Toute l'actualité de la Cybersécurité


Help shape the future of resilient private 5G

2026-08-12 12:00:00
The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G

Lire la suite »

CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

2026-08-12 10:05:33
CAV3RN is a modular espionage framework that is becoming harder to see on a network. Its newest communication component hides remote-control traffic behind Google Apps Script, a service many organizations...

Lire la suite »

AI Is Making Everyone Faster but Not Necessarily Better

2026-08-12 09:51:24
AI is making workers faster, but speed without judgment creates polished mediocrity. Here's why taste, context, and human responsibility matter more than ever.

Lire la suite »

How I Used GPT-5.6 Sol to Upgrade an Existing Product Without Rebuilding It

2026-08-12 09:37:55
A solo builder explains how GPT-5.6 became more useful as a product auditor, code reviewer, and design partner than as a simple code generator.

Lire la suite »

WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud

2026-08-12 09:33:20
A newly identified Android malware family, tracked as WindRelay, is being used alongside the SpyNote remote-access trojan to convert victims' phones into rogue contactless-card readers and enable real-time,...

Lire la suite »

Une arnaque téléphonique piège des centaines de mairies en France

2026-08-12 09:31:12
Un commercial a promis à une mairie dans le Cher un standard téléphonique complet. Celle-ci s'est retrouvée avec trois téléphones fixes et des lignes qui sont la plupart du temps hors service....

Lire la suite »

GitHub Users Adapt to Initially Disliked Features but Retain Lingering Frustrations

2026-08-12 09:30:02
Why do developers complain about GitHub but stay? Explore six persistent workflow problems, vendor lock-in, and why teams keep working around GitHub's flaws.

Lire la suite »

Santé publique France visée par une cyberattaque ?

2026-08-12 09:27:54
Santé publique France visée par une intrusion revendiquée, avec élévation de privilèges et accès administrateur.

Lire la suite »

Mystery Lumber Delivery on Your Driveway? Here's How to Avoid Legal and Financial Disaster

2026-08-12 09:15:02
Unsolicited lumber deliveries can lead to legal and financial pitfalls, requiring immediate and informed action to avoid liability, storage fees,

Lire la suite »

Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

2026-08-12 09:04:15
Sandworm has turned the routine job interview into a route for compromising IT workers. The campaign uses convincing recruiter conversations, live video calls and a booby-trapped virtual private network...

Lire la suite »

Binance Just Turned Loyalty Into an Asset Class: Inside VIP Earn's 20% Rate Premium and 10x Quotas

2026-08-12 09:02:11
Binance launches VIP Earn with APRs up to 10-20% above regular rates and 10x quotas across 20+ tokens for VIP 1-9 users. Full analysis of what it changes.

Lire la suite »

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

2026-08-12 09:01:54
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310...

Lire la suite »

Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG' Email

2026-08-12 08:34:05
A new credential phishing campaign is using a fake “New Audio MSG” email to draw recipients toward a convincing Google-themed sign-in page. The message turns a familiar voicemail-style prompt into...

Lire la suite »

Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum

2026-08-12 08:27:13
Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats following...

Lire la suite »

Hindsight 'Solopreneur' Cracks AI Content Moderation, Beating Tech Giants

2026-08-12 08:26:27
A sub-600M-parameter AI model from Hindsight reportedly outperforms major content moderation models at detecting coded language, slang, and hidden threats.

Lire la suite »

The Best Network Traffic Analysis (NTA) Tools, Compared and Priced (2026)

2026-08-12 08:25:16
Network traffic analysis spans two buying worlds — ops tools with published price lists and security platforms with quote-only enterprise pricing — and knowing which world you're shopping in saves...

Lire la suite »

Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely

2026-08-12 08:24:28
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation could allow attackers to run malicious code on affected...

Lire la suite »

Top 10 Best Business VPN Solutions in 2026

2026-08-12 08:18:08
The best business VPN solutions in 2026 are increasingly the ones that aren't traditional VPNs at all. Twingate and Tailscale lead for modern least-privilege remote access, Cisco Secure Client (AnyConnect)...

