Toute l'actualité de la Cybersécurité


Cyberattaque chez un prestataire de Suez : des données sensibles dérobées et mises en ligne

2026-08-21 16:02:44
Un prestataire de Suez Eau France a été victime d'une cyberattaque. Une partie des données a été exfiltrée et mise en ligne sur Internet. Si le fournisseur d'eau ne peut pas encore déterminer...

Lire la suite »

How I Built a Data Pipeline From Scratch Using Python

2026-08-21 16:00:06
Learn how I built a scalable data pipeline from scratch using Python, covering ingestion, processing, storage, and automation.

Lire la suite »

Your Screenplay Isn't Too Vague for a Director, but It Is for an AI Model

2026-08-21 16:00:03
AI video models do not infer intent like human crews. This guide shows how to rewrite vague screenplay action into clear, visible instructions for generation.

Lire la suite »

Pokémon Center touché par la cyberattaque d'un prestataire

2026-08-21 15:56:09
Cyberattaque : des données de clients Pokémon Center exposées et certaines précommandes annulées en Europe.

Lire la suite »

Hundreds of leaked AWS keys give full control over corporate accounts

2026-08-21 15:55:15
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]

Lire la suite »

Target visé par une nouvelle revendication de fuite

2026-08-21 15:41:54
Un pirate renvendique le vol de codes sources à un géant de la grande distribution, sur fond d'une précédente fuite interne.

Lire la suite »

Des bases de joueurs européens de casino diffusées sur un forum pirate

2026-08-21 15:28:56
Un vendeur propose des bases de joueurs de casino européens contenant coordonnées, téléphones et données de dépôt.

Lire la suite »

Checker max cible les portefeuilles Solana en masse

2026-08-21 15:12:09
Checker max analyse Solana par lots de 1 000 adresses, une capacité sensible pour le triage de portefeuilles proposé sur un forum de pirates.

Lire la suite »

How CertiK Found Five Vulnerabilities in Besu and Got Them Fixed in a Fortnight

2026-08-21 15:06:40
CertiK reported five resource exhaustion bugs to the Besu maintainers who shipped the fixes within a fortnight and then published severity ratings that disagree

Lire la suite »

Microsoft blames Windows gaming issues on RGB lighting devices

2026-08-21 14:54:49
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]

Lire la suite »

AI Code Review: If AI Writes the Code, How Do We Review It at Scale?

2026-08-21 14:54:44
Learn what AI code review is, how it differs from AI code generation, where it fits in the SDLC, and how to evaluate AI review tools for production.

Lire la suite »

Scammers Use WhatsApp Groups to Coordinate Millions in Victim Trades and Pump Real Stocks

2026-08-21 14:52:11
Scammers are using WhatsApp groups to turn ordinary investors into an unwitting buying force. The operation does not need a hacked trading account or a stolen card. Instead, it persuades people to place...

Lire la suite »

DYSPHOR1A, nouveau groupe de ransomware maître chanteur

2026-08-21 14:44:23
DYSPHOR1A émerge comme un nouveau groupe ransomware maître chanteur, avec ventes, fuites et retraits payants de données.

Lire la suite »

Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks

2026-08-21 14:41:55
A Chinese-speaking cybercrime group is using AI-assisted tools to turn vulnerable web servers into entry points. It shows how familiar flaws become more dangerous when attackers automate the work around...

Lire la suite »

prismsec

2026-08-21 14:34:25
Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

Lire la suite »

Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection

2026-08-21 14:14:20
Hackers are using Unicode emoji characters to hide an Agent Tesla JScript dropper in a business email compromise campaign aimed at finance teams. The tactic turns a payment-related attachment into a difficult-to-read...

Lire la suite »

I Turned My iOS Memory Game Into a Physical Board for Shipaton

2026-08-21 14:08:05
I took Adversary off-screen, turning its core mechanic into a physical prototype as the next step in my Build in Public journey.

Lire la suite »

agentic-dm-gateway

2026-08-21 14:04:23
Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to block secret leakage and image-beacon exfiltration.

