Toute l'actualité de la Cybersécurité
Mate Security Grows Over 500% Since Q3 2025 and Pushes Past M in Funding
2026-07-28 19:09:53
Mate Security secures M in Series A funding after 500% growth, as Fortune 500 demand grows for its agentic AI security operations platform worldwide.
Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
2026-07-28 19:07:43
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet...
Ubuntu FreeRDP RDP Client Significant Clipboard Regression Fix USN-8561-2
2026-07-28 19:02:55
A regression affecting clipboard functionality in FreeRDP was introduced in an earlier security update. Users should update to resolve the issue in Ubuntu 26.04 LTS and 24.04 LTS.
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
2026-07-28 18:59:07
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128.
The HAWK attack exploits a previously...
CISA shares advice on isolating vital systems during cyberattacks
2026-07-28 18:41:04
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or...
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
2026-07-28 18:32:03
OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain...
Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years
2026-07-28 18:24:07
Anthropic researchers using Claude Mythos Preview have uncovered mathematical flaws in major cryptographic algorithms that human experts failed to spot for years. The AI found improved attacks against...
vBulletin fixes critical pre-auth RCE flaw with public exploit
2026-07-28 18:08:50
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
USN-8561-2: FreeRDP regression
2026-07-28 18:08:13
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to
version 3.30.0 introduced a regression in the clipboard functionality. This
update fixes the problem.
We apologize for the inconvenience.
Original...
JetBrains Urging Customers to Patch Critical TeamCity Flaw that Enables OS Command Execution
2026-07-28 17:46:13
JetBrains has urgently released security updates for a critical vulnerability in TeamCity On-Premises that could allow remote attackers to bypass authentication and execute arbitrary operating system...
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
2026-07-28 17:40:32
Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth device-code flow abuse and adversary-in-the-middle (AiTM)...
PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites
2026-07-28 17:34:10
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.
Chrome Extension Monitors AI Conversations Across ChatGPT, Claude, Gemini, and Other Platforms
2026-07-28 17:24:03
A Chrome extension with roughly 100,000 installs is quietly harvesting every prompt and AI response typed across nine major artificial intelligence platforms. Despite its official listing and privacy...
Mageia 10 gstreamer1.0-libav Heap Corruption CVE-2026-52717
2026-07-28 17:07:40
A security advisory reported heap corruption in the gst-libav AV protocol pipe, affecting Mageia release 10, linked to CVE-2026-52717.
Mageia libslirp Critical TCP OOB Read Info Leak Vulnerability CVE-2026-9539
2026-07-28 17:07:39
Mageia releases 10 and 9 have updates addressing a security vulnerability related to TCP URG OOB Read Information Leak (CVE-2026-9539).
Nginx Buffer Overflow Vulnerability Allows Attackers to Execute Arbitrary Code – PoC Released
2026-07-28 16:46:41
A high-severity heap buffer overflow in NGINX Plus and NGINX Open Source can let unauthenticated attackers crash worker processes and, under certain conditions, run arbitrary code. Tracked as CVE-2026-42533,...
openSUSE Kernel Important Patch Fixing Five Issues 2026-3319-1
2026-07-28 16:41:54
A security update for SUSE Linux Kernel fixes five vulnerabilities, enhancing system protection via recommended installation methods for affected products including SUSE Linux Enterprise Server and openSUSE...
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
2026-07-28 16:38:48
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak
2026-07-28 16:28:04
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.
Debian hplip Important Escalation and Code Exec Risks DSA-6402-1
2026-07-28 16:13:19
Debian addresses two vulnerabilities in hplip that could lead to privilege escalation or code execution, urging users to upgrade to the fixed version 3.22.10+dfsg0-8.1+deb13u1.
Click to pray expose les données de plus de 700 000 fidèles
2026-07-28 16:06:07
Click To Pray expose 700 000 comptes via une faille idiote, avec un risque élevé de phishing ciblé et d'usurpation.
Rethinking Ransomware Defense at the Filesystem Layer
2026-07-28 16:00:38
Ransomware defense using fanotify and append only archives
Formatif Earns a 44 Proof of Usefulness Score by Building a 100% Offline, Local-First Desktop Media Processing Suite
2026-07-28 16:00:16
Formatif earned a 44 Proof of Usefulness score for running 59 media-processing and AI enhancement tools entirely on local hardware.
Disrupting supply chain attacks on npm and GitHub Actions
2026-07-28 16:00:00
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.