Lire la suite »

Why Document Work Is Finally Moving Out of Desktop Software

2026-08-12 08:12:58
Discover why PDF editing is moving from desktop software to browser-based tools as remote work makes document access, conversion, and editing more flexible.

Lire la suite »

Microsoft corrige 398 failles Windows, dont une brèche exploitée par les pirates nord-coréens

2026-08-12 08:11:10
Microsoft vient de colmater 398 failles de sécurité dans le code de Windows. Trois failles zero day ont été débusquées ce mois-ci. L'une des failles est déjà exploitée par le tristement célèbre...

Lire la suite »

ShieldBreak: New Windows Zero-Day Bypasses Microsoft's RoguePlanet Patch

2026-08-12 08:07:15
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclipse,...

Lire la suite »

ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT

2026-08-12 08:05:00
ClickFix campaigns are once again turning an ordinary user action into the opening move of a serious intrusion. A newly documented chain uses a fake fix prompt to lead victims toward CNCMachineRMS, a...

Lire la suite »

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

2026-08-12 08:04:52
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other...

Lire la suite »

When a Stranger Reaches Out, People Now Check First

2026-08-12 08:01:37
Discover why people are checking unknown numbers, dating profiles, emails, and images before responding, as online verification becomes part of digital trust.

Lire la suite »

Paper Trading Won't Prove Your Strategy Works

2026-08-12 07:47:41
A demo account can't teach you to hold a loser. It can tell you whether your orders actually reach the exchange.

Lire la suite »

Top 10 Best Network Access Control (NAC) Solutions in 2026

2026-08-12 07:46:43
Modern network access control solutions decide which devices get onto your network, what they can reach once connected, and what happens when an unmanaged printer, camera, or unmanaged POS device shows...

Lire la suite »

How ControlCom Turns 300+ Million Monthly Facility Data Points Into Instant Answers With Tiger Data

2026-08-12 07:46:04
See how ControlCom Connect uses TimescaleDB to monitor thousands of industrial assets, process 300M+ data points monthly, and uncover costly anomalies.

Lire la suite »

Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks

2026-08-12 07:44:42
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that dynamically blends direct HTTPS traffic with Google Apps...

Lire la suite »

YOLO26 Object Detection: A Practical Guide

2026-08-12 07:44:32
Learn how YOLO26 handles object detection, its five model sizes, key use cases, limitations, inputs, outputs, and deployment options.

Lire la suite »

Top 10 Best DDoS Protection Services in 2026

2026-08-12 07:41:58
Cloudflare is the best DDoS protection service for most organizations in 2026, scoring highest in our evaluation on the combination of network capacity, always-on mitigation speed, and cost predictability...

Lire la suite »

Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access

2026-08-12 07:38:58
Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level access and helps neutralize endpoint visibility. This...

Lire la suite »

Building an AI Startup Without Funding

2026-08-12 07:36:41
I turned 25 on August 10th. Here's what I built to get here: two products in one fellowship, an AI platform, and a studio built from scratch, alone.

Lire la suite »

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

2026-08-12 07:31:40
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier...

Lire la suite »

Fuite de données chez Bloctel : des numéros de téléphone ont été piratés, c'est officiel

2026-08-12 07:12:53
Bloctel ferme ses portes… et se fait pirater. Alors que le service contre le démarchage téléphonique cesse ses activités, un pirate est parvenu à dérober une liste de numéros de téléphone inscrits...

Lire la suite »

Cette puce dans votre poche semble anodine : elle peut envoyer des SMS à votre insu et déclencher des actions à distance

2026-08-12 07:01:04
Et si une simple carte SIM pouvait prendre le contrôle d'un smartphone ou d'un objet connecté ? Des chercheurs ont découvert que les commandes normalement utilisées pour communiquer avec le modem...

Lire la suite »

Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE

2026-08-12 06:49:55
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday security updates...

Lire la suite »

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

2026-08-12 06:41:38
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The...