Lire la suite »

Zombie Card: An expired Visa credit card can be used for purchases

2026-08-21 14:03:48
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.

Lire la suite »

Le « Legal Engineer », ce nouveau métier à la frontière du droit et de l'IA que Microsoft recrute

2026-08-21 14:02:06
Au sein de la direction juridique, le Principal Legal Engineer devra concevoir et déployer des agents IA, retravailler les prompts et les workflows juridiques mais aussi orchestrer Copilot et Harvey,...

Lire la suite »

The TechBeat: The Claude Opus 5 Rumor Passed the Screenshot Test, Not the API Contract Test (8/21/2026)

2026-08-21 14:01:05
8/21/2026: Trending stories on Hackernoon today!

Lire la suite »

Is Online Privacy Possible? How Digital Identities Can Help

2026-08-21 14:00:10
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas...

Lire la suite »

500 Blog Posts To Learn About Mobile App Development

2026-08-21 14:00:09
Learn everything you need to know about Mobile App Development via these 500 free HackerNoon blog posts.

Lire la suite »

Calling on Cyber Pros to Help Defend City Hall

2026-08-21 14:00:00
Government agencies with smaller budgets need support — and here's how you can help.

Lire la suite »

Un recrutement VPN français intrigue sur un forum pirate

2026-08-21 13:56:56
Un membre d'un forum pirate russe recrute des francophones pour un VPN, malgré un historique lié au spam et aux RAT.

Lire la suite »

Data Debt in Production ML Pipelines: Detection and Remediation at Scale

2026-08-21 13:42:19
Learn how to catch data debt before it degrades production ML models using schema checks, null monitoring, PSI, KS tests, and drift detection.

Lire la suite »

Microsoft rolls out Classic Outlook theme for New Outlook users

2026-08-21 13:39:35
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]

Lire la suite »

A Reference Architecture for AI-Driven Healthcare Data Engineering

2026-08-21 13:30:58
Healthcare data platforms are evolving beyond ETL, using AI for anomaly detection, entity matching, forecasting, compliance, and data quality.

Lire la suite »

OpenAI Adds Controls That Should've Been There Already

2026-08-21 13:30:00
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.

Lire la suite »

Claude Opus 5 Routes Around Obfuscated Binaries Instead of Defeating the Protection

2026-08-21 13:26:20
Claude Opus 5 did not crack hardened binaries in a reverse-engineering experiment. Instead, it sought easier ways to recover hidden information, showing AI-assisted analysis can be capable yet unreliable....

Lire la suite »

Turning Apache DolphinScheduler Into an Agent-Friendly Workflow Platform

2026-08-21 13:19:08
dsctl adds CLI-based automation, workflow-as-code, CI/CD, and controlled AI-agent operations to Apache DolphinScheduler through its REST APIs.

Lire la suite »

Cybersecurity Ventures and World Economic Forum On The Global Cost of Cybercrime

2026-08-21 13:15:37
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 21, 2026 – Read the full Irish Times Story A special report from The Irish Times declares cyber...

Lire la suite »

US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim

2026-08-21 13:08:51
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank...

Lire la suite »

Deux millions de données françaises mises en vente

2026-08-21 13:08:19
Un forum pirate propose deux millions de données françaises, sans preuve publique sur leur origine.

Lire la suite »

Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks

2026-08-21 13:06:57
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the...

Lire la suite »

Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts

2026-08-21 13:06:34
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisements, impersonated financial experts, and coordinated...

Lire la suite »

Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks

2026-08-21 13:06:02
GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478, a critical unauthenticated code injection vulnerability affecting self-managed...

Lire la suite »

openSUSE Chromium Critical Buffer Overflow Issues Vuln 2026-0293-1

2026-08-21 13:04:47
openSUSE has released a critical security update for Chromium, addressing 15 vulnerabilities including buffer overflows and type confusion. Users are urged to apply the update promptly.

Lire la suite »

Sandb0x-Xtract0r

2026-08-21 13:04:01
Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM reports.

