Toute l'actualité de la Cybersécurité


Hackers run khunt post-exploitation toolkit from Oracle database

2026-08-05 19:55:25
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]

Lire la suite »

CSS: The Hidden Threat Lurking in Your Inbox

2026-08-05 19:47:55
CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

Lire la suite »

OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries

2026-08-05 19:14:21
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.

Lire la suite »

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

2026-08-05 19:08:36
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.

Lire la suite »

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

2026-08-05 18:44:31
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure...

Lire la suite »

Impacket for Pentester: reg

2026-08-05 18:37:00
Overview The Windows registry is a hierarchical database that governs application behaviour, user profiles, service configurations, security policies, and system startup. For penetration testers, remote The...

Lire la suite »

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

2026-08-05 18:33:47
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement...

Lire la suite »

Mageia 10 WoeUSB-ng Bugfix Advisory for 2026-0075 Release

2026-08-05 18:28:28
An update for Mageia 10 addresses a bug in woeusb-ng by adding the 7zip package as a required dependency, resolving the issue reported in bug 36029.

Lire la suite »

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

2026-08-05 18:03:31
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.

Lire la suite »

COLDCARD security audit phishing attack installs remote access tool

2026-08-05 17:49:41
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected .6 million Bitcoin theft to trick users into installing ScreenConnect remote access...

Lire la suite »

Google Blogger Locked Legitimate Websites After Mistaking Them for Malware

2026-08-05 17:45:57
Thousands of Blogger website owners woke up this week to a jarring surprise: their perfectly legitimate blogs had been locked and slapped with a “Malware and Similar Malicious Content” violation...

Lire la suite »

Mageia Tomcat Important Authentication Bypass CVE-2026-50229 CVE-2026-55957

2026-08-05 17:22:51
Mageia has released security updates for versions 10 and 9, addressing multiple vulnerabilities including XSS attacks, authentication bypass, and incomplete web.xml logging.

Lire la suite »

Mageia 10 php-fpdf Bugfix Notification for Advisory 2026-0076

2026-08-05 17:22:50
Mageia 10 has released an update to php-fpdf version 1.9.0, which resolves deprecated warnings in PHP 8.5 and a bug linked to PDF creation dates.

Lire la suite »

Mageia 10 9 Netprofile Bugfix Advisory 2026-0074 Released for Users

2026-08-05 17:22:49
A bugfix update for Mageia 10 and 9 addresses an issue where netprofile sent messages to the wrong user service, correcting it to the appropriate one.

Lire la suite »

Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted

2026-08-05 17:19:17
TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook,...

Lire la suite »

Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

2026-08-05 17:18:53
Cybercriminals spent July 2026 proving that trusted business utilities including Microsoft authentication pages, Zoom event invitations, and official government portals can be weaponized against enterprise...

Lire la suite »

5 Best AI Detection & Response Platforms for 2026

2026-08-05 16:56:41
Compare AI detection & response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and response.

Lire la suite »

Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits

2026-08-05 16:37:31
A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that these savings are coming from an unexpected...

Lire la suite »

​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

2026-08-05 16:30:00
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post ​​Microsoft named a Leader in the KuppingerCole Leadership...

Lire la suite »

Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

2026-08-05 16:27:17
Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal,...

Lire la suite »

Microsoft Awards Record Million to 562 Researchers in Biggest Bug Bounty Year

2026-08-05 16:19:51
Microsoft has awarded more than million to 562 security researchers through its bug bounty program, marking the largest annual payout in the company's history. Researchers from 64 countries reported...

Lire la suite »

Debian 12 LTS DLA-4720-1 Linux Kernel Critical Escalation Issues

2026-08-05 16:10:13
Debian released an advisory regarding vulnerabilities in the Linux kernel that could lead to privilege escalation, denial of service, or information leaks, urging users to upgrade.

Lire la suite »

Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection

2026-08-05 16:10:06
Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents, extending native AWS Web Application Firewall (WAF)...

Lire la suite »

openSUSE Leap 16.0 python-httplib2 Important Memory Issue CVE-2026-59939

2026-08-05 15:52:05
openSUSE has released a security update for python-httplib2 addressing a vulnerability (CVE-2026-59939) allowing malicious HTTP servers to cause MemoryError in clients. Users should update via YaST or...

