Toute l'actualité de la Cybersécurité


GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations

2026-07-25 17:20:48
A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations,...

Lire la suite »

Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable

2026-07-25 16:07:02
A well-known AI red teamer claims to have developed a universal jailbreak that works against leading large language models, including heavily guarded flagships such as GPT-5.6 Sol, Claude Opus 5, and...

Lire la suite »

openSUSE Tumbleweed python313-astropy Moderate Threat CVE-2023-41334

2026-07-25 15:36:46
An update for python313-astropy-8.0.1-1.1 on openSUSE Tumbleweed addresses the CVE-2023-41334 vulnerability, improving security for affected users.

Lire la suite »

openSUSE perl-XML-Bare Moderate Security Issue 2026-11351-1

2026-07-25 15:36:46
openSUSE Tumbleweed has released an update for perl-XML-Bare-0.53-7.1 addressing two vulnerabilities, improving security with moderate ratings and CVSS scores of 6.1 and 6.2.

Lire la suite »

openSUSE Tumbleweed perl-HTTP-Date Moderate Threat Advisory CVE-2026-14741

2026-07-25 15:36:46
An update for perl-HTTP-Date-6.80.0-1.1 on openSUSE Tumbleweed addresses a vulnerability identified as CVE-2026-14741, providing security improvements for users.

Lire la suite »

openSUSE Tumbleweed proftpd Moderate Security Issue CVE-2026-42167

2026-07-25 15:36:46
openSUSE Tumbleweed has released an update for proftpd-1.3.9c-1.1 addressing a vulnerability rated moderate, specifically CVE-2026-42167, which impacts various proftpd packages.

Lire la suite »

openSUSE google-osconfig-agent Moderate Security Threat Vuln 2026-11349-1

2026-07-25 15:36:46
The google-osconfig-agent-20260708.00-3.1 update for openSUSE Tumbleweed addresses a vulnerability identified as CVE-2026-56852, rated as moderate with CVSS scores indicating potential impact.

Lire la suite »

openSUSE Tumbleweed 2026-11346-1 Chromedriver Moderate Security Update

2026-07-25 15:36:45
An update for openSUSE Tumbleweed addresses 12 vulnerabilities in chromedriver version 150.0.7871.181-1.1, requiring installation for improved security.

Lire la suite »

openSUSE Tumbleweed ffmpeg Moderate Security Issues Fix 2026-11347-1

2026-07-25 15:36:45
An update for ffmpeg on openSUSE Tumbleweed addresses two vulnerabilities, providing fixes for security issues rated moderate, with specific CVEs and CVSS scores noted.

Lire la suite »

openSUSE amazon-ecs-init Moderate Access Risk Vuln 2026-11345-1

2026-07-25 15:36:45
An openSUSE Tumbleweed update for amazon-ecs-init addresses a vulnerability, CVE-2026-56852, rated moderate, with various CVSS scores indicating severity and impact.

Lire la suite »

10 Best ZTNA Solutions (Zero Trust Network Access) In 2026

2026-07-25 15:28:00
Zero Trust Network Access (ZTNA) anchors 2026 cybersecurity amid remote, cloud, and hybrid booms. ZTNA solutions aren’t hype—they’re vital for data locks, compliance wins, and borderless...

Lire la suite »

Australian energy provider Origin Energy disclosed a data breach impacting customer data

2026-07-25 15:21:19
Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after...

Lire la suite »

Malicious sites use JavaScript to build malware in browser memory

2026-07-25 15:21:09
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]

Lire la suite »

ShinyHunters data leaks fuel ,000 sextortion email scam

2026-07-25 14:16:26
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding ,000 in Bitcoin. [...]

Lire la suite »

The TechBeat: Vibe Coding Gets You 80% There. This Is What the Other 20% Requires. (7/25/2026)

2026-07-25 14:00:49
7/25/2026: Trending stories on Hackernoon today!

Lire la suite »

405 Blog Posts To Learn About Development

2026-07-25 14:00:15
Learn everything you need to know about Development via these 405 free HackerNoon blog posts.

Lire la suite »

Don't Buy an Uncensored AI on a Flash Drive: What You Can Do Instead

2026-07-25 14:00:02
A look at how flash-drive local AI kits sell convenience, while the same private offline setup is already free with Ollama or open source tools.

Lire la suite »

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

2026-07-25 12:52:43
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute...

Lire la suite »

How to Diagnose Production Bugs When You Can't Reproduce Them Locally

2026-07-25 11:00:08
Learn how to diagnose production-only bugs using logs, metrics, distributed tracing, and environment analysis — and why a PaaS makes debugging far easier.

Lire la suite »

How Daylight Security's Viral Videos Turned The CISO Genie Into A Black Hat Sensation

2026-07-25 10:44:18
build a booth, showcase a product and try to convince security leaders to make time for a conversation.

Lire la suite »

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

2026-07-25 10:14:26
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3...

Lire la suite »

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

2026-07-25 10:14:21
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts...

Lire la suite »

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

2026-07-25 10:14:03
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part...

Lire la suite »

Fuites de données : la France devient la victime numéro un d'Europe, c'est de pire en pire

2026-07-25 10:00:33
Avec 43,4 millions de comptes piratés entre janvier et juin 2026, la France s'impose comme le pays le plus touché d'Europe par les fuites de données. C'est également le second pays le plus touché...

Lire la suite »

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

2026-07-25 09:53:41
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects...

Lire la suite »

OpenAI confirms ChatGPT is down worldwide

2026-07-25 09:31:09
ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. [...]

Lire la suite »

Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks

2026-07-25 08:02:36
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers...

Lire la suite »

Google Launches Unified Cryptonym-Based Naming System for Threat Actors

2026-07-25 07:35:24
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies...

Lire la suite »

Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials

2026-07-25 07:25:13
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data,...

Lire la suite »

Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks

2026-07-25 06:28:42
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs)...

Lire la suite »

Un hacker russe se sert de Gemini pour piloter son botnet à sa place

2026-07-25 06:02:46
Un pirate russe a détourné Gemini pour piloter à distance un botnet. Pour convaincre l'IA de se plier à ses demandes, le hacker s'est servi de tactiques de manipulation très simples.

Lire la suite »

AI is Turning Managers Into Governance Actors

2026-07-25 06:00:02
AI will not eliminate management. It will test whether management can remain legitimate when decisions are increasingly mediated by machines.

Lire la suite »

DATA Network Surpasses 100 Million Registrations as $DATA Trading Competition Opens on Upbit

2026-07-25 05:43:19
The milestone comes alongside a growing onchain revenue model for real-world AI data, as Upbit runs a four-day $DATA trading competition for eligible users

Lire la suite »

Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices

2026-07-25 03:36:03
Foxit PDF Reader has been found vulnerable to a local privilege escalation flaw that allows standard Windows users to gain full SYSTEM-level control under specific conditions. The issue, tracked as CVE-2026-57239,...

Lire la suite »

Kevin Feige Gives Hint About the Future of the MCU

2026-07-25 03:12:11
Kevin Feige talks about the future of the MCU post Avengers: Secret Wars.

Lire la suite »

132 Blog Posts To Learn About Developers

2026-07-25 02:00:11
Learn everything you need to know about Developers via these 132 free HackerNoon blog posts.

Lire la suite »

List of 21 new domains

2026-07-25 00:00:00
.fr achat-eliorgroup[.fr] (registrar: Hostinger operations UAB) amndesgouv[.fr] (registrar: PLANETHOSTER) antafrance[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) authsuiviappro[.fr] (registrar:...

Lire la suite »