Toute l'actualité de la Cybersécurité


What We Missed: Delta Flight Disrupted With Wi-Fi Hack

2026-08-20 19:11:15
In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy....

Lire la suite »

PCAPdroid v2.0.0

2026-08-20 18:27:13
No-root network monitor, firewall and PCAP dumper for Android

Lire la suite »

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

2026-08-20 18:03:12
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new...

Lire la suite »

cloudquery plugins-destination-snowflake-v5.2.14

2026-08-20 17:57:11
Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from AWS, Azure, GCP, and 70+ cloud and SaaS sources.

Lire la suite »

Hackers poison arrayref Rust crate to push infostealer malware

2026-08-20 17:53:52
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]

Lire la suite »

N-able Bug Exposes Password Vault Master Keys

2026-08-20 17:39:24
The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?...

Lire la suite »

NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs

2026-08-20 17:36:49
NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning...

Lire la suite »

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

2026-08-20 17:32:51
Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress.

Lire la suite »

BLAKE3 v1.8.7

2026-08-20 17:27:23
Fast cryptographic hash function with PRF, MAC, KDF, and XOF modes. Supports verified streaming, incremental updates, and parallelized hashing via Merkle tree structure.

Lire la suite »

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, M Reward, GLM-5.3 AI Exploit and More

2026-08-20 17:23:48
A lot of this week's trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header...

Lire la suite »

CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users

2026-08-20 17:04:18
A limited CRLF injection flaw can be escalated into a severe HTTP desynchronization attack, poisoning CDN caches and delivering XSS payloads to users on legitimate websites. The attack, called CRLF-Powered...

Lire la suite »

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

2026-08-20 16:59:44
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity...

Lire la suite »

Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel

2026-08-20 16:39:41
Microsoft Defender's legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations, potentially enabling attackers with administrative...

Lire la suite »

Popular Rust Packages With 244M Downloads Compromised to Run Malware

2026-08-20 16:15:06
A major supply chain attack targeting the Rust ecosystem, in which two widely used crates, arrayref and append-only-vec, were hijacked to silently deliver malware the moment developers compiled their...

Lire la suite »

Self-Hosting AI Models on a Raspberry Pi 5: A Complete Guide to Free, Private, Local AI Inference

2026-08-20 15:59:59
This guide walks through exactly how I set it up, what works, what doesn't, and the specific models that actually run well on ARM hardware with limited RAM.

Lire la suite »

After 74 Days of Post-Quantum Blocks in Production, QoreChain's QOR Begins Trading on MEXC August 20

2026-08-20 15:31:13
QoreChain brings NIST-standardized post-quantum cryptography to a live Layer 1 as QOR begins trading on MEXC following 74 days of mainnet operation.

Lire la suite »

Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands

2026-08-20 15:24:09
A critical security flaw in NASA/JPL’s open-source AMMOS Instrument Toolkit GUI (AIT-GUI) could let an unauthenticated attacker send live commands to spacecraft and scientific instruments, run arbitrary...

Lire la suite »

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

2026-08-20 15:23:02
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost execution, and .rdata payload extraction. Includes 30+ C2...

Lire la suite »

Complement Your DevPost Hackathon with a HackerNoon Blogging Contest for Maximum Media Mentions

2026-08-20 15:07:48
Turn your Devpost hackathon into evergreen developer content with a HackerNoon Blogging Contest.

Lire la suite »

La France est-elle devenue une « passoire » ? Le manque de spécialistes en cybersécurité inquiète

2026-08-20 15:07:25
Le nombre de cyberattaques s'est multiplié ces derniers mois en France. Le marché de la cybersécurité est sous tension et la demande de nouvelles recrues n'a jamais été aussi forte. Le problème...

Lire la suite »

Meet the Wrap Pack: You Can Vibe Code Software, But You Can't Vibe Code Distribution

2026-08-20 15:00:06
Making money from AI, is not a secret formula; it's a very clear path and pattern.

Lire la suite »

We Tested ROLL Beauty for 19 Hours and Found Nine Bugs

2026-08-20 15:00:03
Built for Shipaton 2026, ROLL Beauty passed its simulator tests before a 19-hour real-world session exposed nine computer-vision bugs.