The post Disrupting supply chain attacks on npm...
The Future of Human Work: Finding Our Place in the Age of AI
2026-07-28 15:56:23
As AI takes over more cognitive tasks, are we losing the skills that make us human? Explore how AI is reshaping learning, work, and human purpose.
openSUSE Leap 16.0 Chromium Important Use After Free Issues 2026-21453-1
2026-07-28 15:53:18
openSUSE has released a security update for Chromium addressing four vulnerabilities, including out-of-bounds write and use-after-free issues, along with a bug fix for Leap 16.0.
openSUSE Leap 16.0 agama-web-ui Important Security Patch SUSE-2026-21448-1
2026-07-28 15:52:39
openSUSE released a security update for agama-web-ui addressing 13 vulnerabilities with 14 bug fixes, focusing on various issues related to data handling and security exploits.
SwiftList Earns a 83.84 Proof of Usefulness Score by Building an AI Platform for Generating Complete Property Listings
2026-07-28 15:43:42
SwiftList earned an 83.84 Proof of Usefulness score for turning property photos and details into complete real estate marketing packages.
Aembit Joins Snowflake to Tackle AI's Next Security Frontier: Trusted Agent Interoperability
2026-07-28 15:16:19
Silver Spring, MD, USA, 28th July 2026, CyberNewswire
openSUSE Tumbleweed valkey Moderate Security Update 2026-11381-1
2026-07-28 15:37:19
An update for openSUSE Tumbleweed addresses two vulnerabilities in the valkey package, rated moderate, with CVSS scores of 7.5 and 8.8.
openSUSE Tumbleweed python313-CherryPy Moderate Issue CVE-2019-9740
2026-07-28 15:37:18
An update for python313-CherryPy-18.10.0-4.1 on openSUSE Tumbleweed addresses a vulnerability identified as CVE-2019-9740, rated moderate with a CVSS score of 5.4.
openSUSE Libssh Moderate Security Advisory CVE-2026-15370 CVE-2026-59843
2026-07-28 15:37:18
An update for openSUSE Tumbleweed's libssh-config-0.11.5-1.1 addresses nine vulnerabilities with various CVSS scores, enhancing overall security for affected users.
openSUSE Ignition Important Security Issues Fix 2026-11376-1
2026-07-28 15:37:18
An update for ignition-2.26.0-5.1 on openSUSE Tumbleweed addresses three security vulnerabilities identified by CVEs, with varying severity ratings and CVSS scores.
Designing for Human Confidence: Why Trust Alone Isn't Enough for AI Products
2026-07-28 15:36:06
Trust is the outcome, not the starting point. Discover why confidence should be the primary design objective for AI-native products.
Wi-Fi public : ce que votre fournisseur, pirates et marketing peuvent voir
2026-07-28 15:29:46
En voyage, découvrez ce que votre fournisseur ou pirate voient et comment protéger vos données sur un Wi-Fi public.
itsfolio.tech Earns a 50 Proof of Usefulness Score by Building an AI-Powered Resume-to-Portfolio Converter
2026-07-28 15:28:04
itsfolio.tech earned a 50 Proof of Usefulness score for turning resume PDFs into fully hosted online portfolios in seconds.
Agent Memory Has a Lock-In Problem. Open Formats Are How We Fix It.
2026-07-28 15:20:49
AI agents shouldn't lose their memories when you switch platforms. Learn how Open Knowledge Format (OKF) enables portable, version-controlled agent memory.
Smart Care Triage Earns a 35.03 Proof of Usefulness Score by Building a Decision-Support Tool for Hospital Intake
2026-07-28 15:19:47
Smart Care Triage earned a 35.03 Proof of Usefulness score for using explainable AI to support faster, safer hospital intake decisions.
Debian Samba Important DoS and Privilege Escalation DSA-6401-1
2026-07-28 15:16:55
Debian issued advisory DSA-6401-1 on July 28, 2026, regarding multiple vulnerabilities in Samba that could lead to denial of service, domain takeover, information disclosure, or privilege escalation,...
Apple iOS 26.6 Fixes Flaws Enabling Kernel Code Execution, Root Access and Sandbox Escape
2026-07-28 15:15:50
Apple has released iOS 26.6 and iPadOS 26.6 to address a significant number of security vulnerabilities, including flaws that could allow malicious applications to execute code with kernel privileges,...