Lire la suite »

US Bank Investigating Data Breach Following LockBit Ransomware Claim

2026-08-21 13:01:06
US Bank is investigating LockBit's claims of a breach and data theft, with the ransomware group threatening to publish the alleged stolen files on September 3 unless an undisclosed ransom is paid. Lee...

Lire la suite »

Zero Trust In The Age Of AI Driven Cyber Threats (Why Cisos Must Redefine Enterprise Trust Boundaries In 2026)

2026-08-21 13:00:48
Enterprise cybersecurity is undergoing a structural shift driven by two converging forces: the collapse of traditional network perimeters and the rapid weaponization of artificial intelligence by threat...

Lire la suite »

Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes

2026-08-21 13:00:14
A critical vulnerability in N-able Passportal's Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization's entire password vault, including...

Lire la suite »

Your Five-Minute AI Film Does Not Need a 15-Beat Structure

2026-08-21 13:00:02
The classic 15-beat structure is built for a 90-minute feature. Here's how to size a beat sheet for a short AI-generated film instead.

Lire la suite »

C.Hunters, un service pirate testé pour la France

2026-08-21 12:52:57
C.Hunters propose des appels ciblés sur un forum pirate, avec un intérêt explicite pour la France.

Lire la suite »

Binance Launches Agent OS, Letting AI Agents Trade on Your Account With Limits You Set

2026-08-21 12:40:00
Covering AI, Web3, Cybersecurity, Startup Funding & Enterprise SaaS. Top Journalist & Thought Leadership Media Leader

Lire la suite »

openSUSE rsync Important Security Fix for 33 Issues Vuln 2026-3657-1

2026-08-21 12:35:51
A SUSE security update for rsync addresses 33 vulnerabilities and includes one security fix, impacting several supported SUSE Linux versions and providing essential installation instructions.

Lire la suite »

SUSE rsync Important Security Update for 33 Vulnerabilities 2026-3657-1

2026-08-21 12:35:34
A security update for rsync addresses 33 vulnerabilities, enhancing system protection against risks such as directory escape, command injection, and privilege escalations in various SUSE products.

Lire la suite »

detection-defense-library

2026-08-21 12:34:05
Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD driver intelligence, and Splunk workflows.

Lire la suite »

SUSE MozillaFirefox Important Security Update 2026-3658-1

2026-08-21 12:34:01
SUSE has released a security update for MozillaFirefox addressing 58 vulnerabilities, including critical issues in components like Graphics and JavaScript, with recommended installation methods provided....

Lire la suite »

openSUSE Kubernetes Old Important Security Update SUSE-SU-2026-3659-1

2026-08-21 12:33:15
SUSE has released a critical security update for kubernetes-old, allowing installation through standard methods like YaST or zypper, aimed at addressing vulnerabilities.

Lire la suite »

SUSE Kubernetes-Legacy Significant Security Update 2026-3659-1

2026-08-21 12:32:59
A security update for kubernetes-old has been released, addressing vulnerabilities by rebuilding it against the latest go security release, applicable to several SUSE and openSUSE products.

Lire la suite »

openSUSE Kubernetes Significant Security Patch 2026-3660-1

2026-08-21 12:32:21
A security update for Kubernetes has been released, rebuilding it against the latest Go security release, affecting several SUSE and openSUSE products with recommended installation methods provided.

Lire la suite »

SUSE Kubernetes Important Security Update Advisory 2026-3660-1

2026-08-21 12:32:05
SUSE released an important security update for Kubernetes, rebuilding it against the latest Go security release, with specific installation instructions for various affected product versions.

Lire la suite »

SUSE Helm Essential Security Patch Announcement for 2026-3661-1

2026-08-21 12:31:27
SUSE has released a security update for helm, rebuilding it against the latest Go security release, affecting several SUSE Linux Enterprise products and accessible via zypper.

Lire la suite »

openSUSE Podman Security Advisory CVE-2026-55686 CVE-2026-57231 Guide

2026-08-21 12:30:50
A security update for podman addresses two vulnerabilities in openSUSE Leap 15.3 and SUSE Enterprise Storage 7.1, allowing unauthorized host filesystem access and leaking environment variables.