Lire la suite »

Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks

2026-08-20 14:59:22
A nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.

Lire la suite »

ChatGPT for Teens tackles risky chats and homework shortcuts

2026-08-20 14:44:31
OpenAI has strengthened ChatGPT's protections for teens, but some of its strongest parental controls still depend on linked accounts.

Lire la suite »

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

2026-08-20 14:39:48
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

Lire la suite »

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

2026-08-20 14:36:27
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to...

Lire la suite »

Banking Has Spent 20 Years Fighting Alert Noise. Engineering Should Learn From It

2026-08-20 14:11:59
Financial crime alerting runs at a 95% false positive rate. Twenty years of failing to fix it taught banking things engineering teams keep rediscovering.

Lire la suite »

Microsoft met fin à son offre Azure VMware Solution avec licences incluses

2026-08-20 14:06:50
Microsoft va retirer de son catalogue l'offre Azure VMware Solution (AVS) intégrant les licences. Les clients devront désormais apporter leurs propres licences VMware Cloud Foundation (VCF). The post...

Lire la suite »

How MSPs can catch phishing attacks email filters miss

2026-08-20 14:01:11
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect...

Lire la suite »

The TechBeat: How BlackBerry Reinvented Itself After Losing the Smartphone War (8/20/2026)

2026-08-20 14:00:53
8/20/2026: Trending stories on Hackernoon today!

Lire la suite »

66 Blog Posts To Learn About Macos

2026-08-20 14:00:02
Learn everything you need to know about Macos via these 66 free HackerNoon blog posts.

Lire la suite »

USN-8654-1: Netty vulnerabilities

2026-08-20 13:57:14
It was discovered that Netty did not properly handle malformed HTTP/2 control frames. An attacker could use this to cause a denial of service via resource exhaustion. This issue only affects Ubuntu 18.04...

Lire la suite »

ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones

2026-08-20 13:55:54
A new version of the ToxicPanda Android banking trojan is widening the danger for mobile users. The malware can steal banking PINs, imitate trusted screens, and take deeper control of infected phones...

Lire la suite »

Working From Home Is Healthier in Some Ways and Worse in Others

2026-08-20 13:50:39
Research links remote work to less movement, more musculoskeletal strain, and higher loneliness. Here's how to make a home workday healthier.

Lire la suite »

Spain's Wildfires Put Starlink's Direct-to-Cell Network to the Test

2026-08-20 13:50:30
Starlink Direct-to-Cell is providing emergency SMS in wildfire-hit parts of Spain after damaged telecom infrastructure cut mobile coverage.

Lire la suite »

Why Smaller Engineering Teams May Be Building Better Products

2026-08-20 13:50:24
AI coding tools don't guarantee productivity. Real gains come from redesigning engineering workflows, teams, and decision-making around them.

Lire la suite »

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

2026-08-20 13:48:24
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape...

Lire la suite »

Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes

2026-08-20 13:39:22
Hackers are using fake CAPTCHA pages to push a malware loader that can shut down security software before a follow-on payload runs. The campaign combines compromised WordPress websites, a familiar browser...

Lire la suite »

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

2026-08-20 13:35:13
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the...

Lire la suite »

Un institut français victime d'une cyberattaque : les données de 7 500 personnes compromises

2026-08-20 13:31:32
L'Institut de recherche pour le développement (IRD) a subi une cyberattaque exposant les données personnelles de 7 500 personnes. Les informations compromises comprennent notamment : nom, numéro de...

Lire la suite »

Ubuntu PostgreSQL Critical Buffer Overflow SQL Injection Vuln 8653-1

2026-08-20 13:30:44
Ubuntu released a security update addressing multiple vulnerabilities in PostgreSQL across various versions, allowing potential arbitrary code execution and sensitive information disclosure by authenticated...

Lire la suite »

wasm2c-tableflip

2026-08-20 13:30:20
wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Lire la suite »

'Grandoreiro' Malware Resurfaces With Mexico Campaign

2026-08-20 13:30:00
The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.

