Toute l'actualité de la Cybersécurité


HaE HaEFile-1.0.3

2026-08-21 20:36:44
Modular Burp Suite extension for fine-grained highlighting and extraction of sensitive data from HTTP and WebSocket traffic, enabling efficient security analysis.

Lire la suite »

Krawl v2.3.0

2026-08-21 20:06:19
Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging vulnerabilities using realistic, randomly generated decoy data...

Lire la suite »

USN-8669-1: Linux kernel (NVIDIA) vulnerabilities

2026-08-21 19:59:28
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); ...

Lire la suite »

USN-8643-3: Linux kernel (NVIDIA) vulnerabilities

2026-08-21 19:54:33
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; ...

Lire la suite »

USN-8659-2: Linux kernel (HWE) vulnerability

2026-08-21 19:49:55
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch;

Lire la suite »

91 Spring CVEs: The AI Vulnerability Consumption Problem

2026-08-21 19:47:04
TL;DR Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects. At the time of publishing,...

Lire la suite »

USN-8668-1: Linux kernel (GCP) vulnerabilities

2026-08-21 19:45:48
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could...

Lire la suite »

USN-8667-1: Linux kernel (KVM) vulnerabilities

2026-08-21 19:27:34
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588....

Lire la suite »

USN-8662-2: Linux kernel (FIPS) vulnerabilities

2026-08-21 19:23:06
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; ...

Lire la suite »

prowler v5.39.1

2026-08-21 19:06:28
Prowler is the world's most widely used open-source cloud security platform that automates security and compliance across any cloud environment. Connect your agents now and build on the Agentic Cloud...

Lire la suite »

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

2026-08-21 18:53:00
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence...

Lire la suite »

Debian SPIP Critical Remote Code Execution Vuln DSA-6456-1

2026-08-21 18:45:35
A vulnerability in SPIP could allow unauthenticated remote code execution; it has been fixed in version 4.4.21+dfsg-0+deb13u1 for the stable distribution.

Lire la suite »

yakit v1.4.8-0821

2026-08-21 18:36:27
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and exploitation.

Lire la suite »

emp3r0r v4.11.0

2026-08-21 18:06:06
Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Lire la suite »

Your Shredded Visa Card May Still Work at the Checkout

2026-08-21 18:03:59
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts...

Lire la suite »

New SynkLoader malware pushed in Microsoft Teams phishing campaign

2026-08-21 18:01:30
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]

Lire la suite »

Claude Mythos 5 Now Available in Claude Security for Vulnerability Scanning

2026-08-21 17:46:37
Anthropic has expanded access to its frontier AI cyber-defense capabilities by making Claude Mythos 5 available in Claude Security, enabling enterprise customers to scan codebases for vulnerabilities...

Lire la suite »

OWASP Flags Top AI Skill Risks in New Security Blueprint

2026-08-21 17:36:53
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons....

Lire la suite »

edk2 edk2-stable202608

2026-08-21 17:35:41
Cross-platform firmware development environment implementing UEFI and PI specifications. Provides build tools, cryptographic libraries, and virtual platform support for hardware and embedded systems security....

Lire la suite »

retire.js v5.5.0

2026-08-21 17:05:35
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

Lire la suite »

Microsoft Expands Mailbox Storage From 50 GB to 100 GB for Users

2026-08-21 16:37:25
Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users can now receive up to 100 GB of Exchange Online...

Lire la suite »

claude-bug-bounty v6.0.0

2026-08-21 16:35:26
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

Lire la suite »

Escape Data ZATAZ 2.0 transforme l'enquête en jeu

2026-08-21 16:16:14
Escape Data ZATAZ 2.0 mêle escape game, OSINT, observation et réflexes cyber dans une enquête numérique estivale.

Lire la suite »

awesome-llvm-security

2026-08-21 16:05:16
Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and compiler-level reverse engineering.

Lire la suite »

Cyberattaque chez un prestataire de Suez : des données sensibles dérobées et mises en ligne

2026-08-21 16:02:44
Un prestataire de Suez Eau France a été victime d'une cyberattaque. Une partie des données a été exfiltrée et mise en ligne sur Internet. Si le fournisseur d'eau ne peut pas encore déterminer...

Lire la suite »

How I Built a Data Pipeline From Scratch Using Python

2026-08-21 16:00:06
Learn how I built a scalable data pipeline from scratch using Python, covering ingestion, processing, storage, and automation.

Lire la suite »

Your Screenplay Isn't Too Vague for a Director, but It Is for an AI Model

2026-08-21 16:00:03
AI video models do not infer intent like human crews. This guide shows how to rewrite vague screenplay action into clear, visible instructions for generation.

Lire la suite »

Pokémon Center touché par la cyberattaque d'un prestataire

2026-08-21 15:56:09
Cyberattaque : des données de clients Pokémon Center exposées et certaines précommandes annulées en Europe.

Lire la suite »

Hundreds of leaked AWS keys give full control over corporate accounts

2026-08-21 15:55:15
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]

Lire la suite »

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

2026-08-21 15:52:10
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows...