Lire la suite »

Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows

2026-08-12 06:38:32
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Seashell Blizzard. The activity, observed since...

Lire la suite »

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

2026-08-12 06:15:58
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity...

Lire la suite »

Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Day

2026-08-12 05:49:49
Microsoft's August 2026 Patch Tuesday released fixes for hundreds of vulnerabilities across various products, including Windows, Office, SharePoint, Azure, .NET, PowerShell, Visual Studio Code, and...

Lire la suite »

DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin' Phishing Attack

2026-08-12 05:32:40
A Delta Air Lines flight returning travelers from Las Vegas reportedly became the site of a high-altitude Wi-Fi phishing incident when someone on board allegedly disrupted the aircraft's official internet...

Lire la suite »

Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

2026-08-12 05:16:52
A newly disclosed flaw in Microsoft SharePoint Server has raised fresh concerns across enterprise IT environments, as security researchers reveal how attackers could remotely inject and execute malicious...

Lire la suite »

Zoom Zero-Click ‘Zoomsday' Flaw Lets Meeting Participants Execute Code on Other Users' Devices

2026-08-12 05:04:51
Zoom has released security updates to address four vulnerabilities that could expose meeting participants to significant attacks, including a zero-click remote code execution flaw dubbed “Zoomsday.”...

Lire la suite »

One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT

2026-08-12 05:00:51
A ClickFix prompt can end in a remote-access foothold. CNCMachineRMS, an undocumented x64 RAT deployed at the end of a BabaDeda loader chain that turns a user-driven execution event into persistent hands-on-keyboard...

Lire la suite »

Microsoft Outlook Vulnerability Allows Attackers to Execute Malicious Code Remotely

2026-08-12 03:40:32
Microsoft has disclosed a new remote code execution flaw in Outlook, tracked as CVE-2026-70329, as part of its August 2026 Patch Tuesday rollout. The vulnerability stems from an integer overflow or wraparound...

Lire la suite »

Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit

2026-08-12 03:23:37
North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule rootkit, according to new research from Check...

Lire la suite »

Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack

2026-08-12 02:34:28
What is the Attack? Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations,...

Lire la suite »

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

2026-08-12 01:15:55
Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]

Lire la suite »

Fedora 43 ClamAV Denial of Service Patch FEDORA-2026-a9beec8485

2026-08-12 01:11:21
Fedora 43 has released ClamAV version 1.4.6, enhancing the anti-virus toolkit with updates for proper error handling and multiple denial of service vulnerabilities. Updates are available via dnf.

Lire la suite »

Fedora 43 libidn Critical Out-of-bounds Exploit CVE-2026-57053

2026-08-12 01:11:15
Fedora 43 has released an update for libidn, version 1.44, fixing a security issue identified as CVE-2026-57053, addressing an out-of-bounds read vulnerability.

Lire la suite »

Fedora 44 ClamAV Denial of Service Issues Addressed 2026-ecf6fe868f

2026-08-12 00:48:44
Fedora 44 has updated ClamAV to version 1.4.6, enhancing its anti-virus toolkit functionality and addressing multiple security vulnerabilities and errors related to UTF-8 string handling.

Lire la suite »

Fedora 44 libidn Security Fix CVE-2026-57053 Out-of-bounds Read

2026-08-12 00:48:37
Fedora 44 has released an update for libidn version 1.44, addressing a security flaw (CVE-2026-57053) related to out-of-bounds reads in ToUnicode APIs.

Lire la suite »

Fedora 44 Domoticz Important Web Server API Fix for 2026-471f1abb1f

2026-08-12 00:48:33
Fedora released domoticz version 2026.3, an open-source home automation system, emphasizing essential security fixes for the web server and API, making the upgrade highly recommended.

Lire la suite »

SUSE OpenSSL Moderate DoS Fix Vulnerability 2026-3578-1

2026-08-12 00:40:12
A security update for openssl-1_1 addresses a remote DoS vulnerability in TLS ClientHello, affecting several SUSE products. Installation can be done via recommended methods or specific commands.

Lire la suite »