Toute l'actualité de la Cybersécurité
HaE HaEFile-1.0.3
2026-08-21 20:36:44
Modular Burp Suite extension for fine-grained highlighting and extraction of sensitive data from HTTP and WebSocket traffic, enabling efficient security analysis.
Krawl v2.3.0
2026-08-21 20:06:19
Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging vulnerabilities using realistic, randomly generated decoy data...
USN-8669-1: Linux kernel (NVIDIA) vulnerabilities
2026-08-21 19:59:28
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
...
USN-8643-3: Linux kernel (NVIDIA) vulnerabilities
2026-08-21 19:54:33
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
...
USN-8659-2: Linux kernel (HWE) vulnerability
2026-08-21 19:49:55
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
91 Spring CVEs: The AI Vulnerability Consumption Problem
2026-08-21 19:47:04
TL;DR
Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects.
At the time of publishing,...
USN-8668-1: Linux kernel (GCP) vulnerabilities
2026-08-21 19:45:48
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could...
USN-8667-1: Linux kernel (KVM) vulnerabilities
2026-08-21 19:27:34
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588....
USN-8662-2: Linux kernel (FIPS) vulnerabilities
2026-08-21 19:23:06
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
...
prowler v5.39.1
2026-08-21 19:06:28
Prowler is the world's most widely used open-source cloud security platform that automates security and compliance across any cloud environment. Connect your agents now and build on the Agentic Cloud...
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
2026-08-21 18:53:00
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence...
Debian SPIP Critical Remote Code Execution Vuln DSA-6456-1
2026-08-21 18:45:35
A vulnerability in SPIP could allow unauthenticated remote code execution; it has been fixed in version 4.4.21+dfsg-0+deb13u1 for the stable distribution.
yakit v1.4.8-0821
2026-08-21 18:36:27
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and exploitation.
emp3r0r v4.11.0
2026-08-21 18:06:06
Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.
Your Shredded Visa Card May Still Work at the Checkout
2026-08-21 18:03:59
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts...
New SynkLoader malware pushed in Microsoft Teams phishing campaign
2026-08-21 18:01:30
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
Claude Mythos 5 Now Available in Claude Security for Vulnerability Scanning
2026-08-21 17:46:37
Anthropic has expanded access to its frontier AI cyber-defense capabilities by making Claude Mythos 5 available in Claude Security, enabling enterprise customers to scan codebases for vulnerabilities...
OWASP Flags Top AI Skill Risks in New Security Blueprint
2026-08-21 17:36:53
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons....
edk2 edk2-stable202608
2026-08-21 17:35:41
Cross-platform firmware development environment implementing UEFI and PI specifications. Provides build tools, cryptographic libraries, and virtual platform support for hardware and embedded systems security....
retire.js v5.5.0
2026-08-21 17:05:35
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
Microsoft Expands Mailbox Storage From 50 GB to 100 GB for Users
2026-08-21 16:37:25
Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users can now receive up to 100 GB of Exchange Online...
claude-bug-bounty v6.0.0
2026-08-21 16:35:26
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Escape Data ZATAZ 2.0 transforme l'enquête en jeu
2026-08-21 16:16:14
Escape Data ZATAZ 2.0 mêle escape game, OSINT, observation et réflexes cyber dans une enquête numérique estivale.
awesome-llvm-security
2026-08-21 16:05:16
Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and compiler-level reverse engineering.
Cyberattaque chez un prestataire de Suez : des données sensibles dérobées et mises en ligne
2026-08-21 16:02:44
Un prestataire de Suez Eau France a été victime d'une cyberattaque. Une partie des données a été exfiltrée et mise en ligne sur Internet. Si le fournisseur d'eau ne peut pas encore déterminer...
How I Built a Data Pipeline From Scratch Using Python
2026-08-21 16:00:06
Learn how I built a scalable data pipeline from scratch using Python, covering ingestion, processing, storage, and automation.
Your Screenplay Isn't Too Vague for a Director, but It Is for an AI Model
2026-08-21 16:00:03
AI video models do not infer intent like human crews. This guide shows how to rewrite vague screenplay action into clear, visible instructions for generation.
