Bulletin ID: 2026-005-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/02 14:30 PM PST Description: AWS-LC is an open-source, general-purpose cryptographic library. We identified three distinct issues: - CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. - CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification in AWS-LC Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. - CVE-2026-3338: PKCS7_verify...
https://aws.amazon.com/security/security-bulletins/rss/2026-005-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Issues with AWS Research and Engineering Studio (RES)
Bulletin ID: 2026-014-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/06 14:00 PM PDT Description: Research and Engineering Studio (RES) on AWS is an open source, web portal design for administrators to create and manage secure cloud-based research and engineering environments. We have identified the following issues with the AWS Research and Engineering Studio (RES). CVE-2026-5707: Unsanitized input in an OS Command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. CVE-2026-5708: Improper control of user-modifiable attributes in the session...
https://aws.amazon.com/security/security-bulletins/rss/2026-014-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer Underflow
Bulletin ID: 2026-021-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:00 PM PDT Description: FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. - CVE-2026-7422: Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own registered endpoints. - CVE-2026-7423: Integer underflow in the ICMP and ICMPv6 echo reply handlers allows an adjacent network device to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the...
https://aws.amazon.com/security/security-bulletins/rss/2026-021-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Security Findings in SageMaker Python SDK
Bulletin ID: 2026-004-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/02/02 14:30 PM PST Description: CVE-2026-1777 - Exposed HMAC in SageMaker Python SDK SageMaker Python SDK's remote functions feature uses a per‑job HMAC key to protect the integrity of serialized functions, arguments, and results stored in S3. We identified an issue where the HMAC secret key is stored in environment variables and disclosed via the DescribeTrainingJob API. This allows third parties with DescribeTrainingJob permissions to extract the key, forge cloud-pickled payloads with valid HMACs, and overwrite S3 objects. CVE-2026-1778 - Insecure TLS Configuration in SageMaker Python SDK SageMaker Python SDK is an open source library for training and deploying machine learning...
https://aws.amazon.com/security/security-bulletins/rss/2026-004-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Issue with Amazon SageMaker Python SDK - Model artifact integrity verification issues (CVE-2026-8596 & CVE-2026-8597)
Bulletin ID: 2026-031-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/14/2026 13:00 PM PDT Description: Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. The ModelBuilder component simplifies model deployment by automating model artifact preparation and SageMaker model creation. We identified two issues affecting the model artifact integrity verification mechanism in the ModelBuilder/Serve component: - CVE-2026-8596: We identified a cleartext storage of sensitive information issue in the ModelBuilder/Serve component. When building models using ModelBuilder, the SDK stored an HMAC signing key as a container environment variable (SAGEMAKER_SERVE_SECRET_KEY). This key was returned in...
https://aws.amazon.com/security/security-bulletins/rss/2026-031-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ComoDoS - Exploiting a Remote Kernel Vulnerability in Comodo Internet Security
Sometimes firewall stops attackers, sometimes attackers stop firewall. analyzing a zero-day vulnerability in Comodo Internet Security's Firewall driver.
https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Inside APAC's malvertising ecosystem: How scams spread through social media ads
Bitdefender Labs has uncovered a large-scale malvertising ecosystem operating across APAC, where scam campaigns are distributed through paid advertising on Meta platforms and quickly generate massive reach. Key takeaways * Bitdefender Labs identified 12,000 scam campaigns across 13 APAC countries * These campaigns generated more than 400,000 ad sightings through paid ads on Meta platforms * Health and finance are the leading scam categories, together accounting for 37.3% of all campaigns
https://www.bitdefender.com/en-us/blog/labs/inside-the-apac-malvertising-ecosystem
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Football Fever Fuels Scam Campaigns Across Email and Social Media
Football fans are increasingly targeted by scams exploiting club loyalty, national teams, football collectibles, streaming demand, and the growing excitement around the FIFA World Cup 2026, according to Bitdefender Labs. Our most recent investigation uncovered more than 55 football-related malvertising campaigns targeting users through fake online stores, social media ads, IPTV piracy operations, fraudulent football apps, and FIFA-themed giveaway and lottery scams distributed through email. K
https://www.bitdefender.com/en-us/blog/labs/football-fever-fuels-scam-campaigns-across-email-and-social-media
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

SSH Labs
SSH is a widely used protocol that provides secure access to remote systems. It enables encrypted communication, file transfers, command execution and shell access for system administration. Visit https://sshlabs.compass-security.training to learn more about SSH security.
https://blog.compass-security.com/2026/05/ssh-labs/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Missing Security Layer in AI-First Development
 
https://www.legitsecurity.com/blog/the-missing-security-layer-in-ai-first-development
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Investigation update: GitHub Enterprise Server signing key rotation
GitHub Enterprise Server customers need to take immediate action. The post Investigation update: GitHub Enterprise Server signing key rotation appeared first on The GitHub Blog.
https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Microsoft's MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
Bitdefender security researchers have discovered that attackers continue to exploit Microsoft HTML Application Host (MSHTA), a legacy utility available by default on Windows systems that can execute VBScript and JavaScript from local or remote files.
https://www.bitdefender.com/en-us/blog/labs/microsofts-mshta-legacy-malware-windows
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain for the Pixel 9, we wanted to see if it was possible to write a similar exploit chain for Pixel 10. Updating the Dolby Exploit Altering our exploit for CVE-2025-54957 was fairly straightforward. The majority of needed changes involved updating offsets calculated for the specific version of the library we targeted on the Pixel 9 to similar offsets in the library for Pixel 10. The only challenge (outside of wishing we'd better documented which syncframes contained offsets) was that the Pixel 10...
https://projectzero.google/2026/05/pixel-10-exploit.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Introducing RAPTR
I'm happy to announce that we are releasing the beta version of RAPTR, a fully open source, API driven collaboration platform built specifically for red and purple team engagements.
https://blog.compass-security.com/2026/05/introducing-raptr/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Stronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business Week
Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America's entrepreneurs and small business owners. Part of the U.S. Department of Commerce, NIST's mission is to drive U.S. innovation and global competitiveness, and the small business community is central to this mission. In this year's blog, we shine a spotlight on some new and upcoming NIST resources that are all focused on strengthening the cybersecurity and resilience of the nation's small business community. Build Your Small
https://www.nist.gov/blogs/cybersecurity-insights/stronger-cybersecurity-stronger-business-nist-celebrates-2026-national
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Operation Road Trap: Fake toll and parking texts are spreading worldwide
A new mass smishing campaign uncovered by Bitdefender Labs shows that scammers are sending tens of thousands of fraudulent text messages to mobile users across 12 countries, impersonating transport authorities, toll operators, and parking services. Key takeaways * Since December 2025, Bitdefender Labs researchers have been tracking smishing campaigns targeting drivers on a global scale. The scam campaigns are still active as of April 2026 * Over 79,000 fraudulent messages have already been
https://www.bitdefender.com/en-us/blog/labs/operation-road-trap
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

From DMV to Wallet: Understanding Verifiable Digital Credential Issuance
In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define how a credential is structured and shared, but neither can function without an issuance process. This blog post explores what it takes to issue verifiable digital credentials, with a focus on mobile driver's licenses (mDLs). We'll look at how issuance works today in practice, where inconsistencies exist, and how standards bodies (FIDO, ISO and OpenID Foundation) are working to
https://www.nist.gov/blogs/cybersecurity-insights/dmv-wallet-understanding-verifiable-digital-credential-issuance
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Tabletop Simulations: Where Theory Meets Reality
On paper, the vast majority of crisis plans look reasonable, actionable and complete. Once the rubber hits the road, however, chaos emerges quickly.
https://blog.compass-security.com/2026/04/tabletop-simulations-where-theory-meets-reality/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Scaling Our Vision: Welcoming Tamar Nulman and Omri Arnon to the Legit Team
 
https://www.legitsecurity.com/blog/scaling-our-vision-welcoming-tamar-nulman-and-omri-arnon-to-the-legit-team
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AI threats in the wild: The current state of prompt injections on the web
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting this vector today – and if so, how?To answer these questions and to uncover real-world abuse, we initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. This is what we found. The threat of indirect prompt injectionUnlike a direct injection where a user...
http://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Azure-Hosted Scanning Cluster Launches WordPress Webshell Discovery Campaign
Sensor Intel Series: March 2026 CVE Trends
https://www.f5.com/labs/articles/azure-hosted-scanning-cluster-launches-wordpress-webshell-discovery-campaign
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Common Entra ID Security Assessment Findings – Part 4: Weak Conditional Access Policies
This post is part of a small blog series covering common Entra ID security findings observed during real-world assessments. Each article explores selected findings in more detail to provide a clearer understanding of the underlying risks and practical implications. Conditional Access Policies Conditional Access policies are among the most important security controls in Entra ID. […]
https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-4-weak-conditional-access-policies/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Just for Fun – An Unofficial Pen Test Game Module for D&D 5e
Friends, I built an unlicensed, totally unofficial module for my local gaming group based on Dungeons and Dragons 5th Edition, specifically the amazing “Keys from the Golden Vault” heist book. You can download it here. It cannot be resold, and please credit me in distribution. Love to hear your feedback from playtests!
https://tisiphone.net/2026/04/13/just-for-fun-an-unofficial-pen-test-game-module-for-dd-5e/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its proactive security measures further. Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware. The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnerabilities in a risky area, while also laying...
http://security.googleblog.com/2026/04/bringing-rust-to-pixel-baseband.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Mythos: Just One Piece of the Cybersecurity Puzzle
 