Lire la suite »

Twitch wants your content for Amazon AI training. Here's how to opt out

2026-08-20 13:28:01
Twitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.

Lire la suite »

MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data

2026-08-20 13:27:06
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud...

Lire la suite »

fnprint

2026-08-20 13:27:04
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Lire la suite »

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

2026-08-20 13:24:28
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability...

Lire la suite »

lg-webos-kexec

2026-08-20 13:23:15
Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs kernel build flow.

Lire la suite »

New Android Malware Steals Banking PINs and Relays Data Through Someone Else's Infected Phones

2026-08-20 13:20:41
A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick researchers rarely see in the wild: when an infected phone has no internet...

Lire la suite »

New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts

2026-08-20 13:18:20
Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as “CRLF-Powered Desync Attacks.” This...

Lire la suite »

reconkg

2026-08-20 13:17:49
Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification commands classified by what running them does to the target....

Lire la suite »

Club One Casino revendiqué par 3AM puis PEAR

2026-08-20 13:15:42
Hack Twins : Un nouveau casino apparaît chez deux groupes de pirates informatiques différents.

Lire la suite »

File-Tunnel v3.5.2

2026-08-20 13:14:33
Tunnel TCP connections through a file

Lire la suite »

Avec OpenRouter, Stripe veut contrôler la facture de l'IA

2026-08-20 13:08:38
Avec le rachat d'OpenRouter, Stripe s'attaque à l'autre versant de l'économie des modèles : le coût de chaque requête, de chaque token et, à terme, de chaque agent IA. The post Avec OpenRouter,...

Lire la suite »

An Air Gap Doesn't Remove the Supply Chain. It Makes Every Crossing a Decision.

2026-08-20 13:00:02
For years, air-gapped environments have been the gold standard for protecting classified systems and critical infrastructure. Isolate the network, remove the path, reduce the risk. The logic...

Lire la suite »

Coinkite's AI Audit Didn't Fail. It Was Pointed in the Wrong Direction

2026-08-20 12:58:52
A 4M Bitcoin bug hid for five years. I found it with AI in minutes, three times out of three. The vendor's own AI audit missed it. Here's why.

Lire la suite »

Editorial Style Videos Are The Cutting Edge Of Cybersecurity Journalism

2026-08-20 12:58:27
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 20, 2026 – Read the Full Story An editorial style video uses journalistic narration and storytelling, changing...

Lire la suite »

context-aware-offensive-intelligence

2026-08-20 12:57:56
Research framework redefining post-exploitation through decision intelligence.

Lire la suite »

Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox to Steal Payments

2026-08-20 12:54:55
A single phishing email was enough to give attackers access to a finance employee's Microsoft 365 account and redirect vendor payments. The incident shows how criminals can bypass multi-factor authentication...

Lire la suite »

New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments

2026-08-20 12:52:23
Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC payments. This attack exploits a vulnerability...

Lire la suite »

Your Mac already has a built-in firewall. Here's how to get more from it

2026-08-20 12:45:00
Malwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall.

Lire la suite »

Zapscape-Fix — Updated!

2026-08-20 12:44:56
Generic kernel live patch for the KVM/x86 shadow-MMU use-after-free (Zapscape, CVE-2026-64561)

Lire la suite »

SFR confirme une fuite de données, 2,1 millions de lignes revendiquées par le pirate des impôts

2026-08-20 12:34:05
Détectée le 2 juillet, la fuite n'arrive dans les boîtes mail des clients que sept semaines plus tard. Sur un forum cybercriminel, un pirate revendiquait entre-temps 2,1 millions de lignes extraites...

Lire la suite »

Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution

2026-08-20 12:32:34
Zyxel has released firmware updates for a high-severity command injection vulnerability, tracked as CVE-2026-6837, affecting 18 wireless access point models. The flaw exists in the export-cgi component...

Lire la suite »

Citrix urges admins to patch new NetScaler flaws as soon as possible

2026-08-20 12:14:38
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]

Lire la suite »

OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities

2026-08-20 12:05:43
OpenAI has temporarily slowed the development of its latest frontier AI models after initial testing suggested that its upcoming Astra system may meet the company's “Critical” cybersecurity...