Lire la suite »

Target visé par une nouvelle revendication de fuite

2026-08-21 15:41:54
Un pirate renvendique le vol de codes sources à un géant de la grande distribution, sur fond d'une précédente fuite interne.

Lire la suite »

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

2026-08-21 15:41:44
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat...

Lire la suite »

openSUSE Tumbleweed redis Moderate CVE-2026-62356 Patch 2026-11542-1

2026-08-21 15:37:02
openSUSE Tumbleweed released an update for redis-8.10.1-1.1 addressing a moderate severity vulnerability identified as CVE-2026-62356, enhancing system security.

Lire la suite »

openSUSE Tumbleweed python313-pytest-html Moderate CVE-2026-73088

2026-08-21 15:37:01
An update for python313-pytest-html-4.2.0-5.1 on openSUSE Tumbleweed addresses a vulnerability, improving system security with details available in the corresponding CVE reference.

Lire la suite »

openSUSE go1.27 Moderate Security Update 2026-11536-1 for Multiple Issues

2026-08-21 15:37:01
An update for openSUSE Tumbleweed has been released, addressing nine vulnerabilities in the go1.27-1.27rc3-1.1 package, enhancing security for affected products.

Lire la suite »

openSUSE Tumbleweed libjxl-devel Moderate Fix CVE-2026-52584 2026-11537-1

2026-08-21 15:37:01
An update for openSUSE Tumbleweed resolves a vulnerability in the libjxl-devel package, providing enhanced security through version 0.12.0-1.1 for several related packages.

Lire la suite »

awesome-game-security

2026-08-21 15:34:56
Curated index of game security research: anti-cheat internals, DMA attacks, reverse engineering, kernel/mobile protections, and graphics API hooking for offensive and defensive analysis.

Lire la suite »

Des bases de joueurs européens de casino diffusées sur un forum pirate

2026-08-21 15:28:56
Un vendeur propose des bases de joueurs de casino européens contenant coordonnées, téléphones et données de dépôt.

Lire la suite »

Checker max cible les portefeuilles Solana en masse

2026-08-21 15:12:09
Checker max analyse Solana par lots de 1 000 adresses, une capacité sensible pour le triage de portefeuilles proposé sur un forum de pirates.

Lire la suite »

How CertiK Found Five Vulnerabilities in Besu and Got Them Fixed in a Fortnight

2026-08-21 15:06:40
CertiK reported five resource exhaustion bugs to the Besu maintainers who shipped the fixes within a fortnight and then published severity ratings that disagree

Lire la suite »

Debian LTS firefox-esr Critical Code Escalation Issues DLA-4750-1

2026-08-21 15:05:42
Debian LTS advisories report multiple security issues in the firefox-esr package that could lead to various vulnerabilities, urging users to upgrade to the patched versions.

Lire la suite »

camoufox v152.0.4-beta.29

2026-08-21 15:04:36
Open-source anti-detect Firefox fork for undetectable web scraping and AI agent automation. Injects realistic browser fingerprints, spoofs geolocation/WebRTC, and evades anti-bot systems at scale.

Lire la suite »

Oracle Linux 10 kbd Moderate Threat Fix ELSA-2026-57597

2026-08-21 15:01:40
Oracle Linux released updates for version 10, addressing CVE-2026-72693 with enhancements to the openvt process matching. New RPMs are available for x86_64 and aarch64 architectures.

Lire la suite »

Oracle Linux 10 Kernel Important Bug Fixes Advisory ELSA-2026-57251

2026-08-21 15:01:38
Oracle Linux has released several kernel updates addressing multiple CVEs, including security enhancements and fixes for various stability and performance issues in its 10th version.

Lire la suite »

Oracle Linux 10 ansible-core Important Remote Access Fix ELSA-2026-57148

2026-08-21 15:01:36
Oracle Linux 10 updates include versions of ansible-core and ansible-test that address CVE-2026-11332, which involved potential arbitrary git configuration injection during role installation.

Lire la suite »

Oracle Linux 10 java-25-openjdk Medium Update For ELSA-2026-55798

2026-08-21 15:01:34
Oracle Linux has released updated Java packages for version 10 to address several CVEs, including CVE-2026-60589 and others, with a detailed list of RPMs provided.

Lire la suite »

Oracle Linux 9 kbd Moderate Buffer Overflow Fix ELSA-2026-57610

2026-08-21 15:01:27
Oracle Linux 9 has received an update for kbd packages to address CVE-2026-72693, improving openvt process matching. Updated RPMs are available for x86_64 and aarch64.

Lire la suite »

Oracle Linux 9 Kernel Important Bug Fix Advisory ELSA-2026-57252

2026-08-21 15:01:25
Oracle Linux 9 has released kernel updates addressing various CVEs, improving security and performance through updates to kernel components and features, including UKI signing and timers.

Lire la suite »

Microsoft blames Windows gaming issues on RGB lighting devices

2026-08-21 14:54:49
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]

Lire la suite »

AI Code Review: If AI Writes the Code, How Do We Review It at Scale?