https://www.legitsecurity.com/blog/mythos-just-one-piece-of-the-cybersecurity-puzzle
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Protecting Cookies with Device Bound Session Credentials
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft typically occurs when a user inadvertently downloads malware onto their device. Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server. Infostealer malware...
http://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Common Entra ID Security Assessment Findings – Part 3: Weak Privileged Identity Management Configuration
This post is part of a small blog series covering common Entra ID security findings observed during real-world assessments. Each article explores selected findings in more detail to provide a clearer understanding of the underlying risks and practical implications. What Is Privileged Identity Management? Privileged Identity Management (PIM) is a service in Microsoft Entra ID […]
https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-3-weak-privileged-identity-management-configuration/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Google Workspace's continuous approach to mitigating indirect prompt injections
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user's query. This may even be possible without any input directly from the user.IPI is not the kind of technical problem you “solve” and move on. Sophisticated LLMs with increasing use of agentic automation combined with a wide range of content create an ultra-dynamic and evolving playground for adversarial attacks. That's why Google takes a sophisticated and comprehensive approach to these attacks. We're continuously...
http://security.googleblog.com/2026/04/google-workspaces-continuous-approach.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

When AI Writes the Code, What Changes for Security?
 
https://www.legitsecurity.com/blog/when-ai-writes-the-code-what-changes-for-security
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

VRP 2025 Year in Review
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting their acceptance by the external research community, without which such programs cannot function.Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer. This was more evident...
http://security.googleblog.com/2026/03/vrp-2025-year-in-review.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Axios Hijacked: npm Account Takeover Deploys Cross-Platform RAT to Millions
Axios Hijacked: npm Account Takeover Deploys Cross-Platform RAT to Millions
https://www.legitsecurity.com/blog/axios-hijacked-npm-account-takeover-deploys-cross-platform-rat-to-millions
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Common Entra ID Security Assessment Findings – Part 2: Privileged Unprotected Groups
In part 2 of our 4-part series on common Entra ID security findings, we show how seemingly harmless group configurations can be abused to bypass security controls and gain high privileges. The post shows scenarios where insufficiently protected groups are used to: weaken Conditional Access protections for administrators enable privilege escalation through PIM for Groups grant privileged access to Azure resources, leading to full compromise We also show how to detect these issues in practice using EntraFalcon and how to mitigate them.
https://blog.compass-security.com/2026/03/common-entra-id-security-assessment-findings-part-2-privileged-unprotected-groups/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

When Your Scanner Becomes the Weapon: From Trivy to LiteLLM
When Your Scanner Becomes the Weapon: From Trivy to LiteLLM
https://www.legitsecurity.com/blog/when-your-scanner-becomes-the-weapon-from-trivy-to-litellm
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible" problems in drug discovery, materials science, and energy—tasks that even the most powerful classical supercomputers cannot handle. However, the same unique ability to consider different options simultaneously also allows these machines to bypass our current digital locks. This puts the public-key cryptography we've relied on for decades at risk, potentially compromising everything from bank transfers to trade secrets. To secure our future, it is vital to adopt the new Post-Quantum Cryptography (PQC) standards National Institute of Standards and Technology (NIST) is urging...
http://security.googleblog.com/2026/03/post-quantum-cryptography-in-android.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

MSSQLand – Lightweight MS-SQL Interaction Tool for Lateral Movement and Post-Exploitation
MSSQLand enables red teams to interact with MS-SQL servers and linked instances in restricted environments without complex T-SQL queries. Assembly-ready tool for lateral movement.
https://www.darknet.org.uk/2026/03/mssqland-lightweight-ms-sql-interaction-tool-for-lateral-movement-and-post-exploitation/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Reflections from the Second NIST Cyber AI Profile Workshop
Thank you to everyone who participated in the Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile) Workshop in January! The input we received on the Preliminary Draft during this workshop has been invaluable and is informing the development of the next draft of the NIST Cyber AI Profile. We are working toward publishing a full workshop summary soon that captures themes and highlights from the event. In the interim, we would like to share a preview of what we heard… Background on the Second Cyber AI Profile Workshop This workshop was a continuation of the past months
https://www.nist.gov/blogs/cybersecurity-insights/reflections-second-nist-cyber-ai-profile-workshop
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

All aboard: the NIST Cybersecurity for IoT Program is headed to our next stop! Share your input on where we're headed during our Future Directions Two-Day Workshop on March 31st.
Workshop Details… We're looking forward to hearing from the community during our “Future Directions” Workshop! Date: March 31 - April 1, 2026 Where: NIST's Gaithersburg campus! Registration and Details: HERE Can't make it? We still want to hear from you – email us at IoTSecurity [at] nist.gov (IoTSecurity[at]nist[dot]gov). All Aboard for Product Cybersecurity The NIST Cybersecurity for Internet of Things (IoT) Program was established to help real-world practitioners navigate the gray areas between IT and connected products. This provides clarity when it comes to challenges, available existing resources, and understanding where
https://www.nist.gov/blogs/cybersecurity-insights/all-aboard-nist-cybersecurity-iot-program-headed-our-next-stop-share
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Windsurf IDE Extension Drops Malware via Solana Blockchain
Bitdefender researchers have discovered a malicious Windsurf IDE (integrated development environment) extension that deploys a multi-stage NodeJS stealer by using the Solana blockchain as the payload infrastructure.
https://www.bitdefender.com/en-us/blog/labs/windsurf-extension-malware-solana
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads
Bitdefender's security researchers have discovered a malicious Google Ads campaign targeting anyone searching for downloads related to Claude, the large language model developed by Anthropic.
https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Credential Stuffing in 2025 – How Combolists, Infostealers and Account Takeover Became an Industry
Credential stuffing drove 22% of all breaches in 2025. How combolists, infostealers and ATO tooling are fuelling enterprise account takeover at scale
https://www.darknet.org.uk/2026/03/credential-stuffing-in-2025-how-combolists-infostealers-and-account-takeover-became-an-industry/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Global Scam Machines: Inside a Meta-Powered Investment Fraud Ecosystem Spanning 25 Countries
In February-March 2026, Bitdefender Labs identified and mapped a sprawling global scam infrastructure and scalable disinformation-for-profit network that uses trusted news brands, real personalities, fabricated media narratives, emotional hooks, and advanced evasion techniques to drive victims into investment fraud funnels. On February 9-March 5, 2026, we analyzed 310 malvertising campaigns distributed through paid advertising on Meta platforms. Key findings: * This is a global, coordinated
https://www.bitdefender.com/en-us/blog/labs/global-investment-scam-network-using-meta-ads
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass
DumpBrowserSecrets extracts saved passwords, cookies, OAuth tokens and autofill data from Chrome, Edge, Firefox, Opera and Vivaldi, bypassing App-Bound Encryption via Early Bird APC injection.
https://www.darknet.org.uk/2026/03/dumpbrowsersecrets-browser-credential-harvesting-with-app-bound-encryption-bypass/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CASI Leaderboard Shifts: Sugar-Coated Poison, and the Expanding AI Attack Surface
AI Security Insights – March 2026
https://www.f5.com/labs/articles/casi-leaderboard-shifts-sugar-coated-poison-and-the-expanding-ai-attack-surface
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