HostLens AI Earns a 55.35 Proof of Usefulness Score by Building an Agentic GraphRAG AI Assistant for Rental Market Insights
2026-07-28 15:14:04
HostLens AI earned a 55.35 Proof of Usefulness score for using GraphRAG and Airbnb data to assess rental ROI and market viability.
Votre iPhone doit être mis à jour sans attendre : ce qu'Apple vient de corriger est inquiétant
2026-07-28 15:07:16
Apple déploie une nouvelle mise à jour pour l'iPhone. Derrière quelques changements discrets se cache surtout plus de 75 correctifs de sécurité, un chiffre élevé en partie attribué aux outils...
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
2026-07-28 15:01:33
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process.
If that happens, Tengu's other persistence mechanisms...
Electric Vehicles Have Gotten Better, But Have They Earned Your Trust Yet?
2026-07-28 15:00:43
Do drivers finally trust electric vehicles? Explore HackerNoon poll results, EV adoption trends, charging concerns, and Tesla prediction markets.
The Next AI War Will Be Fought Over Access, Not Models.
2026-07-28 14:56:25
The next AI race won't be won by the smartest model. Discover why compute access, infrastructure, and national AI strategy may define the future instead.
Microsoft lance MAI-Cyber-1-Flash et pousse l'IA au cœur du SOC
2026-07-28 14:49:49
MAI-Cyber-1-Flash est le premier modèle d'IA conçu pour la cybersécurité. Intégré à MDASH, il promet d'accélérer la détection des failles tout en réduisant le coût des opérations.
The post...
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
2026-07-28 14:41:36
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol...
The TechBeat: A Developer's Guide to Agentic AI Frameworks and Components (7/28/2026)
2026-07-28 14:01:06
7/28/2026: Trending stories on Hackernoon today!
Is Your SSO Protected Against Modern Credential Attacks?
2026-07-28 14:00:10
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening...
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
2026-07-28 13:33:47
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.
Artifactory is JFrog's software repository...
From Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global Investing
2026-07-28 13:28:34
See how stablecoins, tokenized stocks and fractional investing lower costs and expand global access to US markets through modern financial super apps worldwide.
Fake Claude Code Install Guide Uses Google Ads to Deliver MacSync Infostealer
2026-07-28 13:23:35
Fake Google Ads are being used to push a convincing Claude Code installation guide that delivers the MacSync infostealer to macOS users. The campaign turns an ordinary developer search into a path for...
Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations
2026-07-28 13:10:52
A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against organizations in the United States, putting Java applications that process untrusted JSON at immediate risk....
Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads
2026-07-28 13:02:24
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses...
Origin Confirms Data Breach – Hackers Accessed 900,000 Customers' Data
2026-07-28 13:01:41
Origin Energy, an Australian energy provider, has confirmed that unauthorized access to customer information has affected approximately 900,000 current and former customers. The company has completed...
AI Changes the Software Supply Chain and How We Secure It
2026-07-28 13:00:06
Artificial intelligence is expanding the software supply chain beyond traditional software components, introducing new dependencies that require security leaders to rethink how software is governed....
Rapid7 Cyber GRC is now available: Turn security action into compliance proof
2026-07-28 13:00:00
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to...
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
2026-07-28 13:00:00
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape...
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
2026-07-28 12:56:14
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.
The critical issue, tracked as CVE-2026-53921...
Réseaux sociaux : ce qui changera en 2026 et 2027
2026-07-28 12:56:07
Réseaux sociaux interdits aux moins de 15 ans : calendrier, contrôle d'âge, risques cyber et leçons australiennes.
Kimi K3 : comment Moonshot AI est passé à l'échelle
2026-07-28 12:51:32
Le rapport technique de Kimi K3 témoigne d'un chantier sur trois grands axes pour tenir l'échelle des (quasi) 3 milliards de paramètres et 1000 experts.
The post Kimi K3 : comment Moonshot AI est passé...
We rebuilt Malwarebytes Mobile Security for the scams of today
2026-07-28 12:40:00
Your phone needs more than a lock screen to stay safe. We've rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
Shared Claude chats were searchable on Google
2026-07-28 12:33:11
Reddit users found that by using a specific search query, they could find shared Claude conversations in search results.
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
2026-07-28 12:32:24
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure...
Former Citigroup CISO Blauner on What Makes A Great Security Leader
2026-07-28 12:30:00
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
Public Exploit Lands for vBulletin's Pre-Auth RCE, CVE-2026-61511
2026-07-28 12:18:07
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection works and who still needs to patch.