Lire la suite »

SUSE Podman Important Security Fix for CVE-2026-55686 CVE-2026-57231

2026-08-21 12:30:33
A security update for podman addresses two vulnerabilities affecting openSUSE Leap 15.3 and SUSE Enterprise Storage 7.1, enabling prevention of directory manipulation and environment variable leaks.

Lire la suite »

Six Maximum-Severity Flaws Found in Cisco Products

2026-08-21 12:30:16
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms...

Lire la suite »

CISA orders feds to patch actively exploited TrueConf Server flaws

2026-08-21 12:25:33
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications...

Lire la suite »

custom-oscp-tooling

2026-08-21 12:04:13
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and payload/credential command generation.

Lire la suite »

Encore, encore, encore … un nouveau groupe ransomware : SovCali

2026-08-21 12:03:50
Un nouvel acteur du rançongiciel, SovCali, apparaît et affirme détenir des données de Lucid Motors, première cible publiquement revendiquée.

Lire la suite »

The New Russian Playbook: Bypassing MFA Without Cracking Passwords

2026-08-21 12:00:48
OAuth Exploitation Russian threat actors are shifting away from plain old password theft and moving toward legitimate platform features like OAuth permissions. Groups like UNC6293 and UNC7005 take their...

Lire la suite »

Medical records, SSNs, and bank details exposed in CareCloud data breach

2026-08-21 11:50:55
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.

Lire la suite »

Comment Lazarus détourne des offres d'emploi pour infiltrer l'industrie de la défense

2026-08-21 11:38:57
Le groupe nord-coréen Lazarus a combiné ingénierie sociale sophistiquée et exploitation d'une faille inédite pour s'introduire chez des acteurs de la défense et de l'aérospatiale en Europe, en...

Lire la suite »

Russian Hackers Abuse OAuth and WhatsApp Device Linking to Hijack High-Value Accounts

2026-08-21 11:31:54
Suspected Russian cyber-espionage groups are increasingly turning ordinary sign-in and device-linking features into tools for account takeover. Their latest campaigns do not depend on breaking passwords...

Lire la suite »

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

2026-08-21 11:30:16
A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial...

Lire la suite »

Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access

2026-08-21 11:23:51
Cybersecurity researchers have revealed a critical vulnerability in N-able's PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials...

Lire la suite »

Wazuh and AI For Enhanced SOC Workflows

2026-08-21 11:21:39
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive...

Lire la suite »

Fake Conferences, OAuth and WhatsApp: Inside Russia's New Espionage Tactics

2026-08-21 11:11:11
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked...

Lire la suite »

OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing

2026-08-21 11:07:22
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed...

Lire la suite »

Microsoft warns of max severity Entra ID flaw exploited in attacks

2026-08-21 11:04:10
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

Lire la suite »

mcp-stdio-shellguard v0.1.2

2026-08-21 11:03:56
Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security 200k-server stdio-RCE class (LiteLLM CVE-2025-69256)....

Lire la suite »

Hackers abuse FTP server banners to deliver new Windows malware

2026-08-21 11:00:00
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]

Lire la suite »

Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

2026-08-21 10:56:24
Cybercriminals are abusing interest in generative AI to trick users into downloading malware. In a newly documented incident, a file posing as a Google Gemini installer delivered the Vidar information...

Lire la suite »

Puériculture : trois bases clients revendiquées en 2026

2026-08-21 10:34:18
Trois bases liées à la maternité et la puériculture sont revendiquées en 2026, dont Made in Bébé, Allobébé et Babyvista.

Lire la suite »

oscp-notes-2026

2026-08-21 10:33:30
OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

Lire la suite »

Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords

2026-08-21 10:27:17
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing...

Lire la suite »

SickKids data breach exposes employee and job applicant info

2026-08-21 10:10:42
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party...

Lire la suite »

cantina

2026-08-21 10:03:48
OSCP-legal network recon orchestrator for port discovery, service classification, and enum-only plugin dispatch across HTTP, SMB, FTP, SNMP, SSH, and more.