On the Effectiveness of Mutational Grammar Fuzzing
Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a way that any resulting samples still adhere to the grammar rules, thus the structure of the samples gets maintained by the mutation process. In case of coverage-guided grammar fuzzing, if the resulting sample (after the mutation) triggers previously unseen code coverage, this sample is saved to the sample corpus and used as a basis for future mutations. This technique has proven capable of finding complex issues and I have used it successfully in the past, including to find issues in XSLT implementations in web browsers and even JIT engine bugs. However, despite the approach being effective, it...
https://projectzero.google/2026/03/mutational-grammar-fuzzing.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.5.2 and 1.4.4 security patch versions published
Today, we are publishing the 1.5.2 and 1.4.4 security patch versions.  The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub with both Alpine and Debian containers. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version. 1.5.2 ClamAV 1.5.2 is a patch release with the following fixes: CVE-2026-20031: Fixed an error handling bug in the HTML file parser that may crash the program and cause a denial-of-service (DoS) condition. This issue was introduced in version 1.1.0. The fix is included in 1.5.2 and 1.4.4. Fixed a possible infinite loop when scanning some JPEG files by upgrading affected ClamAV...
https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cultivating a robust and efficient quantum-safe HTTPS
Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures (“PLANTS”), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant cryptography and some of the steps we've taken to address them in earlier blog posts. To ensure the scalability and efficiency of the ecosystem, Chrome has no immediate plan to add traditional...
http://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn't know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I thought I should take a closer look. I typically start by reading the documentation for an API I don't know about, assuming it's documented at all. It can give you an idea of how long the API has existed as well as its security properties. The documentation's remarks contain the following three statements that I thought were interesting: If the caller has UIAccess, however, they can use a windows hook to inject code into the target process, and from within the target process, send a handle back to the caller. GetProcessHandleFromHwnd is a convenience function...
https://projectzero.google/2026/02/gphfh-deep-dive.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Staying One Step Ahead: Strengthening Android's Lead in Scam Protection
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We've shared how Android's proactive, multi-layered scam defenses utilize Google AI to protect users around the world from over 10 billion suspected malicious calls and messages every month1. While that scale is significant, the true impact of these protections is best understood through the stories of the individuals they help keep safe every day. This includes people like Majik B., an IT professional in Sunnyvale, California. Despite his technical background, Majik recently found himself on a call that felt dangerously legitimate. While using his Pixel, he received a call that appeared to be from his bank. The number looked correct, the...
http://security.googleblog.com/2026/02/strengthening-android-lead-in-scam-protection.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Celebrating Two Years of CSF 2.0!
Celebrate this milestone with us! Email us at csf [at] nist.gov (csf[at]nist[dot]gov) or tag @NISTcyber on X telling us what your favorite CSF 2.0 resource is (or how your organization has benefitted from implementing the CSF 2.0). Today marks two years since the publication of the Cybersecurity Framework (CSF) 2.0! Published in 2024, the CSF 2.0 included the addition of a Govern Function, increased emphasis on cybersecurity supply chain risk management, updated categories and subcategories to address current threat and technology shifts, and expansion into a suite of resources designed to make the CSF 2.0 easier to
https://www.nist.gov/blogs/cybersecurity-insights/celebrating-two-years-csf-20
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Keeping Google Play & Android app ecosystems safe in 2025
Posted by Vijaya Kaza, VP and GM, App & Ecosystem Trust The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that trust, we're focused on ensuring that apps do not cause real-world harm, such as malware, financial fraud, hidden subscriptions, and privacy invasions. As bad actors leverage AI to change their tactics and launch increasingly sophisticated attacks, we've deepened our investments in AI and real-time defenses over the last year to maintain the upper hand and stop these threats before they reach users. Upgrading Google Play's AI-powered, multi-layered user protections We've seen a clear impact from these safety efforts on Google Play. In 2025, we prevented over...
http://security.googleblog.com/2026/02/keeping-google-play-android-app-ecosystem-safe-2025.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Bypassing Administrator Protection by Abusing UI Access
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn't exist. I described one of the ways I was able to bypass the feature before it was released. In total I found 9 bypasses during my research that have now all been fixed. In this blog post I wanted to describe the root cause of 5 of those 9 issues, specifically the implementation of UI Access, how this has been a long standing problem with UAC that's been under-appreciated, and how it's being fixed now. A Question of Accessibility Prior to Windows Vista any process running on a user's desktop could control any window created by another, such as by sending window messages. This behavior could be abused if a privileged user, such as SYSTEM,...
https://projectzero.google/2026/02/windows-administrator-protection.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

LummaStealer Is Getting a Second Life Alongside CastleLoader
Bitdefender researchers have discovered a surge in LummaStealer activity, showing how one of the world's most prolific information-stealing malware operations managed to survive despite being almost brought down by law enforcement less than a year ago. LummaStealer is a highly scalable information-stealing threat with a long history, having operated under a malware-as-a-service model since it appeared on the scene in late 2022. The threat quickly evolved into one of the most widely deployed in
https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

LDAP authentication bypass in Agentless VPN and FSSO
CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. Revised on 2026-07-04 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-25-1052
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap
With hundreds of malicious OpenClaw skills blending in among legitimate ones, manually reviewing every script or command isn't realistic — especially when skills are designed to look helpful and familiar. That's why Bitdefender offers a free AI Skills Checker, designed to help people quickly assess whether an AI skill might be risky before they install or run it. Using the tool, you can: * Analyze AI skills and automation tools for suspicious behavior * Spot red flags like hidden execution,
https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Supporting Wayland's XDG activation protocol with Gtk/Glib
One of the biggest sore points with Wayland is its focus stealing protection. The idea is good: an application should not be able to bring itself into focus at an unexpected time, only when the currently active application allows it. Support is still lacking however, which might also be due to Gtk/Glib implementing the required XDG activation protocol but not really documenting it. It took me a bit of time to figure this out without any public information, this article will hopefully make things easier for other people. Contents How the XDG activation protocol works State of implementation in Gtk/Glib Starting applications via Gio.AppInfo Starting applications by other means How the XDG activation protocol works The main idea behind the XDG activation protocol...
https://palant.info/2026/02/03/supporting-waylands-xdg-activation-protocol-with-gtk/glib/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529
In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-free vulnerability (CVE-2025-31235) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability. I'll explain the technical details of turning a potentially exploitable crash into a working exploit: a journey filled with dead ends, creative problem solving, and ultimately, success. The Vulnerability: A Quick Recap If you haven't already, I highly recommend reading my detailed writeup on this vulnerability before proceeding. As...
https://projectzero.google/2026/01/sound-barrier-2.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload Delivery
Bitdefender researchers have discovered an Android RAT (remote access trojan) campaign that combines social engineering, the resources of the Hugging Face online platform as staging, and extensive use of Accessibility Services to compromise devices.
https://www.bitdefender.com/en-us/blog/labs/android-trojan-campaign-hugging-face-hosting-rat-payload
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

New Android Theft Protection Feature Updates: Smarter, Stronger
Posted by Nataliya Stanetsky, Fabricio Ferracioli, Elliot Sisteron, Irene Ang of the Android Security Team Phone theft is more than just losing a device; it's a form of financial fraud that can leave you suddenly vulnerable to personal data and financial theft. That's why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt. Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals. Stronger Authentication Safeguards We've expanded our security to protect you against an even wider range of threats. These updates are now available for Android devices running Android...
http://security.googleblog.com/2026/01/android-theft-protection-feature-updates.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Celebrating Data Privacy Week with NIST's Privacy Engineering Program
Grab your party hats – it's Data Privacy Week! Data Privacy Week is a global initiative led by the National Cybersecurity Alliance to spread awareness about online privacy and empower individuals and businesses to respect privacy, safeguard data, and enable trust. In celebration of this week, the NIST Privacy Engineering Program is reflecting on recent work and looking ahead to what's coming in the new year. Throughout 2026, we plan to continue collaborating with our privacy stakeholder community to develop and advance privacy risk management guidelines to help organizations of all sizes
https://www.nist.gov/blogs/cybersecurity-insights/celebrating-data-privacy-week-nists-privacy-engineering-program
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Bypassing Windows Administrator Protection
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary. This blog post will give a brief overview of the new feature, how it works and how it's different from UAC. I'll then describe some of the security research I undertook while it was in the insider preview builds on Windows 11. Finally I'll detail one of the nine separate vulnerabilities that I found to bypass the feature to silently gain full administrator privileges. All the issues that I reported to Microsoft have been fixed, either prior to the feature being officially released (in optional...
https://projectzero.google/2026/26/windows-administrator-protection.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement. Audio Attack Surface The Dolby UDC is part of the 0-click attack surface of most Android devices because of audio transcription in the Google Messages application. Incoming audio messages are transcribed before a user interacts with the message. On Pixel 9, a second process com.google.android.tts also decodes incoming audio. Its purpose is not completely clear, but it seems to be related to making incoming messages searchable.
https://projectzero.google/2026/01/pixel-0-click-part-3.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessible from the mediacodec SELinux context. BigWave is hardware present on the Pixel SOC that accelerates AV1 decoding tasks, which explains why it is accessible from the mediacodec context. As previous research has copiously affirmed, Android drivers for hardware devices are prime places to find powerful local...
https://projectzero.google/2026/01/pixel-0-click-part-2.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription. Incoming SMS and RCS audio attachments received by Google Messages are now automatically decoded with no user interaction. As a result, audio decoders are now in the 0-click attack surface of most Android phones. I've spent a fair bit of time investigating these decoders, first reporting CVE-2025-49415 in the Monkey's Audio codec on Samsung devices. Based on this research, the team reviewed the Dolby Unified Decoder, and Ivan Fratric...
https://projectzero.google/2026/01/pixel-0-click-part-1.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