Public Exploit Lands for vBulletin’s...
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
2026-07-28 12:10:23
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
When cyber attacks happen: helping organisations recover
2026-07-28 12:00:00
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
2026-07-28 11:55:20
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities...
USN-8621-1: Samba vulnerabilities
2026-07-28 11:50:00
It was discovered that Samba's pam_winbind incorrectly handled home
directory ownership when mkhomedir was enabled. A local attacker could
possibly use this issue to cause a denial of service by triggering...
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
2026-07-28 11:36:44
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings...
Update your iPhone, iPad and Mac to fix Apple security holes
2026-07-28 11:35:40
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.
Confidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in Use
2026-07-28 11:24:52
Modern AI runs on shared, high-performance infrastructure that processes enormous volumes of sensitive data and valuable model weights.…
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
2026-07-28 11:17:06
JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after...
Vatican’s Click To Pray app exposed personal data from 700,000 users
2026-07-28 11:11:36
Anyone could access other Click To Pray users' personal information. The flaw went unfixed for more than six months after it was reported.
Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands
2026-07-28 10:58:50
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system...
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
2026-07-28 10:50:55
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations
Nvidia mise gros sur le mystère Sutskever
2026-07-28 10:40:13
Nvidia investit environ 5 milliards $ dans Safe Superintelligence, le laboratoire très secret d'Ilya Sutskever, pour sécuriser un nouveau client stratégique face à la concurrence.
The post Nvidia...
Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations
2026-07-28 10:38:26
Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations, with evidence pointing...
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
2026-07-28 10:34:07
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in...
Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal
2026-07-28 09:47:56
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence,...
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
2026-07-28 09:35:40
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed...
Anthropic et les modèles open-weight : oui, mais…
2026-07-28 09:24:25
Non signataire de la lettre ouverte par laquelle la tech US défend les modèles open-weight, Anthropic expose sa position.
The post Anthropic et les modèles open-weight : oui, mais… appeared first...
Suitable AI : 15 176 comptes exposés via GraphQL
2026-07-28 09:16:47
Suitable AI : une fuite revendiquée expose 15 176 candidats et des failles critiques à grande échelle.
Fake ShinyHunters Emails Give Victims 48 Hours to Pay ,000 Bitcoin Ransom
2026-07-28 09:14:09
Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom...
Data breach at medical billing firm MCBS affects 1.26 million people
2026-07-28 09:10:03
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Anthropic dévoile Claude Opus 5
2026-07-28 09:09:05
Anthropic poursuit sa stratégie d’industrialisation de l’IA générative avec le lancement de Claude Opus 5, une récente (...)
KomikoAI : une fuite relie courriels et prompts
2026-07-28 09:01:19
Des données personnelles d'un professionnel de l'IA piratés : courriels, identifiants, contenus générés et prompts d'utilisateurs.
How I found an IDOR in Google Classroom on Day 3 of my Hunting?
2026-07-28 08:56:56
Hello Guys,Hope you are well. This is my first writeup and I will tell you how I found IDOR on Google Classroom on Day 3 of my hunting on Google. I hope it will inspire you.I selected my first target...
U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
2026-07-28 08:19:29
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure...
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
2026-07-28 08:16:39
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing...
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
2026-07-28 08:11:22
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.
The...
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
2026-07-28 08:04:44
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free...
Mirage Kitten targets Middle East and Africa region with new malware
2026-07-28 08:00:20
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
2026-07-28 08:00:00
Claudia Zoon is Senior Manager, Channel Sales at Rapid7.Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly...
TryHackMe(RootMe)- Write-Up
2026-07-28 07:56:04
IntroHey everyone! Today we're solving the TryHackMe room RootMe — a great beginner-friendly box that covers web enumeration, exploiting a file upload vulnerability to get a reverse shell, and...
Tryhackme Room — W1seGuy | by Sahil Malvi
2026-07-28 07:53:58
Tryhackme Room — W1seGuy | by Sahil MalviHere's a link to the room: https://tryhackme.com/r/room/w1seguyTASK [1] Source CodeYes, it's me again with another crypto challenge!Have a look at...
The Invisible Hack: How a Linux Bug Lets Anyone Become Root — Without Leaving a Single Trace
2026-07-28 07:53:45
A deep dive into CVE-2026–31431 — the vulnerability that breaks the most fundamental rule of computer security: that what's on disk is what runs.Imagine you hire a security guard for your house....