Pokémon Center touché par la cyberattaque d'un prestataire
2026-08-21 15:56:09
Cyberattaque : des données de clients Pokémon Center exposées et certaines précommandes annulées en Europe.
Hundreds of leaked AWS keys give full control over corporate accounts
2026-08-21 15:55:15
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
2026-08-21 15:52:10
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows...
Target visé par une nouvelle revendication de fuite
2026-08-21 15:41:54
Un pirate renvendique le vol de codes sources à un géant de la grande distribution, sur fond d'une précédente fuite interne.
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
2026-08-21 15:41:44
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
Kaspersky, which discovered the threat...
openSUSE Tumbleweed redis Moderate CVE-2026-62356 Patch 2026-11542-1
2026-08-21 15:37:02
openSUSE Tumbleweed released an update for redis-8.10.1-1.1 addressing a moderate severity vulnerability identified as CVE-2026-62356, enhancing system security.
openSUSE Tumbleweed python313-pytest-html Moderate CVE-2026-73088
2026-08-21 15:37:01
An update for python313-pytest-html-4.2.0-5.1 on openSUSE Tumbleweed addresses a vulnerability, improving system security with details available in the corresponding CVE reference.
openSUSE go1.27 Moderate Security Update 2026-11536-1 for Multiple Issues
2026-08-21 15:37:01
An update for openSUSE Tumbleweed has been released, addressing nine vulnerabilities in the go1.27-1.27rc3-1.1 package, enhancing security for affected products.
openSUSE Tumbleweed libjxl-devel Moderate Fix CVE-2026-52584 2026-11537-1
2026-08-21 15:37:01
An update for openSUSE Tumbleweed resolves a vulnerability in the libjxl-devel package, providing enhanced security through version 0.12.0-1.1 for several related packages.
awesome-game-security
2026-08-21 15:34:56
Curated index of game security research: anti-cheat internals, DMA attacks, reverse engineering, kernel/mobile protections, and graphics API hooking for offensive and defensive analysis.
Des bases de joueurs européens de casino diffusées sur un forum pirate
2026-08-21 15:28:56
Un vendeur propose des bases de joueurs de casino européens contenant coordonnées, téléphones et données de dépôt.
Checker max cible les portefeuilles Solana en masse
2026-08-21 15:12:09
Checker max analyse Solana par lots de 1 000 adresses, une capacité sensible pour le triage de portefeuilles proposé sur un forum de pirates.
How CertiK Found Five Vulnerabilities in Besu and Got Them Fixed in a Fortnight
2026-08-21 15:06:40
CertiK reported five resource exhaustion bugs to the Besu maintainers who shipped the fixes within a fortnight and then published severity ratings that disagree
Debian LTS firefox-esr Critical Code Escalation Issues DLA-4750-1
2026-08-21 15:05:42
Debian LTS advisories report multiple security issues in the firefox-esr package that could lead to various vulnerabilities, urging users to upgrade to the patched versions.
camoufox v152.0.4-beta.29
2026-08-21 15:04:36
Open-source anti-detect Firefox fork for undetectable web scraping and AI agent automation. Injects realistic browser fingerprints, spoofs geolocation/WebRTC, and evades anti-bot systems at scale.
Oracle Linux 10 kbd Moderate Threat Fix ELSA-2026-57597
2026-08-21 15:01:40
Oracle Linux released updates for version 10, addressing CVE-2026-72693 with enhancements to the openvt process matching. New RPMs are available for x86_64 and aarch64 architectures.
Oracle Linux 10 Kernel Important Bug Fixes Advisory ELSA-2026-57251
2026-08-21 15:01:38
Oracle Linux has released several kernel updates addressing multiple CVEs, including security enhancements and fixes for various stability and performance issues in its 10th version.
Oracle Linux 10 ansible-core Important Remote Access Fix ELSA-2026-57148
2026-08-21 15:01:36
Oracle Linux 10 updates include versions of ansible-core and ansible-test that address CVE-2026-11332, which involved potential arbitrary git configuration injection during role installation.