When AI Gets Bullied: How Agentic Attacks Are Replaying Human Social Engineering
AI Security Insights – January 2026
https://www.f5.com/labs/articles/when-ai-gets-bullied-how-agentic-attacks-are-replaying-human-social-engineering
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Podcast – GirlsTalkCyber – Episode 24
I spoke to the GirlsTalkCyber podcast about understanding and being aware of threats against critical infrastructure. We talked about things you should think about as geopolitical, economic, and climate instability increase across the world and how that relates to cyber threats. https://girlstalkcyber.com/24-what-happens-if-hackers-poison-the-water-interview-with-lesley-carhart/
https://tisiphone.net/2026/01/13/podcast-girlstalkcyber-episode-24/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Smashing Security – 449: How to scam someone in seven days
I am so excited to be on Smashing Security! Such a huge pleasure to finally make it onto one my favorite podcasts of all time with Graham Cluley! While I spoke about the jobs market and what students and hiring managers should be doing about it, Graham told me that my star sign isn’t good […]
https://tisiphone.net/2026/01/07/smashing-security-449-how-to-scam-someone-in-seven-days/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Backdoors in VStarcam cameras
VStarcam is an important brand of cameras based on the PPPP protocol. Unlike the LookCam cameras I looked into earlier, these are often being positioned as security cameras. And they in fact do a few things better like… well, like having a mostly working authentication mechanism. In order to access the camera one has to know its administrator password. So much for the theory. When I looked into the firmware of the cameras I discovered a surprising development: over the past years this protection has been systematically undermined. Various mechanisms have been added that leak the access password, and in several cases these cannot be explained as accidents. The overall tendency is clear: for some reason VStarcam really wants to have access to their customer's passwords. A reminder: “P2P”...
https://palant.info/2026/01/07/backdoors-in-vstarcam-cameras/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem
Understanding mDL credential formats Standards in the VDC Ecosystem In our first blog post in this series, we highlighted that VDCs can represent a wide range of credentials, from a driver's license to a diploma to proof of age. The ability to use VDCs in a wide variety of use cases is a major reason why many are looking at the VDC ecosystem as technology that can change how we present identity and attributes (both in person and online). While credential variety is a good thing, interoperability requires a common set of standards and protocols for issuing, using, and verifying VDCs. The next
https://www.nist.gov/blogs/cybersecurity-insights/digital-identities-getting-know-verifiable-digital-credential-0
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Analysis of PPPP “encryption”
My first article on the PPPP protocol already said everything there was to say about PPPP “encryption”: Keys are static and usually trivial to extract from the app. No matter how long the original key, it is mapped to an effective key that's merely four bytes long. The “encryption” is extremely susceptible to known-plaintext attacks, usually allowing reconstruction of the effective key from a single encrypted packet. So this thing is completely broken, why look any further? There is at least one situation where you don't know the app being used so you cannot extract the key and you don't have any traffic to analyze either. It's when you are trying to scan your local network for potential hidden cameras. This script will currently only work for cameras using plaintext communication....
https://palant.info/2026/01/05/analysis-of-pppp-encryption/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

My Top 5 Recommendations on OT Cybersecurity Student Upskilling
I get asked about where to start learning OT cybersecurity as a student a lot. I fully realize that attention spans are short and people are busy, so without further ado let’s get to my top five recommendations: I hope this gives you a few more ideas! Happy new year!
https://tisiphone.net/2026/01/04/my-top-5-recommendations-on-ot-cybersecurity-student-upskilling/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Destination Cyber Podcast on OT
Please see my recent podcast on OT foundations and current events with Destination Cyber from KBI.FM!
https://tisiphone.net/2026/01/04/destination-cyber-podcast-on-ot/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV Signature Retirement
As per our previous announcement ClamAV file signature retirement has been implemented.Users may notice that file sizes are much smaller today as a result of the signature retirements.After we retired impacted signatures our download file sizes are now:bytecode.cvd: 275 KiBmain.cvd: 85 MiBdaily.cvd: 22 MiBOur team is continuing to monitor alerts and the current threat landscape and we are committed to reintroducing retired signatures as needed.For more detailed information on the ClamAV signature please see our previous blog post.ClamAV Signature Retirement AnnouncementIf you have any questions please join our ClamAV mailer here: ClamAV contactOr our ClamAV Discord Server here: ClamAV Discord Server
https://blog.clamav.net/2025/12/clamav-signature-retirement.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Welcome to the new Project Zero Blog
While on Project Zero, we aim for our research to be leading-edge, our blog design was … not so much. We welcome readers to our shiny new blog! For the occasion, we asked members of Project Zero to dust off old blog posts that never quite saw the light of day. And while we wish we could say the techniques they cover are no longer relevant, there is still a lot of work that needs to be done to protect users against zero days. Our new blog will continue to shine a light on the capabilities of attackers and the many opportunities that exist to protect against them. From 2016: Windows Exploitation Techniques: Race conditions with path lookups by James Forshaw From 2017: Thinking Outside The Box by Jann Horn
https://projectzero.google/2025/12/welcome.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

2026 Cybersecurity Predictions
Whatever you think will happen… will happen faster and with more acronyms than ever before.
https://www.f5.com/labs/articles/2026-cybersecurity-predictions
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Unpacking VStarcam firmware for fun and profit
One important player in the PPPP protocol business is VStarcam. At the very least they've already accumulated an impressive portfolio of security issues. Like exposing system configuration including access password unprotected in the Web UI (discovered by multiple people independently from the look of it). Or the open telnet port accepting hardcoded credentials (definitely discovered by lots of people independently). In fact, these cameras have been seen used as part of a botnet, likely thanks to some documented vulnerabilities in their user interface. Is that a thing of the past? Are there updates fixing these issues? Which devices can be updated? These questions are surprisingly hard to answer. I found zero information on VStarcam firmware versions, available updates or security fixes....
https://palant.info/2025/12/15/unpacking-vstarcam-firmware-for-fun-and-profit/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers. These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation. By retiring these outdated practices, which rely on weaker verification signals like physical mail, phone calls, or emails, we are closing potential loopholes for attackers and pushing the ecosystem toward automated, cryptographically verifiable security. To allow affected website operators...
http://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain
After noticing a spike in detections involving what looked like a movie torrent for One Battle After Another, Bitdefender researchers started an investigation and discovered that it was a complex infection chain. The film, Leonardo DiCaprio's latest, has quickly gained notoriety, making it an attractive lure for cybercriminals seeking to infect as many devices as possible. People often search for the latest movies on the internet, hoping to find a copy of a new release that has just begun its
https://www.bitdefender.com/en-us/blog/labs/fake-leonardo-dicaprio-movie-torrent-agent-tesla-powershell
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Further Hardening Android GPUs
Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack. While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely, making them unreachable by restricting attack surface is another effective and often faster way to improve security. This post details our efforts in partnership with Arm to further harden the GPU by reducing the driver's attack surface. The Growing Threat: Why GPU Security Matters The Graphics...
http://security.googleblog.com/2025/12/further-hardening-android-gpus.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A NICE Retrospective on Shaping Cybersecurity's Future
Rodney Petersen has served as the Director of NICE at the National Institute for Standards and Technology (NIST) for the past eleven years where his focus has been on advancing cybersecurity education and workforce development. He will be retiring from federal government service at the end of the 2025 calendar year. Prior to his role at NIST, he has worked in various technology policy and leadership roles with EDUCAUSE and the University of Maryland. The NICE program, led by the National Institute of Standards and Technology (NIST) in the U.S. Department of Commerce, has its origins in the
https://www.nist.gov/blogs/cybersecurity-insights/nice-retrospective-shaping-cybersecuritys-future
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fallacy Failure Attack
AI Security Insights for November 2025
https://www.f5.com/labs/articles/fallacy-failure-attack
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Systemic Ransomware Events in 2025 – How Jaguar Land Rover Showed What a Category 3 Supply Chain Breach Looks Like
Systemic ransomware events in 2025, how Jaguar Land Rover's shutdown exposed Category 3 supply chain risk, with lessons from Toyota, Nissan and Ferrari.
https://www.darknet.org.uk/2025/11/systemic-ransomware-events-in-2025-how-jaguar-land-rover-showed-what-a-category-3-supply-chain-breach-looks-like/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

SmbCrawler – SMB Share Discovery and Secret-Hunting
SmbCrawler is a credentialed SMB share crawler for red teams that discovers misconfigured shares and hunts secrets across Windows networks.
https://www.darknet.org.uk/2025/11/smbcrawler-smb-share-discovery-and-secret-hunting/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Heisenberg Dependency Health Check – GitHub Action for Supply Chain Risk
Heisenberg Dependency Health Check is a GitHub Action that flags risky or newly introduced dependencies in pull requests using supply-chain signals.
https://www.darknet.org.uk/2025/11/heisenberg-dependency-health-check-github-action-for-supply-chain-risk/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Dark Web Search Engines in 2025 – Enterprise Monitoring, APIs and IOC Hunting
Dark web search engines in 2025 and how enterprises use monitoring, APIs and IOC hunting to detect credential leaks, impersonation and supply chain exposure.
https://www.darknet.org.uk/2025/11/dark-web-search-engines-in-2025-enterprise-monitoring-apis-and-ioc-hunting/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV Signature Retirement Announcement
ClamAV was first introduced in 2002; since then, the signature set has grown without bound, delivering as many detections as possible to the community. Due to continually increasing database sizes and user adoption, we are faced with significantly increasing costs of distributing the signature set to the community.To address the issue, Cisco Talos has been working to evaluate the efficacy and relevance of older signatures. Signatures which no longer provide value to the community, based on today's security landscape, will be retired.We are making this announcement as an advisory that our first pass of this retirement effort will affect a significant drop in database size for both the daily.cvd and main.cvd.Our goal is to ensure that detection content is targeted to currently active threats...
https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

mcp-scan – Real-Time Guardrail Monitoring and Dynamic Proxy for MCP Servers
mcp-scan is a dynamic proxy and guardrail monitor for MCP servers, providing real-time traffic inspection and enforcement for agents and tools.
https://www.darknet.org.uk/2025/11/mcp-scan-real-time-guardrail-monitoring-and-dynamic-proxy-for-mcp-servers/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Initial Access Brokers (IAB) in 2025 – From Dark Web Listings to Supply Chain Ransomware Events
Initial access brokers in 2025, how dark web access listings feed ransomware supply chain events like JLR, and what CISOs can do to detect and disrupt them
https://www.darknet.org.uk/2025/11/initial-access-brokers-iab-in-2025-from-dark-web-listings-to-supply-chain-ransomware-events/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool
Reconnoitre automates network reconnaissance and service enumeration for penetration testers and red teams using structured, repeatable workflows.
https://www.darknet.org.uk/2025/11/reconnoitre-open-source-reconnaissance-and-service-enumeration-tool/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