Lire la suite »

Fuite Stripe : au moins 200 Français concernés

2026-08-20 12:04:18
Fuite Stripe : ZATAZ confirme au moins 200 Français concernés et propose une vérification gratuite et humaine.

Lire la suite »

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

2026-08-20 12:01:24
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale...

Lire la suite »

Managing the cyber risk of agentic AI

2026-08-20 12:00:00
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.

Lire la suite »

ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays

2026-08-20 11:58:50
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input...

Lire la suite »

9 million images of people's faces exposed by reverse lookup service

2026-08-20 11:50:54
A researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.

Lire la suite »

Why "Shady AI" is Security's Next Big Governance Problem

2026-08-20 11:45:00
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren't authorized to access it.  The incident began...

Lire la suite »

USN-8653-1: PostgreSQL vulnerabilities

2026-08-20 11:42:58
It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when an early failure occurred. An authenticated user could possibly use this issue to execute arbitrary SQL commands. (CVE-2026-6464) It...

Lire la suite »

Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files

2026-08-20 11:42:09
Cisco has issued security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to access sensitive configuration files on affected systems. This...

Lire la suite »

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

2026-08-20 11:39:35
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the...

Lire la suite »

audit-kernel v7.2

2026-08-20 11:38:16
GitHub mirror of the Linux Kernel's audit repository

Lire la suite »

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

2026-08-20 11:26:08
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions,...

Lire la suite »

Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security

2026-08-20 11:12:34
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually...

Lire la suite »

Palo Alto Networks lance son programme Frontier AI Critical Defense

2026-08-20 11:11:03
En coalisant des acteurs majeur autour d'un dispositif de correctifs virtuels proactifs, Palo Alto Networks veut combler le décalage entre la vitesse des cyberattaques propulsées par l'IA et la capacité...

Lire la suite »

CISA warns of hackers exploiting critical MLflow vulnerability

2026-08-20 11:06:14
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]...

Lire la suite »

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

2026-08-20 11:05:11
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker...

Lire la suite »

Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services

2026-08-20 10:49:16
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has...

Lire la suite »

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

2026-08-20 10:38:28
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting...

Lire la suite »

Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE

2026-08-20 10:34:25
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app....

Lire la suite »

Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud

2026-08-20 10:28:26
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle...

Lire la suite »

Oracle Linux 10 yggdrasil Important CVE-2026-33810 Advisory ELSA-2026-57126

2026-08-20 10:25:53
Oracle Linux 10 has released updates for the yggdrasil package, fixing CVE-2026-33810 and rebuilding it against an updated golang. New RPMs are available for x86_64 and aarch64.

Lire la suite »

Oracle Linux glib2 Moderate D-Bus Buffer Overflow Patch ELSA-2026-57015

2026-08-20 10:25:52
Oracle Linux 10 has updated glib2 packages available, addressing multiple CVEs including buffer overflows and validation issues to enhance security and system stability.

Lire la suite »

Oracle perl-Date-Manip Important DoS Fix ELSA-2026-56971

2026-08-20 10:25:50
Oracle Linux Security Advisory ELSA-2026-56971 announces updated rpms for version 10 to address CVE-2026-60075, fixing a potential regex DoS vulnerability in date/time parsing.

Lire la suite »

Oracle Linux PHP 8.4 Important Bug Fix Advisory ELSA-2026-56969

2026-08-20 10:25:49
Oracle Linux has released updates for PHP 8.4.24 addressing CVEs 2026-17543 and 2026-17544, with new RPMs for x86_64 and aarch64 architectures available via the Unbreakable Linux Network.

Lire la suite »

Oracle Linux MySQL 8.4 Important Bug Fix Advisory ELSA-2026-56007

2026-08-20 10:25:47
Oracle Linux 10 has new MySQL 8.4.11 packages addressing multiple CVEs, enhancing security. The updates include various components for x86_64 and aarch64 architectures available via the Unbreakable Linux...