Oracle Linux 10 java-25-openjdk Medium Update For ELSA-2026-55798
2026-08-21 15:01:34
Oracle Linux has released updated Java packages for version 10 to address several CVEs, including CVE-2026-60589 and others, with a detailed list of RPMs provided.
Oracle Linux 9 kbd Moderate Buffer Overflow Fix ELSA-2026-57610
2026-08-21 15:01:27
Oracle Linux 9 has received an update for kbd packages to address CVE-2026-72693, improving openvt process matching. Updated RPMs are available for x86_64 and aarch64.
Oracle Linux 9 Kernel Important Bug Fix Advisory ELSA-2026-57252
2026-08-21 15:01:25
Oracle Linux 9 has released kernel updates addressing various CVEs, improving security and performance through updates to kernel components and features, including UKI signing and timers.
Microsoft blames Windows gaming issues on RGB lighting devices
2026-08-21 14:54:49
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
AI Code Review: If AI Writes the Code, How Do We Review It at Scale?
2026-08-21 14:54:44
Learn what AI code review is, how it differs from AI code generation, where it fits in the SDLC, and how to evaluate AI review tools for production.
Scammers Use WhatsApp Groups to Coordinate Millions in Victim Trades and Pump Real Stocks
2026-08-21 14:52:11
Scammers are using WhatsApp groups to turn ordinary investors into an unwitting buying force. The operation does not need a hacked trading account or a stolen card. Instead, it persuades people to place...
DYSPHOR1A, nouveau groupe de ransomware maître chanteur
2026-08-21 14:44:23
DYSPHOR1A émerge comme un nouveau groupe ransomware maître chanteur, avec ventes, fuites et retraits payants de données.
Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks
2026-08-21 14:41:55
A Chinese-speaking cybercrime group is using AI-assisted tools to turn vulnerable web servers into entry points. It shows how familiar flaws become more dangerous when attackers automate the work around...
prismsec
2026-08-21 14:34:25
Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting
Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection
2026-08-21 14:14:20
Hackers are using Unicode emoji characters to hide an Agent Tesla JScript dropper in a business email compromise campaign aimed at finance teams. The tactic turns a payment-related attachment into a difficult-to-read...
I Turned My iOS Memory Game Into a Physical Board for Shipaton
2026-08-21 14:08:05
I took Adversary off-screen, turning its core mechanic into a physical prototype as the next step in my Build in Public journey.
Zombie Card: An expired Visa credit card can be used for purchases
2026-08-21 14:03:48
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.
Le « Legal Engineer », ce nouveau métier à la frontière du droit et de l'IA que Microsoft recrute
2026-08-21 14:02:06
Au sein de la direction juridique, le Principal Legal Engineer devra concevoir et déployer des agents IA, retravailler les prompts et les workflows juridiques mais aussi orchestrer Copilot et Harvey,...
The TechBeat: The Claude Opus 5 Rumor Passed the Screenshot Test, Not the API Contract Test (8/21/2026)
2026-08-21 14:01:05
8/21/2026: Trending stories on Hackernoon today!
Is Online Privacy Possible? How Digital Identities Can Help
2026-08-21 14:00:10
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas...
500 Blog Posts To Learn About Mobile App Development
2026-08-21 14:00:09
Learn everything you need to know about Mobile App Development via these 500 free HackerNoon blog posts.
Calling on Cyber Pros to Help Defend City Hall
2026-08-21 14:00:00
Government agencies with smaller budgets need support — and here's how you can help.
Un recrutement VPN français intrigue sur un forum pirate
2026-08-21 13:56:56
Un membre d'un forum pirate russe recrute des francophones pour un VPN, malgré un historique lié au spam et aux RAT.
Data Debt in Production ML Pipelines: Detection and Remediation at Scale
2026-08-21 13:42:19
Learn how to catch data debt before it degrades production ML models using schema checks, null monitoring, PSI, KS tests, and drift detection.
Microsoft rolls out Classic Outlook theme for New Outlook users
2026-08-21 13:39:35
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
A Reference Architecture for AI-Driven Healthcare Data Engineering
2026-08-21 13:30:58
Healthcare data platforms are evolving beyond ETL, using AI for anomaly detection, entity matching, forecasting, compliance, and data quality.