An overview of the PPPP protocol for IoT cameras
My previous article on IoT “P2P” cameras couldn't go into much detail on the PPPP protocol. However, there is already lots of security research on and around that protocol, and I have a feeling that there is way more to come. There are pieces of information on the protocol scattered throughout the web, yet every one approaching from a very specific narrow angle. This is my attempt at creating an overview so that other people don't need to start from scratch. While the protocol can in principle be used by any kind of device, it is mostly being used for network-connected cameras. It isn't really peer-to-peer as advertised but rather relies on central servers, yet the protocol allows to transfer the bulk of data via a direct connection between the client and the device. It's hard...
https://palant.info/2025/11/05/an-overview-of-the-pppp-protocol-for-iot-cameras/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Passively Downloading Malware Payloads Via Image Caching
Detailing an improved Cache Smuggling technique to turn 3rd party software into passive malware downloader.
https://malwaretech.com/2025/10/exif-smuggling.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.5.1 patch version published
Today, we are publishing ClamAV 1.5.1. This version has been released shortly after ClamAV 1.5.0 in order to address several significant issues that were identified following its publication.The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub. The images on Docker Hub may not be immediately available on release day.ClamAV 1.5.1 is a patch release with the following fixes:Fixed a significant performance issue when scanning some PE filesFixed an issue recording file entries from a ZIP archive central directory which resulted in "Heuristics.Limits.Exceeded.MaxFiles" alerts when using the ClamScan --alert-exceeds-max command line option or ClamD AlertExceedsMax config file optionImproved...
https://blog.clamav.net/2025/10/clamav-151-patch-version-published.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.5.0 released!
The ClamAV 1.5.0 is now available. You may find the source code and installers for this release at clamav.net/downloads or on the ClamAV GitHub release page. IMPORTANT: A major feature of the 1.5 release is a FIPS-mode compatible method for verifying the authenticity of CVD signature database archives and CDIFF signature database patch files. This feature relies on “.cvd.sign” signature files for the daily, main, and bytecode databases. The Freshclam with 1.5.0 will download these files as will the latest version of CVDUpdate. When they are not present, ClamAV will fall back to using the legacy MD5-based RSA signature check.Tip: If you are downloading the source from the GitHub release page, the package labeled "clamav-1.5.0.tar.gz" does not require an internet connection to build....
https://blog.clamav.net/2025/10/clamav-150-released.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Sharpening the Focus on Product Requirements and Cybersecurity Risks: Updating Foundational Activities for IoT Product Manufacturers
Update: The comment period for your feedback on the second public draft of NIST IR 8259 has been extended through December 10, 2025. Over the past few months, NIST has been revising and updating Foundational Activities for IoT Product Manufacturers (NIST IR 8259 Revision 1 Initial Public Draft), which describes recommended pre-market and post-market activities for manufacturers to develop products that meet their customers' cybersecurity needs and expectations. Thank you so much for the thoughtful comments and feedback throughout this process; 400+ participants across industry, consumer
https://www.nist.gov/blogs/cybersecurity-insights/sharpening-focus-product-requirements-and-cybersecurity-risks-updating
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Reasonable Expectations for Cybersecurity Mentees
Most of my audience is on the more senior end of the career spectrum. As a result, a lot of my writing about careers is aimed at senior cybersecurity professionals, encouraging managers and experienced practitioners to support the next generation. But that doesn't mean newcomers are free from responsibility in their career journey. If you're […]
https://tisiphone.net/2025/09/24/reasonable-expectations-for-cybersecurity-mentees/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Entra ID actor token validation bug allowing cross-tenant global admin
A critical vulnerability discovered in Microsoft's Entra ID (formerly Azure AD) allowed for cross-tenant access and potential global admin privilege escalation. The flaw was found in the legacy Azure AD Graph API, which improperly validated the originating tenant for undocumented "Actor tokens." An attacker could use a token from their own tenant to authenticate as any user, including Global Admins, in any other tenant. This vulnerability bypassed security policies like Conditional Access. The issue was reported to Microsoft, who deployed a global fix within days.
https://www.cloudvulndb.org/global-admin-entra-id-actor-tokens
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

More Mozilla User-Agents, Please: a Deep Dive into an Inadvertent Disclosure Scanner
Sensor Intel Series: September 2025 Trends
https://www.f5.com/labs/articles/more-mozilla-user-agents-please-a-deep-dive-into-an-inadvertent-disclosure-scanner
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Top 10 Things I'd Like to See in University OT Cybersecurity Curriculum (2025 Edition)
Most of you who have been following me for a while know that I have a very strange and unusual job in cybersecurity. I’m one of maybe a hundred or so people on earth who does full time incident response and forensics for industrial devices and networks that are hacked. Things like power plants, trains, […]
https://tisiphone.net/2025/09/10/the-top-10-things-id-like-to-see-in-university-ot-cybersecurity-curriculum-2025-edition/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A look at a P2P camera (LookCam app)
I've got my hands on an internet-connected camera and decided to take a closer look, having already read about security issues with similar cameras. What I found far exceeded my expectations: fake access controls, bogus protocol encryption, completely unprotected cloud uploads and firmware riddled with security flaws. One could even say that these cameras are Murphy's Law turned solid: everything that could be done wrong has been done wrong here. While there is considerable prior research on these and similar cameras that outlines some of the flaws, I felt that the combination of severe flaws is reason enough to publish an article of my own. My findings should apply to any camera that can be managed via the LookCam app. This includes cameras meant to be used with less popular apps of the...
https://palant.info/2025/09/08/a-look-at-a-p2p-camera-lookcam-app/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Open Online Mentoring Guide
I’ve had a sign up for open online career mentoring on my site for quite a number of years now (in addition to running similar career clinics in-person). As I’ve gotten more and more traction internationally on the program, a lot of senior folks have asked how to set up a program for office hours […]
https://tisiphone.net/2025/09/01/open-online-mentoring-guide/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Stories Ink Interviewed Me, and I love Stories.
I was recently at the Tech Leaders Summit in Hunter Valley and the imitable Jennifer O’Brien covered my backstory and how I got into the odd space of Operational Technology. This is a nice change of format for people who aren’t into podcasts and she tells such a good narrative. It was really cool to […]
https://tisiphone.net/2025/09/01/stories-ink-interviewed-me-and-i-love-stories/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Dataform cross-tenant path traversal
Dataform could have allowed a malicious customer to gain unauthorized cross-tenant access to other customer's code repositories and data. By preparing a maliciously crafted package.json file, an attacker could exploit a path traversal vulnerability in the npm package installation process, thereby gaining read and write access in other customers' repositories. According to Google, there was no evidence of exploitation in the wild.
https://www.cloudvulndb.org/dataform-path-traversal
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.5.0 release candidate now available!
The ClamAV 1.5.0 release candidate is now available. You may find the source code and installers for this release at clamav.net/downloads or on the ClamAV GitHub release page. The release candidate phase is expected to last two to four weeks before we publish the stable release. This will depend on whether any changes are required to stabilize this version. Please take this time to evaluate ClamAV 1.5.0. Please help us validate this release by providing feedback via GitHub issues, via the ClamAV mailing list or on our Discord. IMPORTANT: A major feature of the 1.5 release is a FIPS-compliant method for verifying the authenticity of CVD signature database archives and CDIFF signature database patch files. The feature is ready to test in this release candidate, but we are not...
https://blog.clamav.net/2025/08/clamav-150-release-candidate-now.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AWS ECS Agent Information Disclosure Vulnerability
A vulnerability in the Amazon ECS agent could allow an introspection server to be accessed off-host. This information disclosure issue, if exploited, could allow another instance in the same security group to access the server's data. The vulnerability does not affect instances where off-host access is set to 'false'. The issue has been patched in version 1.97.1 of the ECS agent.
https://www.cloudvulndb.org/aws-ecs-agent-information-disclosure-vulnerability
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

IoT Penetration Testing: From Hardware to Firmware
As Internet of Things (IoT) devices continue to permeate every aspect of modern life, homes, offices, factories, vehicles, their attack surfaces have become increasingly attractive to adversaries. The challenge with testing IoT systems lies in their complexity: these devices often combine physical interfaces, embedded firmware, network services, web applications, and companion mobile apps into a [...] The post IoT Penetration Testing: From Hardware to Firmware appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/iot-hacking/iot-penetration-testing-from-hardware-to-firmware/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