Lire la suite »

openSUSE Leap 16.0 rrdtool Important Local Escalation Fix 2026-21525-1

2026-08-05 15:52:02
openSUSE released a security update for rrdtool, addressing CVE-2026-43958, a critical stack buffer overflow vulnerability that could allow local privilege escalation in openSUSE Leap 16.0.

Lire la suite »

openSUSE Nginx Important Map Directive Regex Issue CVE-2026-42533

2026-08-05 15:52:00
openSUSE has released an important security update for nginx addressing CVE-2026-42533, which involves a vulnerability related to map directive and regex matching, particularly affecting openSUSE Leap...

Lire la suite »

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

2026-08-05 15:51:33
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]

Lire la suite »

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

2026-08-05 15:48:39
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving...

Lire la suite »

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

2026-08-05 15:36:03
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One...

Lire la suite »

U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog

2026-08-05 15:25:18
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure...

Lire la suite »

New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It's Measurable

2026-08-05 13:16:25
Las Vegas, United States, 5th August 2026, CyberNewswire

Lire la suite »

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

2026-08-05 15:14:05
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI)...

Lire la suite »

Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance

2026-08-05 12:00:56
SIngapore, Singapore, 5th August 2026, CyberNewswire

Lire la suite »

Sometimes You Get the Bear, and Sometimes...

2026-08-05 15:00:06
A true story about the time I got scammed online, and my advice to the reader to predict how to you'll mitigate the panic; and then plan how you'll react.

Lire la suite »

Talos Integrates with STS Digital to Bring Institutional Crypto Options and Spot Liquidity

2026-08-05 15:00:04
STS Digital integrates with Talos, giving institutional investors direct access to regulated crypto options & spot liquidity through the Talos trading platform.

Lire la suite »

Google Blogger locks hundreds of blogs in malware false positive

2026-08-05 14:59:29
Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]

Lire la suite »

Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

2026-08-05 14:51:03
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers. Rather...

Lire la suite »

What Is Unitree Robotics? How to Buy and Short It on MEXC

2026-08-05 14:43:12
Discover what Unitree Robotics is, why it's attracting global investor attention, and how to trade UNITREE Pre IPO Futures on MEXC with long or short positions.

Lire la suite »

En un an, qu'a produit le Conseil de l'IA et du numérique ?

2026-08-05 14:42:20
Retour sur les principaux livrables publics que le Conseil national de l'IA et du numérique a produits depuis son installation il y a un an. The post En un an, qu’a produit le Conseil de l’IA...

Lire la suite »

Plus d'un Français sur deux ciblé quotidiennement par des escroqueries, 4 seniors sur 10 ont perdu plus de 5 000 € en 2025

2026-08-05 14:41:45
Selon la dernière étude menée par l’entreprise de cybersécurité Surfshark, plus de la moitié des Français (56 %) reçoivent chaque jour au moins une tentative d’escroquerie. Parmi les...

Lire la suite »

Reducing Attack Surface Without Breaking Production

2026-08-05 14:40:16
When people talk about Linux hardening, the conversation often quickly turns to enterprise security platforms, EDR agents, and complex monitoring stacks.

Lire la suite »

“I'm Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails

2026-08-05 14:35:37
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.

Lire la suite »

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

2026-08-05 14:27:30
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated...

Lire la suite »

ZIGChain Lands Nomura's Laser Digital as Investor and Risk Partner in a 0M Onchain Credit Push

2026-08-05 14:25:41
ZIGChain lands a strategic investment from Nomura's Laser Digital, with risk governance across vault products targeting 0M TVL in emerging-market credit.

Lire la suite »

OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

2026-08-05 14:24:08
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS...

Lire la suite »

Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot

2026-08-05 14:23:13
A long‑running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders' visibility...

Lire la suite »

Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing

2026-08-05 14:06:19
Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay –...

Lire la suite »

77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data

2026-08-05 14:05:55
A wave of counterfeit Open VSX extensions has exposed how easily a familiar developer tool can become a data collection channel. Seventy-seven packages copied the names, namespaces, and descriptions of...

Lire la suite »

How AI-powered phishing killed blocklists for good

2026-08-05 14:01:11
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection...

Lire la suite »

The TechBeat: Building for Shipaton 2026? Share Your Journey on HackerNoon and Compete for an Extra ,500 (8/5/2026)

2026-08-05 14:01:06
8/5/2026: Trending stories on Hackernoon today!

Lire la suite »

500 Blog Posts To Learn About Good Company

2026-08-05 14:00:12
Learn everything you need to know about Good Company via these 500 free HackerNoon blog posts.