OpenAI Adds Controls That Should've Been There Already
2026-08-21 13:30:00
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.
Claude Opus 5 Routes Around Obfuscated Binaries Instead of Defeating the Protection
2026-08-21 13:26:20
Claude Opus 5 did not crack hardened binaries in a reverse-engineering experiment. Instead, it sought easier ways to recover hidden information, showing AI-assisted analysis can be capable yet unreliable....
Turning Apache DolphinScheduler Into an Agent-Friendly Workflow Platform
2026-08-21 13:19:08
dsctl adds CLI-based automation, workflow-as-code, CI/CD, and controlled AI-agent operations to Apache DolphinScheduler through its REST APIs.
Cybersecurity Ventures and World Economic Forum On The Global Cost of Cybercrime
2026-08-21 13:15:37
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 21, 2026 – Read the full Irish Times Story A special report from The Irish Times declares cyber...
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
2026-08-21 13:08:51
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank...
Deux millions de données françaises mises en vente
2026-08-21 13:08:19
Un forum pirate propose deux millions de données françaises, sans preuve publique sur leur origine.
Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks
2026-08-21 13:06:57
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the...
Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts
2026-08-21 13:06:34
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisements, impersonated financial experts, and coordinated...
Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks
2026-08-21 13:06:02
GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478, a critical unauthenticated code injection vulnerability affecting self-managed...
US Bank Investigating Data Breach Following LockBit Ransomware Claim
2026-08-21 13:01:06
US Bank is investigating LockBit's claims of a breach and data theft, with the ransomware group threatening to publish the alleged stolen files on September 3 unless an undisclosed ransom is paid. Lee...
Zero Trust In The Age Of AI Driven Cyber Threats (Why Cisos Must Redefine Enterprise Trust Boundaries In 2026)
2026-08-21 13:00:48
Enterprise cybersecurity is undergoing a structural shift driven by two converging forces: the collapse of traditional network perimeters and the rapid weaponization of artificial intelligence by threat...
Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes
2026-08-21 13:00:14
A critical vulnerability in N-able Passportal's Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization's entire password vault, including...
Your Five-Minute AI Film Does Not Need a 15-Beat Structure
2026-08-21 13:00:02
The classic 15-beat structure is built for a 90-minute feature. Here's how to size a beat sheet for a short AI-generated film instead.
C.Hunters, un service pirate testé pour la France
2026-08-21 12:52:57
C.Hunters propose des appels ciblés sur un forum pirate, avec un intérêt explicite pour la France.
Binance Launches Agent OS, Letting AI Agents Trade on Your Account With Limits You Set
2026-08-21 12:40:00
Covering AI, Web3, Cybersecurity, Startup Funding & Enterprise SaaS. Top Journalist & Thought Leadership Media Leader
Six Maximum-Severity Flaws Found in Cisco Products
2026-08-21 12:30:16
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms...
CISA orders feds to patch actively exploited TrueConf Server flaws
2026-08-21 12:25:33
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications...
Encore, encore, encore … un nouveau groupe ransomware : SovCali
2026-08-21 12:03:50
Un nouvel acteur du rançongiciel, SovCali, apparaît et affirme détenir des données de Lucid Motors, première cible publiquement revendiquée.
The New Russian Playbook: Bypassing MFA Without Cracking Passwords
2026-08-21 12:00:48
OAuth Exploitation Russian threat actors are shifting away from plain old password theft and moving toward legitimate platform features like OAuth permissions. Groups like UNC6293 and UNC7005 take their...
Medical records, SSNs, and bank details exposed in CareCloud data breach
2026-08-21 11:50:55
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.
Comment Lazarus détourne des offres d'emploi pour infiltrer l'industrie de la défense
2026-08-21 11:38:57
Le groupe nord-coréen Lazarus a combiné ingénierie sociale sophistiquée et exploitation d'une faille inédite pour s'introduire chez des acteurs de la défense et de l'aérospatiale en Europe, en...
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
2026-08-21 11:30:16
A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial...