SparkRAT: Exploiting Architectural Weaknesses in Open-Source Offensive Tools
Persistent trend in open-source offensive tooling & implications for defenders
https://www.f5.com/labs/articles/sparkrat-exploiting-architectural-weaknesses-in-open-source-offensive-tools
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Every Reason Why I Hate AI and You Should Too
maybe it's anti-innovation, maybe it's just avoiding hype. But one thing is clear, I'm completely done with hearing about AI.
https://malwaretech.com/2025/08/every-reason-why-i-hate-ai.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Let's get Digital! Updated Digital Identity Guidelines are Here!
Today is the day! Digital Identity Guidelines, Revision 4 is finally here...it's been an exciting journey and NIST is honored to be a part of it. What can we expect? Serving as a culmination of a nearly four-year collaborative process that included foundational research, two public drafts, and about 6,000 individual comments from the public, Revision 4 of Special Publication 800-63, Digital Identity Guidelines, intends to respond to the changing digital landscape that has emerged since the last major revision of this suite, published in 2017. The guidelines presented in Revision 4 explain the
https://www.nist.gov/blogs/cybersecurity-insights/lets-get-digital-updated-digital-identity-guidelines-are-here
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.4.3 and 1.0.9 security patch versions published
Today, we are publishing the 1.4.3 and 1.0.9 security patch versions. We have also added Linux aarch64 (aka ARM64) RPM and DEB installer packages for the 1.4 LTS release.The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version.1.4.3ClamAV 1.4.3 is a patch release with the following fixes: CVE-2025-20260: Fixed a possible buffer overflow write bug in the PDF file parser that could cause a denial-of-service (DoS) condition or enable remote code execution.This issue only affects configurations where both:The max file-size scan limit is set greater than or equal to 1024MB.The...
https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

F5 Labs Top CWEs & OWASP Top Ten Analysis
We expand our view to include CWE and OWASP, and we also examine the latest overall trends for June 2025.
https://www.f5.com/labs/articles/f5-labs-top-cwes-owasp-top-ten-analysis
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Delving Into the SparkRAT Remote Access Tool
Sensor Intel Series: May 2025 CVE Trends
https://www.f5.com/labs/articles/delving-into-the-sparkrat-remote-access-tool
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Remote Prompt Injection in GitLab Duo Leaks Source Code
A remote prompt injection vulnerability in GitLab Duo allowed attackers to steal source code from private projects, manipulate code suggestions, and exfiltrate confidential information. The attack chain involved hidden prompts, HTML injection, and exploitation of Duo's access to private data. GitLab has since patched both the HTML and prompt injection vectors.
https://www.cloudvulndb.org/gitlab-duo-prompt-injection-leak
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AWS Security Tool Introduces Privilege Escalation Risk
AWS's Account Assessment for AWS Organizations tool, designed to audit cross-account access, inadvertently introduced privilege escalation risks due to flawed deployment instructions. Customers were encouraged to deploy the tool in lower-sensitivity accounts, creating risky trust paths from insecure environments into highly sensitive ones. This could allow attackers to pivot from compromised development accounts into production and management accounts.
https://www.cloudvulndb.org/aws-security-tool-risk
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

FreeRTOS and coreSNTP Security Advisories
Security advisories were issued for FreeRTOS and coreSNTP releases containing unintended scripts that could potentially transmit AWS credentials if executed on Linux/macOS. Affected releases have been removed and users are advised to rotate credentials and delete downloaded copies.
https://www.cloudvulndb.org/freertos-coresntp-advisories
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Azure AZNFS-mount Utility Root Privilege Escalation
A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.
https://www.cloudvulndb.org/azure-aznfs-mount-privilege-escalation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AWS Default Roles Can Lead to Service Takeover
Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.
https://www.cloudvulndb.org/aws-default-roles-service-takeover
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Google Cloud ConfusedComposer Privilege Escalation Vulnerability
Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.
https://www.cloudvulndb.org/gcp-confused-composer-vulnerability
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Burning Data with Malicious Firewall Rules in Azure SQL
Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.
https://www.cloudvulndb.org/burning-data-azure-sql-firewall
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Path Traversal in AWS SSM Agent Plugin ID Validation
A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.
https://www.cloudvulndb.org/aws-ssm-agent-path-traversal
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ImageRunner: Privilege Escalation Vulnerability in GCP Cloud Run
An attacker with `run.services.update` and `iam.serviceAccounts.actAs` permissions but without explicit registry access could deploy new revisions of Cloud Run services that pulled private container images stored in the same GCP project. This was possible because Cloud Run uses a service agent with the necessary registry read permissions to retrieve these images, regardless of the caller's access level. By updating a service revision and injecting malicious commands into the container's arguments (e.g., using Netcat for reverse shell access), attackers could extract secrets or run unauthorized code. The flaw stemmed from the Cloud Run service agent's trust model, which did not enforce a separate registry permission check on the deploying identity. Google has since modified this behavior...
https://www.cloudvulndb.org/imagerunner
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.5.0 beta now available!
The ClamAV 1.5.0 beta is now available. You may find the source code and installers for this release at clamav.net/downloads or on the ClamAV GitHub release page. The beta phase is expected to last two to four weeks before we publish the stable release or else publish a release candidate. This will depend on how many changes are required to stabilize this version. Please take this time to evaluate ClamAV 1.5.0. Please help us validate this release by providing feedback via GitHub issues, via the ClamAV mailing list or on our Discord. IMPORTANT: A major feature of the 1.5 release is a FIPS-compliant method for verifying the authenticity of CVD signature database archives and CDIFF signature database patch files. The feature is ready to test in this beta, but we are not yet distributing the...
https://blog.clamav.net/2025/03/clamav-150-beta-now-available.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

2025 Advanced Persistent Bots Report
Uncovering the true scale of persistent bot activity, and the advanced techniques that bot operators use in order to remain hidden from bot defenses.
https://www.f5.com/labs/articles/2025-advanced-persistent-bots-report
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The US Needs A New Cybersecurity Strategy: More Offensive Cyber Operations Isn't It
For a long time Chinese hackers have been operating in the grey area between espionage and warfare. The US has been struggling to defend its networks, but increasing offensive cyber operations in unlikely to help.
https://malwaretech.com/2025/03/the-us-needs-a-new-cybersecurity-strategy.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Advance notice: End of Life for ClamAV 0.103 database updates
ClamAV version 0.103 will reach its end of life (EOL) for database updates on September 14, 2025. After this date, this version will no longer receive the latest virus definitions. To ensure your systems remain protected, please upgrade to the latest supported version of ClamAV before the end-of-life date. This will provide continued access to essential security updates and features. We recommend that users update to the newest release, ClamAV 1.4 LTS. For users that are unable to upgrade to version 1.4, you may find that ClamAV 1.0 LTS is more suitable. The most recent version of ClamAV can be found on the ClamAV Downloads page, on the ClamAV GitHub Releases page, and through Docker Hub. Information about how to install ClamAV is available in our online documentation. The...
https://blog.clamav.net/2025/03/advance-notice-end-of-life-for-clamav.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Why Critical MongoDB Library Flaws Won't See Mass Exploitation
Discover how to mitigate CVE-2024-53900 and CVE-2025-23061, which expose Node.js APIs to remote attacks.
https://www.f5.com/labs/articles/why-critical-mongodb-library-flaws-wont-see-mass-exploitation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Analysis of an advanced malicious Chrome extension
Two weeks ago I published an article on 63 malicious Chrome extensions. In most cases I could only identify the extensions as malicious. With large parts of their logic being downloaded from some web servers, it wasn't possible to analyze their functionality in detail. However, for the Download Manager Integration Checklist extension I have all parts of the puzzle now. This article is a technical discussion of its functionality that somebody tried very hard to hide. I was also able to identify a number of related extensions that were missing from my previous article. Update (2025-02-04): An update to Download Manager Integration Checklist extension has been released a day before I published this article, clearly prompted by me asking adindex about this. The update removes the malicious functionality...
https://palant.info/2025/02/03/analysis-of-an-advanced-malicious-chrome-extension/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.4.2 and 1.0.8 security patch versions published
Today, we are publishing the 1.4.2 and 1.0.8 security patch versions. The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version.1.4.2 ClamAV 1.4.2 is a patch release with the following fixes: CVE-2025-20128: Fixed a possible buffer overflow read bug in the OLE2 file parser that could cause a denial-of-service (DoS) condition. This issue was introduced in version 1.0.0 and affects all currently supported versions. It will be fixed in: 1.4.2 and 1.0.8 Thank you to OSS-Fuzz for identifying this issue. 1.0.8 ClamAV 1.0.8 is a patch release with the following fixes:CVE-2025-20128:...
https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Malicious extensions circumvent Google's remote code ban
As noted last week I consider it highly problematic that Google for a long time allowed extensions to run code they downloaded from some web server, an approach that Mozilla prohibited long before Google even introduced extensions to their browser. For years this has been an easy way for malicious extensions to hide their functionality. When Google finally changed their mind, it wasn't in form of a policy but rather a technical change introduced with Manifest V3. As with most things about Manifest V3, these changes are meant for well-behaving extensions where they in fact improve security. As readers of this blog probably know, those who want to find loopholes will find them: I've already written about the Honey extension bundling its own JavaScript interpreter and malicious extensions...
https://palant.info/2025/01/20/malicious-extensions-circumvent-googles-remote-code-ban/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Chrome Web Store is a mess
Let's make one thing clear first: I'm not singling out Google's handling of problematic and malicious browser extensions because it is worse than Microsoft's for example. No, Microsoft is probably even worse but I never bothered finding out. That's because Microsoft Edge doesn't matter, its market share is too small. Google Chrome on the other hand is used by around 90% of the users world-wide, and one would expect Google to take their responsibility to protect its users very seriously, right? After all, browser extensions are one selling point of Google Chrome, so certainly Google would make sure they are safe? Unfortunately, my experience reporting numerous malicious or otherwise problematic browser extensions speaks otherwise. Google appears to take the “least effort required”...
https://palant.info/2025/01/13/chrome-web-store-is-a-mess/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