Lire la suite »

Oracle Linux curl Important Update ELSA-2026-55450 Fixing Multiple Issues

2026-08-20 10:25:46
Oracle Linux 10 has received updated RPMs for curl due to several vulnerabilities, including fixes for proxy issues, OAuth2 token leakage, and connection reuse problems, addressing numerous CVEs.

Lire la suite »

Oracle Kernel Important Advisory ELSA-2026-38492 CVE-2026-43163

2026-08-20 10:25:44
Oracle Linux 10 has received an update with various kernel RPMs addressing multiple CVEs, enhancing security and adding new certificates, along with numerous bug fixes across different subsystems.

Lire la suite »

Oracle Linux 9 .NET 10.0 Bug Fix Important Advisory ELSA-2026-55857

2026-08-20 10:25:27
Oracle Linux 9 has updated RPMs for .NET SDK and runtime, addressing several CVEs and adding Oracle Linux support, with versions released for both x86_64 and aarch64 architectures.

Lire la suite »

Oracle Linux 9 ELSA-2026-55856 .NET 9.0 Important Security Advisory

2026-08-20 10:25:25
Oracle Linux released updates for .NET SDK and runtime, addressing multiple CVEs and adding support for Oracle Linux 9, with packages available for x86_64 and aarch64 architectures.

Lire la suite »

Oracle Linux Nodejs Important Memory Exhaustion Fix ELSA-2026-55603

2026-08-20 10:25:22
Oracle Linux updated multiple Node.js packages to address several CVEs, including vulnerabilities related to memory exhaustion and IP address issues, improving overall security for users.

Lire la suite »

Oracle Python3 Important CVE-2026-11940 Advisory ELSA-2026-56219

2026-08-20 10:24:36
Oracle has released updated RPMs for Oracle Linux 8 that include security fixes for CVE-2026-11940, with packages for various architectures now available on the Unbreakable Linux Network.

Lire la suite »

New Manic Android malware can exfiltrate data through nearby devices

2026-08-20 10:02:02
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]

Lire la suite »

Identity Abuse Through Trusted Communication Channels

2026-08-20 10:00:25
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication...

Lire la suite »

Critical Zimbra RCE flaw now actively exploited in attacks

2026-08-20 09:46:54
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]

Lire la suite »

Vous pensiez votre carte bancaire expirée inutilisable ? Cette démonstration prouve le contraire

2026-08-20 09:03:48
Une carte bancaire expirée ne devrait plus permettre de payer. Pourtant, des chercheurs ont découvert une méthode permettant, dans certaines conditions, de contourner cette limite. L'attaque repose...

Lire la suite »

U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog

2026-08-20 08:55:52
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added...

Lire la suite »

US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign

2026-08-20 08:36:37
The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public,...

Lire la suite »

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

2026-08-20 07:20:41
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation,...

Lire la suite »

Microsoft says August Windows updates may cause gaming issues

2026-08-20 06:51:03
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]

Lire la suite »

OpenAI confirms ChatGPT is down as logins and signups fail

2026-08-20 00:20:55
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

Lire la suite »

List of 114 new domains

2026-08-20 00:00:00
.fr 1nstantcas1no[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) 21bitcoin[.fr] (registrar: INWX GmbH) 5emeregimentdehussards-weingarten[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) apiprime[.fr]...

Lire la suite »

Multiples vulnérabilités dans les produits Splunk (20 août 2026)

20/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...

Lire la suite »

Multiples vulnérabilités dans Ceph (20 août 2026)

20/08/2026
De multiples vulnérabilités ont été découvertes dans Ceph. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un contournement...

Lire la suite »

Multiples vulnérabilités dans les produits Cisco (20 août 2026)

20/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...

Lire la suite »

Multiples vulnérabilités dans les produits Citrix (20 août 2026)

20/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité...

Lire la suite »

Multiples vulnérabilités dans Microsoft Windows (20 août 2026)

20/08/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Elles permettent à un attaquant de provoquer une élévation de privilèges et une atteinte à la confidentialité des données....

Lire la suite »