Lire la suite »

15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution

2026-08-05 13:59:59
A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be presented at Black Hat USA 2026. TP-Link...

Lire la suite »

Maximor Scales Revenue 35x In Just 9 Months As CFOs Run Out of Accountants

2026-08-05 13:54:52
Maximor reports 35x revenue growth nine months after its M Foundation Capital seed, with AI agents automating 98% of finance transactions for 25+ customers.

Lire la suite »

Microsoft Paid Record Million in Bug Bounties to 562 Security Researchers Worldwide

2026-08-05 13:45:55
Microsoft’s Bug Bounty Program awarded over million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s...

Lire la suite »

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

2026-08-05 13:41:27
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of...

Lire la suite »

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

2026-08-05 13:35:54
Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively...

Lire la suite »

OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access

2026-08-05 13:29:31
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch (OVS) implementation. This vulnerability...

Lire la suite »

Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw

2026-08-05 13:10:08
A SQL injection vulnerability that many organisations might consider a decades-old, well-understood threat has been used as the entry point for a far more sophisticated attack, after threat actors were...

Lire la suite »

History of Hacking: The ILOVEYOU Computer Worm

2026-08-05 13:02:20
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 4, 2026 – Watch the YouTube short “ILOVEYOU“, sometimes referred to as the Love Bug or Loveletter,...

Lire la suite »

Upwork Fees From 2016 To 2026: From Nada to Prada

2026-08-05 13:00:02
Upwork fees from 2016 to 2026: a decade of service fees, Connects, boosts, withdrawals, and new charges. From Nada to Prada.

Lire la suite »

Are Brain Waves the Missing Link for Physical AI?

2026-08-05 12:51:46
HackerNoon readers debate whether brain waves can improve Physical AI as prediction markets bet on Neuralink's implant growth and rising valuation.

Lire la suite »

ClickHouse and Hud Team Up to Add Runtime Intelligence to AI Software Development

2026-08-05 12:46:35
Artificial intelligence is transforming how software is built, but it is also creating new operational challenges for engineering teams. As AI coding assistants generate larger portions of production...

Lire la suite »

SUSE google-osconfig-agent Moderate Input Issue CVE-2026-56852 2026-3496-1

2026-08-05 12:32:01
A security update for google-osconfig-agent addresses CVE-2026-56852, fixing an improper handling of invalid UTF-8 bytes that could cause an infinite loop in affected SUSE products.

Lire la suite »

SUSE google-guest-agent Moderate Infinite Loop Vulnern 2026-3497-1

2026-08-05 12:31:21
A security update for google-guest-agent has been released to address CVE-2026-56852, which involves improper handling of invalid UTF-8 leading to infinite loops in specific SUSE products.

Lire la suite »

SUSE Rsyslog Important Stack Buffer Overflow Vuln 2026-3498-1

2026-08-05 12:30:39
SUSE released a security update for rsyslog addressing a vulnerability that could lead to a stack buffer overflow and a crash due to a configuration-dependent issue.

Lire la suite »

Hack de l'Éducation nationale : un syndicat dénonce un « manque d'information » et de « transparence »

2026-08-05 12:00:13
Pour la troisième fois en 2026, le ministère de l'Éducation nationale a été victime d'une cyberattaque. Un pirate a usurpé l'identité d'un professionnel pour accéder au système de formation des...

Lire la suite »

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

2026-08-05 11:43:27
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built...

Lire la suite »

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

2026-08-05 11:43:19
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real...

Lire la suite »

Des agents Anthropic et OpenAI créent de fausses identités pour piéger un développeur

2026-08-05 11:22:05
L'AI Security Institute britannique révèle que lors d'un test, un agent d'Anthropic propulsé par Mythos 5 a tenté d'introduire du code malveillant dans un projet open source réel, en fabriquant de...

Lire la suite »

Google's synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks

2026-08-05 11:11:48
Over time, passkeys are supposed to replace passwords. But what happens when malware steals the master key?

Lire la suite »

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

2026-08-05 11:04:23
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository...

Lire la suite »

15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks

2026-08-05 10:47:15
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials,...

Lire la suite »

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

2026-08-05 10:35:29
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials...

Lire la suite »

JFrog identifie plus de 450 packages compromis par Shai-Hulud

2026-08-05 10:26:27
L’équipe JFrog Security Research a identifié une nouvelle variante de Shai-Hulud, le ver ciblant la chaîne d’approvisionnement logicielle, qui touche cette fois-ci l’écosystème...