BIScience: Collecting browsing history under false pretenses
This is a guest post by a researcher who wants to remain anonymous. You can contact the author via email. Recently, John Tuckner of Secure Annex and Wladimir Palant published great research about how BIScience and its various brands collect user data. This inspired us to publish part of our ongoing research to help the extension ecosystem be safer from bad actors. This post details what BIScience does with the collected data and how their public disclosures are inconsistent with actual practices, based on evidence compiled over several years. Screenshot of claims on the BIScience website Contents Who is BIScience? BIScience collects data from millions of users BIScience buys data from partner third-party extensions BIScience receives raw...
https://palant.info/2025/01/13/biscience-collecting-browsing-history-under-false-pretenses/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

ClamAV 1.4 as Next Long-Term Stable (LTS)
We are excited to announce that ClamAV 1.4 is now designated as our latest Long-Term Stable (LTS) release. Previously, we planned to announce 1.5 as the next LTS version at the end of 2024. However, unforeseen challenges have delayed the 1.5 release, leading us to choose version 1.4 for long-term support. We apologize for any inconvenience that our delay in the announcement may have caused. The version support dates for ClamAV 1.4 are amended as follows: Key Dates: Initial 1.4 Release Date: August 15, 2024 Patch Versions Continue Until: August 15, 2027 DB Downloads Allowed Until: August 15, 2028 For specific details, please read the ClamAV EOL Policy. Looking ahead, the beta version of ClamAV 1.5 will soon be available for community review. This version will...
https://blog.clamav.net/2025/01/clamav-14-as-next-long-term-stable-lts.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
Performing a root cause analysis & building proof-of-concept for CVE-2024-38063, a CVSS 9.8 Vulnerability In the Windows Kernel IPv6 Parser
https://malwaretech.com/2024/08/exploiting-CVE-2024-38063.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Bypassing EDRs With EDR-Preloading
Evading user mode EDR hooks by hijacking the AppVerifier layer
https://malwaretech.com/2024/02/bypassing-edrs-with-edr-preload.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Silly EDR Bypasses and Where To Find Them
Abusing exception handlers to hook and bypass user mode EDR hooks.
https://malwaretech.com/2023/12/silly-edr-bypasses-and-where-to-find-them.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

An Introduction to Bypassing User Mode EDR Hooks
Understanding the basics of user mode EDR hooking, common bypass techniques, and their limitations.
https://malwaretech.com/2023/12/an-introduction-to-bypassing-user-mode-edr-hooks.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

It might Be Time to Rethink Phishing Awareness
Phishing awareness can be a powerful security tool, or a complete disaster. It all hinges on how you implement it.
https://malwaretech.com/2023/09/it-might-be-time-to-rethink-phishing-awareness.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

A Realistic Look at Implications of ChatGPT for Cybercrime
Analyzing ChatGPT's capabilities and various claims about how it will revolutionize cybercrime.
https://malwaretech.com/2023/02/a-realistic-look-at-chatgpt-cybercrime.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2022-3602 and CVE-2022-3786: OpenSSL 3.0.7 patches Critical Vulnerability
On Tuesday, November 1 2022 between 1300-1700 UTC, the OpenSSL project announced the release of a new version of OpenSSL (version 3.0.7) that will patch a critical vulnerability in OpenSSL version 3.0 and above. Only OpenSSL versions between 3.0 and 3.0.6 are affected at the time of writing. At this moment the details of this [...] The post CVE-2022-3602 and CVE-2022-3786: OpenSSL 3.0.7 patches Critical Vulnerability appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/general-tutorials/openssl-3-0-7-patches-critical-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Student Loan Breach Exposes 2.5M Records
2.5 million people were affected, in a breach that could spell more trouble down the line.
https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Watering Hole Attacks Push ScanBox Keylogger
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Tentacles of ‘0ktapus' Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
https://threatpost.com/0ktapus-victimize-130-firms/180487/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Ransomware Attacks are on the Rise
Lockbit is by far this summer's most prolific ransomware group, trailed by two offshoots of the Conti group.
https://threatpost.com/ransomware-attacks-are-on-the-rise/180481/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
https://threatpost.com/cybercriminals-are-selling-access-to-chinese-surveillance-cameras/180478/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Twitter Whistleblower Complaint: The TL;DR Version
Twitter is blasted for security and privacy lapses by the company's former head of security who alleges the social media giant's actions amount to a national security risk.
https://threatpost.com/twitter-whistleblower-tldr-version/180472/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Firewall Bug Under Active Attack Triggers CISA Warning
CISA is warning that Palo Alto Networks' PAN-OS is under active attack and needs to be patched ASAP.
https://threatpost.com/firewall-bug-under-active-attack-cisa-warning/180467/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Fake Reservation Links Prey on Weary Travelers
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
https://threatpost.com/reservation-links-prey-on-travelers/180462/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

iPhone Users Urged to Update to Patch 2 Zero-Days
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
https://threatpost.com/iphone-users-urged-to-update-to-patch-2-zero-days-under-attack/180448/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Google Patches Chrome's Fifth Zero-Day of the Year
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
https://threatpost.com/google-patches-chromes-fifth-zero-day-of-the-year/180432/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Installing Rogue-jndi on Kali Linux
Following the previous tutorial in which we looked at the log4j vulnerability in VMWare vSphere server, I got some questions about how to set up a malicious LDAP server on Linux. The attacker controlled LDAP server is required to provide the malicious java class (with a reverse shell for example) in response to the forged [...] The post Installing Rogue-jndi on Kali Linux appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/general-tutorials/installing-rogue-jndi-on-kali-linux/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Log4Shell VMware vCenter Server (CVE-2021-44228)
Log4Shell is a critical vulnerability with the highest possible CVSSv3 score of 10.0 that affects thousands of products running Apache Log4j and leaves millions of targets potentially vulnerable. CVE-2021-44228 affects log4j versions 2.0-beta9 to 2.14.1. Log4j is an incredibly popular logging library used in many different products and various Apache frameworks like Struts2, Kafka, and [...] The post Log4Shell VMware vCenter Server (CVE-2021-44228) appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/exploit-tutorials/log4shell-vmware-vcenter-server-cve-2021-44228/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How to customize behavior of AWS Managed Rules for AWS WAF
AWS Managed Rules for AWS WAF provides a group of rules created by AWS that can be used help protect you against common application vulnerabilities and other unwanted access to your systems without having to write your own rules. AWS Threat Research Team updates AWS Managed Rules to respond to an ever-changing threat landscape in order […]
https://aws.amazon.com/blogs/security/how-to-customize-behavior-of-aws-managed-rules-for-aws-waf/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The Great Leak: Microsoft Exchange AutoDiscover Design Flaw
Recently a “design flaw” in the Microsoft Exchange’s Autodiscover protocol was discovered by researchers that allowed access to 372,072 Windows domain credentials and 96,671 unique sets of credentials from applications such as Microsoft Outlook and third-party email clients. According to Amit Serper , the person who discovered the flaw, the source of the leak is [...] The post The Great Leak: Microsoft Exchange AutoDiscover Design Flaw appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/pentesting-exchange/the-great-leak-microsoft-exchange-autodiscover-design-flaw/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

The three most important AWS WAF rate-based rules
May 5, 2025: This post has been updated to reflect that the lowest allowable rate limit setting in AWS WAF rate-based rules has changed from 100 requests to 10. In this post, we explain what the three most important AWS WAF rate-based rules are for proactively protecting your web applications against common HTTP flood events, […]
https://aws.amazon.com/blogs/security/three-most-important-aws-waf-rate-based-rules/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Automatically update AWS WAF IP sets with AWS IP ranges
Note: This blog post describes how to automatically update AWS WAF IP sets with the most recent AWS IP ranges for AWS services. This related blog post describes how to perform a similar update for Amazon CloudFront IP ranges that are used in VPC Security Groups. You can use AWS Managed Rules for AWS WAF […]
https://aws.amazon.com/blogs/security/automatically-update-aws-waf-ip-sets-with-aws-ip-ranges/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AWS Shield threat landscape review: 2020 year-in-review
AWS Shield is a managed service that protects applications that are running on Amazon Web Services (AWS) against external threats, such as bots and distributed denial of service (DDoS) attacks. Shield detects network and web application-layer volumetric events that may indicate a DDoS attack, web content scraping, or other unauthorized non-human traffic that is interacting […]
https://aws.amazon.com/blogs/security/aws-shield-threat-landscape-review-2020-year-in-review/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