Proxy — TryHackMe Active Directory Write-up
2026-07-28 07:48:54
By: Kavin Jindal (@Klevr)Check out the challenge: TryHackMe | ProxyIn this write-up, I will give you a detailed walkthrough of ‘Proxy ', which is an Active Directory based machine on TryHackMe where...
Avec iOS 26.6, Apple corrige près de 90 failles de sécurité, mettez à jour votre iPhone !
2026-07-28 07:45:24
Apple vient de déployer iOS 26.6 sur iPhone et iPad. Cette mise à jour intermédiaire corrige un impressionnant total de 87 failles de sécurité dans le code d'iOS, y compris dans le noyau du système...
Samba Spy — LetsDefend (Walkthrough)
2026-07-28 07:44:48
Investigating a Malicious .jar fileHello guys, I'm back with another writeup. First of all, can you tell me why Ronaldo is out of the World cup? I could not sleep that day. Anyways.. that was just...
Unprotected admin functionality — PortSwigger Access control vulnerabilities Lab 1
2026-07-28 07:43:06
Unprotected admin functionality — PortSwigger Access control vulnerabilities Lab 1Finding ID: BAC-Portswigger-001Title: Unprotected Admin FunctionalityRisk (Severity): HighRationale:The application...
How an Unpatched N-Day Let Any Anonymous Visitor Rewrite WooCommerce Prices in ND Booking
2026-07-28 07:42:03
Author: Shikhali Jamalzade GitHub: alisalive LinkedIn: camalzads Type: Independent Security Research | WordPress Plugin CVE ResearchThis is a write-up of a vulnerability I independently discovered in...
PeekList: How Brave's Playlist bypassed FaceID Protection for Private Tabs
2026-07-28 07:41:35
Brave Browser LogoTL;DRBrave for iOS lets you lock Private Tabs behind Face ID or a device passcode. That protection can be completely bypassed using the built-in Brave Playlist feature. Adding any video...
Discovering an Time-Based Blind SQL Injection in a Tamil Nadu Government Web Portal (TANGEDCO)
2026-07-28 07:38:42
Hunting an Oracle Time-Based Blind SQL Injection: A Real Bug Bounty JourneyBy karthithehackerIntroductionRecently, while performing security testing as part of a bug bounty program, I discovered an Oracle...
USN-8620-1: Linux kernel vulnerabilities
2026-07-28 07:31:41
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could...
USN-8619-1: Linux kernel (HWE) vulnerabilities
2026-07-28 07:28:45
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
USN-8595-3: Linux kernel (AWS) vulnerabilities
2026-07-28 07:25:50
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
USN-8574-3: Linux kernel vulnerabilities
2026-07-28 07:23:25
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
USN-8570-2: Linux kernel (Oracle) vulnerabilities
2026-07-28 07:19:37
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
...
USN-8618-1: Linux kernel vulnerabilities
2026-07-28 07:16:49
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a...
USN-8617-1: Linux kernel (KVM) vulnerabilities
2026-07-28 06:46:54
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this...
USN-8616-1: Linux kernel (IBM) vulnerabilities
2026-07-28 06:43:49
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem...
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
2026-07-28 06:07:22
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.
The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4,...
Houston City College - 831,642 breached accounts
2026-07-28 06:05:24
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email...
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
2026-07-28 04:43:53
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16812 (CVSS...
Cloud Security Alliance CISO Community Releases Emergency Guidance After Autonomous AI Model Breached Hugging Face's Production Systems During a Security Evaluation
2026-07-28 04:38:03
New report analyzes the first publicly documented fully autonomous cyberattack and delivers practical steps security leaders should take to strengthen their AI resilience today
SEATTLE – July 28, 2026...
AI Agent Drives Espionage Attack on Thai Ministry of Finance
2026-07-28 01:00:00
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
List of 33 new domains
2026-07-28 00:00:00
.fr asus-offrespromotionnelles[.fr] (registrar: NETIM)
billionairesp1n[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider)
blockchain-support[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider)
cas1nozerzz[.fr]...
Multiples vulnérabilités dans les produits Apple (28 juillet 2026)
28/07/2026
De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges...
Multiples vulnérabilités dans Samba (28 juillet 2026)
28/07/2026
De multiples vulnérabilités ont été découvertes dans Samba. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des...