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
2026-08-21 11:23:51
Cybersecurity researchers have revealed a critical vulnerability in N-able's PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials...
Wazuh and AI For Enhanced SOC Workflows
2026-08-21 11:21:39
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive...
Fake Conferences, OAuth and WhatsApp: Inside Russia's New Espionage Tactics
2026-08-21 11:11:11
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked...
OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing
2026-08-21 11:07:22
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed...
Microsoft warns of max severity Entra ID flaw exploited in attacks
2026-08-21 11:04:10
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]
Hackers abuse FTP server banners to deliver new Windows malware
2026-08-21 11:00:00
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords
2026-08-21 10:27:17
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing...
SickKids data breach exposes employee and job applicant info
2026-08-21 10:10:42
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party...
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
2026-08-21 10:03:11
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.
Four of the security vulnerabilities...
Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing
2026-08-21 10:00:46
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender's threat model. Its latest experiment found that autonomous coding agents routinely...
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
2026-08-21 09:49:02
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab...
Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data
2026-08-21 09:27:56
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind...
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
2026-08-21 09:17:46
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants....
Poland's CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
2026-08-21 09:14:02
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response...
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
2026-08-21 08:56:13
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with...
Services IT : comment l'IA fait évoluer les contrats de prestation
2026-08-21 08:42:46
Face aux gains de productivité générés par l'IA, les ESN françaises voient leur modèle historique de facturation au temps passé remis en cause.
The post Services IT : comment l'IA fait évoluer...
Une plateforme de gestion de rendez-vous médicaux piratée : 6,8 millions de profils volés
2026-08-21 08:31:31
Un hacker a revendiqué une cyberattaque contre Alaxione, une plateforme spécialisée dans la gestion des rendez-vous médicaux. Il assure avoir mis la main sur 6,8 millions de profils, qui incluraient...
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
2026-08-21 08:22:11
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added...
ToxicPanda 2.0 : un cheval de Troie bancaire Android nettement plus puissant découvert par le zLabs de Zimperium
2026-08-21 08:07:32
zLabs, l'équipe de recherche de Zimperium, leader mondial de la sécurité mobile basée sur l'IA, publie une nouvelle étude consacrée à ToxicPanda 2.0, une évolution majeure du cheval de Troie...
The invisible passenger in your car
2026-08-21 08:00:29
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
Cyberespionnage : l'arsenal « CAV3RN » évolue et détourne Google Apps Script pour cibler Israël
2026-08-21 08:00:08
Selon de nouvelles recherches menées par l’équipe GReAT de Kaspersky, le kit d’outils de cyberespionnage Project CAV3RN continue d’évoluer et de cibler activement des organisations...
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
2026-08-21 07:15:02
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack...
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
2026-08-21 07:04:25
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.
The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4),...
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
2026-08-21 06:06:11
Update: The story was updated after publication to note that the vulnerability has not been exploited.
Although the security bulletin originally marked the "Exploited" field under the Exploitability...
List of 21 new domains
2026-08-21 00:00:00
.fr betifycasinoo[.fr] (registrar: Telepublicity B.V.)
celsiuscasino-connexion[.fr] (registrar: Marcaria.com International Inc.)
cora-distribution[.fr] (registrar: GANDI)
creditmut-capital[.fr] (registrar:...
Multiples vulnérabilités dans Google Chrome (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Vulnérabilité dans Python (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
Vulnérabilité dans SPIP (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans SPIP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que cette vulnérabilité est activement exploitée....
Multiples vulnérabilités dans le noyau Linux de SUSE (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation...
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans les produits IBM (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...
Multiples vulnérabilités dans le noyau Linux de Debian (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges.
Multiples vulnérabilités dans le noyau Linux de Debian LTS (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans Traefik (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans Traefik. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.
Multiples vulnérabilités dans Microsoft Edge (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Vulnérabilité dans Microsoft Office (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
Multiples vulnérabilités dans les produits Microsoft (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un déni de service.
Vulnérabilité dans Microsoft Entra ID (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans Microsoft Entra ID. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-69836...