How to protect a self-managed DNS service against DDoS attacks using AWS Global Accelerator and AWS Shield Advanced
In this blog post, I show you how to improve the distributed denial of service (DDoS) resilience of your self-managed Domain Name System (DNS) service by using AWS Global Accelerator and AWS Shield Advanced. You can use those services to incorporate some of the techniques used by Amazon Route 53 to protect against DDoS attacks. […]
https://aws.amazon.com/blogs/security/how-to-protect-a-self-managed-dns-service-against-ddos-attacks-using-aws-global-accelerator-and-aws-shield-advanced/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Set up centralized monitoring for DDoS events and auto-remediate noncompliant resources
When you build applications on Amazon Web Services (AWS), it's a common security practice to isolate production resources from non-production resources by logically grouping them into functional units or organizational units. There are many benefits to this approach, such as making it easier to implement the principal of least privilege, or reducing the scope of […]
https://aws.amazon.com/blogs/security/set-up-centralized-monitoring-for-ddos-events-and-auto-remediate-noncompliant-resources/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Deploying defense in depth using AWS Managed Rules for AWS WAF (part 2)
In this post, I show you how to use recent enhancements in AWS WAF to manage a multi-layer web application security enforcement policy. These enhancements will help you to maintain and deploy web application firewall configurations across deployment stages and across different types of applications. In part 1 of this post I describe the technologies […]
https://aws.amazon.com/blogs/security/deploying-defense-in-depth-using-aws-managed-rules-for-aws-waf-part-2/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Defense in depth using AWS Managed Rules for AWS WAF (part 1)
In this post, I discuss how you can use recent enhancements in AWS WAF to manage a multi-layer web application security enforcement policy. These enhancements will help you to maintain and deploy web application firewall configurations across deployment stages and across different types of applications. The post is in two parts. This first part describes […]
https://aws.amazon.com/blogs/security/defense-in-depth-using-aws-managed-rules-for-aws-waf-part-1/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Houston consulate one of worst offenders in Chinese espionage, say U.S. officials
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: Reuters The United States ordered the consulate closed this week, leading China to retaliate on Friday by telling the United States to shut its consulate in the city of Chengdu, as relations between the world's two largest economies […] The post Houston consulate one of worst offenders in Chinese espionage, say U.S. officials appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/07/24/houston-consulate-one-of-worst-offenders-in-chinese-espionage-say-u-s-officials/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register The denizens of online forums dedicated to trading in stolen credit cards have been shown to be wretched hives of scum and villainy. This not-so-surprising news comes this week via academics at Washington State University (WSU) in the US, […] The post Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/07/24/shocked-i-am-shocked-to-find-that-underground-bank-card-trading-forums-are-full-of-liars-cheats-small-time-grifters/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

AWS Shield Threat Landscape report is now available
AWS Shield is a managed threat protection service that safeguards applications running on AWS against exploitation of application vulnerabilities, bad bots, and Distributed Denial of Service (DDoS) attacks. The AWS Shield Threat Landscape Report (TLR) provides you with a summary of threats detected by AWS Shield. This report is curated by the AWS Threat Research […]
https://aws.amazon.com/blogs/security/aws-shield-threat-landscape-report-now-available/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vint Cerf suggests GDPR could hurt coronavirus vaccine development
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register TCP-IP-co-developer Vint Cerf, revered as a critical contributor to the foundations of the internet, has floated the notion that privacy legislation might hinder the development of a vaccination for the COVID-19 coronavirus. In an essay written for […] The post Vint Cerf suggests GDPR could hurt coronavirus vaccine development appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/16/vint-cerf-suggests-gdpr-could-hurt-coronavirus-vaccine-development/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Brit defense contractor hacked, up to 100,000 past and present employees' details siphoned off – report
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Britain’s Ministry of Defence contractor Interserve has been hacked, reportedly leaking the details of up to 100,000 of past and current employees, including payment information and details of their next of kin. The Daily Telegraph reports that up to […] The post Brit defense contractor hacked, up to 100,000 past and present employees’ details siphoned off – report appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/16/brit-defense-contractor-hacked-up-to-100000-past-and-present-employees-details-siphoned-off-report/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

US officially warns China is launching cyberattacks to steal coronavirus research
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: CNN The US Department of Homeland Security and the FBI issued a “public service announcement” Wednesday warning that China is likely launching cyberattacks to steal coronavirus data related to vaccines and treatments from US research institutions and pharmaceutical […] The post US officially warns China is launching cyberattacks to steal coronavirus research appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/14/us-officially-warns-china-is-launching-cyberattacks-to-steal-coronavirus-research/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

There's Norway you're going to believe this: World's largest sovereign wealth fund conned out of m in cyber-attack
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register The Norwegian Investment Fund has been swindled out of m (£8.2m) by fraudsters who pulled off what’s been described as “an advance data breach.” Norfund – the world’s largest sovereign wealth fund, created from saved North Sea […] The post There’s Norway you’re going to believe this: World’s largest sovereign wealth fund conned out of m in cyber-attack appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/14/theres-norway-youre-going-to-believe-this-worlds-largest-sovereign-wealth-fund-conned-out-of-10m-in-cyber-attack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Stop tracking me, Google: Austrian citizen files GDPR legal complaint over Android Advertising ID
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Privacy pressure group Noyb has filed a legal complaint against Google on behalf of an Austrian citizen, claiming the Android Advertising ID on every Android device is “personal data” as defined by the EU’s GDPR and that […] The post Stop tracking me, Google: Austrian citizen files GDPR legal complaint over Android Advertising ID appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/14/stop-tracking-me-google-austrian-citizen-files-gdpr-legal-complaint-over-android-advertising-id/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Cyber-attacks hit hospital construction companies
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: BBC Interserve, which helped build Birmingham’s NHS Nightingale hospital, and Bam Construct, which delivered the Yorkshire and the Humber’s, have reported the incidents to authorities. Earlier this month, the government warned healthcare groups involved in the response to […] The post Cyber-attacks hit hospital construction companies appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/13/cyber-attacks-hit-hospital-construction-companies/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Security researchers at Comparitech have reported that an estimated 24,000 Android apps are leaking user data because of misconfigured Firebase databases. Firebase is a popular backend service with SDKs for multiple platforms, including Android, iOS, web, C++ and Unity (for […] The post Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/13/researchers-spot-thousands-of-android-apps-leaking-user-data-through-misconfigured-firebase-databases/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Papa don't breach: Contracts, personal info on Madonna, Lady Gaga, Elton John, others swiped in celeb law firm ‘hack'
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Hackers are threatening to release 756GB of A-list celebs’ contracts, recording deals, and other personal info allegedly stolen from a New York law firm. The miscreants have seemingly got their hands on confidential agreements, private correspondence, contact […] The post Papa don’t breach: Contracts, personal info on Madonna, Lady Gaga, Elton John, others swiped in celeb law firm ‘hack’ appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/13/papa-dont-breach-contracts-personal-info-on-madonna-lady-gaga-elton-john-others-swiped-in-celeb-law-firm-hack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

CVE-2019-19781: Citrix ADC RCE vulnerability
A week before the 2019 holidays Citrix announced that an authentication bypass vulnerability was discovered in multiple Citrix products. The affected products are the Citrix Application Delivery Controller (formerly known as NetScaler AD), Citrix Gateway NetScaler ADC (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP appliance. Exploiting the vulnerability could allow an unauthenticated attacker [...] The post CVE-2019-19781: Citrix ADC RCE vulnerability appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/exploit-tutorials/cve-2019-19781-citrix-adc-rce-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vulnerability Scanning with OpenVAS 9 part 4: Custom scan configurations
For all scans so far, we've only used the default scan configurations such as host discovery, system discovery and Full & fast. But what if we don't want to run all NVTs on a given target (list) and only test for a few specific vulnerabilities? In this case we can create our own custom scan [...] The post Vulnerability Scanning with OpenVAS 9 part 4: Custom scan configurations appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/openvas-9-part-4-custom-scan-configurations/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vulnerability Scanning with OpenVAS 9 part 3: Scanning the Network
In the previous parts of the Vulnerability Scanning with OpenVAS 9 tutorials we have covered the installation process and how to run vulnerability scans using OpenVAS and the Greenbone Security Assistant (GSA) web application. In part 3 of Vulnerability Scanning with OpenVAS 9 we will have a look at how to run scans using different [...] The post Vulnerability Scanning with OpenVAS 9 part 3: Scanning the Network appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-with-openvas-9-scanning-the-network/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning
Is the previous tutorial Vulnerability Scanning with OpenVAS 9.0 part 1 we've gone through the installation process of OpenVAS on Kali Linux and the installation of the virtual appliance. In this tutorial we will learn how to configure and run a vulnerability scan. For demonstration purposes we've also installed a virtual machine with Metasploitable 2 [...] The post Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-openvas-9-0-part-2/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)

Vulnerability Scanning with OpenVAS 9 part 1: Installation & Setup
A couple years ago we did a tutorial on Hacking Tutorials on how to install the popular vulnerability assessment tool OpenVAS on Kali Linux. We’ve covered the installation process on Kali Linux and running a basic scan on the Metasploitable 2 virtual machine to identify vulnerabilities. In this tutorial I want to cover more details [...] The post Vulnerability Scanning with OpenVAS 9 part 1: Installation & Setup appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-openvas-9-pt-1/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)