Lire la suite »

Brazil Health Surveillance Database Exposed 79GB of Sensitive Records

2026-08-05 10:21:27
Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.

Lire la suite »

Intermarché victime d'une fuite de données après une cyberattaque

2026-08-05 09:46:58
Intermarché a confirmé avoir été victime d’une cyberattaque survenue la semaine dernière, ayant entraîné (...)

Lire la suite »

Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces

2026-08-05 09:40:27
Fake Open VSX extensions have hijacked high‑trust namespaces like AMD, Azure, Salesforce, Hyperledger, and a U.S. government agency on the Open VSX Registry, silently harvesting Git and CI metadata...

Lire la suite »

Le Mode IA de Google, ou le Shadow AI qui n'a plus besoin de l'ombre

2026-08-05 09:24:07
Depuis le 22 juillet, les RSSI français ont un nouveau problème. La plupart ne le savent pas encore, parce que rien n’a changé dans leurs logs. Ce jour-là, Google a déployé en France les Aperçus...

Lire la suite »

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

2026-08-05 09:23:03
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they...

Lire la suite »

TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout

2026-08-05 09:13:20
Forescout Vedere Labs research has uncovered 15 previously unknown vulnerabilities affecting TP-Link’s Omada Zero-Touch Provisioning (ZTP) ecosystem, warning that weaknesses in automated device...

Lire la suite »

ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates

2026-08-05 09:10:15
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise malicious activity as routine software updates to...

Lire la suite »

Junk Cleaner clears the clutter from your Android

2026-08-05 09:07:19
The easiest way to reclaim storage on your phone. Free up space without hunting through folders or risking your important files.

Lire la suite »

Critical Veeam ONE Flaw Lets Unauthenticated Attackers Execute Code Remotely

2026-08-05 08:38:15
Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote attacker to execute arbitrary code on an affected...

Lire la suite »

Cyber Libertarians: Esther Dyson & The Knowledge Age

2026-08-05 08:17:46
Meet the woman who helped shape the Internet and dreamed of a freer cyberspace. Esther Dyson's ideas still echo in our digital world today.

Lire la suite »

Cloud-Native Finance Transformation With Adinath Kadam

2026-08-05 08:15:29
Discover how Adinath Kadam is modernizing enterprise FP&A through cloud-native architecture, governed data pipelines, AI integration, and scalable analytics.

Lire la suite »

ChatGPT et Claude ont échappé à tout contrôle : les IA ont lancé 2 nouvelles cyberattaques « dans le monde réel »

2026-08-05 08:11:43
Deux nouvelles cyberattaques ont été orchestrées par des IA hors de contrôle. Lors de tests réalisés par des tiers, Claude et ChatGPT se sont en effet retrouvés en roue libre sur Internet. Les...

Lire la suite »

Angola's Largest Telco Breached Hours Before IPO

2026-08-05 08:00:00
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.

Lire la suite »

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

2026-08-05 07:53:50
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a...

Lire la suite »

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

2026-08-05 07:39:25
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.

Lire la suite »

SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access

2026-08-05 05:52:28
SMOKE#SCREEN uses fake Zoom updates to install ScreenConnect RMM, giving attackers persistent remote access while bypassing defenses. Securonix Threat Research has been tracking an active multi-wave campaign...

Lire la suite »

List of 58 new domains

2026-08-05 00:00:00
.fr 1lolajack[.fr] (registrar: NETIM) 5gringos-france[.fr] (registrar: NETIM) achats-vinted100[.fr] (registrar: One.com A/S) amunracas1no[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) anker-france[.fr]...

Lire la suite »

Multiples vulnérabilités dans les produits Veeam (05 août 2026)

05/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Veeam. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...

Lire la suite »

Multiples vulnérabilités dans HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (05 août 2026)

05/08/2026
De multiples vulnérabilités ont été découvertes dans HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données,...

Lire la suite »

Multiples vulnérabilités dans Google Pixel (05 août 2026)

05/08/2026
De multiples vulnérabilités ont été découvertes dans Google Pixel. Elles permettent à un attaquant de provoquer une élévation de privilèges et un problème de sécurité non spécifié par l'éditeur....

Lire la suite »

Vulnérabilité dans Mozilla Firefox pour Android (05 août 2026)

05/08/2026
Une vulnérabilité a été découverte dans Mozilla Firefox pour Android. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

Lire la suite »