Lire la suite »

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

2026-08-21 10:03:11
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities...

Lire la suite »

Rocky Linux 8 Kernel Important Security Bug Fix Advisory RLSA-2026-57253

2026-08-21 10:01:06
A significant update for Rocky Linux 8 addresses various kernel vulnerabilities and includes bug fixes and enhancements, emphasizing essential security improvements for the operating system.

Lire la suite »

Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing

2026-08-21 10:00:46
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender's threat model. Its latest experiment found that autonomous coding agents routinely...

Lire la suite »

GitLab Warns of Active Exploitation of Critical GraphQL Flaw

2026-08-21 09:49:02
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab...

Lire la suite »

Sitadel v1.5.1

2026-08-21 09:33:25
Web Application Security Scanner

Lire la suite »

Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data

2026-08-21 09:27:56
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind...

Lire la suite »

Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware

2026-08-21 09:17:46
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants....

Lire la suite »

Poland's CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw

2026-08-21 09:14:02
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response...

Lire la suite »

pbtk v1.1.3

2026-08-21 09:03:31
A toolset for reverse engineering and fuzzing Protobuf-based apps

Lire la suite »

Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape

2026-08-21 08:56:13
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with...

Lire la suite »

Services IT : comment l'IA fait évoluer les contrats de prestation

2026-08-21 08:42:46
Face aux gains de productivité générés par l'IA, les ESN françaises voient leur modèle historique de facturation au temps passé remis en cause. The post Services IT : comment l'IA fait évoluer...

Lire la suite »

iDescriptor v0.6.2

2026-08-21 08:33:11
A free, open-source, and cross-platform iDevice management tool

Lire la suite »

Une plateforme de gestion de rendez-vous médicaux piratée : 6,8 millions de profils volés

2026-08-21 08:31:31
Un hacker a revendiqué une cyberattaque contre Alaxione, une plateforme spécialisée dans la gestion des rendez-vous médicaux. Il assure avoir mis la main sur 6,8 millions de profils, qui incluraient...

Lire la suite »

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

2026-08-21 08:22:11
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added...

Lire la suite »

ToxicPanda 2.0 : un cheval de Troie bancaire Android nettement plus puissant découvert par le zLabs de Zimperium

2026-08-21 08:07:32
zLabs, l'équipe de recherche de Zimperium, leader mondial de la sécurité mobile basée sur l'IA, publie une nouvelle étude consacrée à ToxicPanda 2.0, une évolution majeure du cheval de Troie...

Lire la suite »

badkeys v0.0.20

2026-08-21 08:02:46
Tool to find common vulnerabilities in cryptographic public keys

Lire la suite »

The invisible passenger in your car

2026-08-21 08:00:29
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.

Lire la suite »

Cyberespionnage : l'arsenal « CAV3RN » évolue et détourne Google Apps Script pour cibler Israël

2026-08-21 08:00:08
Selon de nouvelles recherches menées par l’équipe GReAT de Kaspersky, le kit d’outils de cyberespionnage Project CAV3RN continue d’évoluer et de cibler activement des organisations...

Lire la suite »

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

2026-08-21 07:15:02
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack...

Lire la suite »

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

2026-08-21 07:04:25
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4),...

Lire la suite »

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

2026-08-21 06:06:11
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as...

Lire la suite »

Multiples vulnérabilités dans Google Chrome (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Lire la suite »

Vulnérabilité dans Python (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Lire la suite »

Vulnérabilité dans SPIP (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans SPIP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que cette vulnérabilité est activement exploitée....

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de SUSE (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans les produits IBM (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Debian (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges.

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Debian LTS (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans Traefik (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans Traefik. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.

Lire la suite »

Multiples vulnérabilités dans Microsoft Edge (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Lire la suite »

Vulnérabilité dans Microsoft Office (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

Lire la suite »

Multiples vulnérabilités dans les produits Microsoft (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un déni de service.

Lire la suite »

Vulnérabilité dans Microsoft Entra ID (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans Microsoft Entra ID. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-69836...

Lire la suite »