2026-08-21 14:54:44
Learn what AI code review is, how it differs from AI code generation, where it fits in the SDLC, and how to evaluate AI review tools for production.

Lire la suite »

Scammers Use WhatsApp Groups to Coordinate Millions in Victim Trades and Pump Real Stocks

2026-08-21 14:52:11
Scammers are using WhatsApp groups to turn ordinary investors into an unwitting buying force. The operation does not need a hacked trading account or a stolen card. Instead, it persuades people to place...

Lire la suite »

DYSPHOR1A, nouveau groupe de ransomware maître chanteur

2026-08-21 14:44:23
DYSPHOR1A émerge comme un nouveau groupe ransomware maître chanteur, avec ventes, fuites et retraits payants de données.

Lire la suite »

Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks

2026-08-21 14:41:55
A Chinese-speaking cybercrime group is using AI-assisted tools to turn vulnerable web servers into entry points. It shows how familiar flaws become more dangerous when attackers automate the work around...

Lire la suite »

prismsec

2026-08-21 14:34:25
Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

Lire la suite »

Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection

2026-08-21 14:14:20
Hackers are using Unicode emoji characters to hide an Agent Tesla JScript dropper in a business email compromise campaign aimed at finance teams. The tactic turns a payment-related attachment into a difficult-to-read...

Lire la suite »

I Turned My iOS Memory Game Into a Physical Board for Shipaton

2026-08-21 14:08:05
I took Adversary off-screen, turning its core mechanic into a physical prototype as the next step in my Build in Public journey.

Lire la suite »

Zombie Card: An expired Visa credit card can be used for purchases

2026-08-21 14:03:48
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.

Lire la suite »

Le « Legal Engineer », ce nouveau métier à la frontière du droit et de l'IA que Microsoft recrute

2026-08-21 14:02:06
Au sein de la direction juridique, le Principal Legal Engineer devra concevoir et déployer des agents IA, retravailler les prompts et les workflows juridiques mais aussi orchestrer Copilot et Harvey,...

Lire la suite »

The TechBeat: The Claude Opus 5 Rumor Passed the Screenshot Test, Not the API Contract Test (8/21/2026)

2026-08-21 14:01:05
8/21/2026: Trending stories on Hackernoon today!

Lire la suite »

Is Online Privacy Possible? How Digital Identities Can Help

2026-08-21 14:00:10
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas...

Lire la suite »

500 Blog Posts To Learn About Mobile App Development

2026-08-21 14:00:09
Learn everything you need to know about Mobile App Development via these 500 free HackerNoon blog posts.

Lire la suite »

Calling on Cyber Pros to Help Defend City Hall

2026-08-21 14:00:00
Government agencies with smaller budgets need support — and here's how you can help.

Lire la suite »

Un recrutement VPN français intrigue sur un forum pirate

2026-08-21 13:56:56
Un membre d'un forum pirate russe recrute des francophones pour un VPN, malgré un historique lié au spam et aux RAT.

Lire la suite »

Data Debt in Production ML Pipelines: Detection and Remediation at Scale

2026-08-21 13:42:19
Learn how to catch data debt before it degrades production ML models using schema checks, null monitoring, PSI, KS tests, and drift detection.

Lire la suite »

Microsoft rolls out Classic Outlook theme for New Outlook users

2026-08-21 13:39:35
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]

Lire la suite »

A Reference Architecture for AI-Driven Healthcare Data Engineering

2026-08-21 13:30:58
Healthcare data platforms are evolving beyond ETL, using AI for anomaly detection, entity matching, forecasting, compliance, and data quality.

Lire la suite »

OpenAI Adds Controls That Should've Been There Already

2026-08-21 13:30:00
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.

Lire la suite »

Claude Opus 5 Routes Around Obfuscated Binaries Instead of Defeating the Protection

2026-08-21 13:26:20
Claude Opus 5 did not crack hardened binaries in a reverse-engineering experiment. Instead, it sought easier ways to recover hidden information, showing AI-assisted analysis can be capable yet unreliable....

Lire la suite »

Turning Apache DolphinScheduler Into an Agent-Friendly Workflow Platform

2026-08-21 13:19:08
dsctl adds CLI-based automation, workflow-as-code, CI/CD, and controlled AI-agent operations to Apache DolphinScheduler through its REST APIs.

Lire la suite »

Cybersecurity Ventures and World Economic Forum On The Global Cost of Cybercrime

2026-08-21 13:15:37
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 21, 2026 – Read the full Irish Times Story A special report from The Irish Times declares cyber...

Lire la suite »

US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim

2026-08-21 13:08:51
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank...

Lire la suite »

Deux millions de données françaises mises en vente

2026-08-21 13:08:19
Un forum pirate propose deux millions de données françaises, sans preuve publique sur leur origine.

Lire la suite »

Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks

2026-08-21 13:06:57
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the...

Lire la suite »

Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts

2026-08-21 13:06:34
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisements, impersonated financial experts, and coordinated...

Lire la suite »

Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks

2026-08-21 13:06:02
GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478, a critical unauthenticated code injection vulnerability affecting self-managed...

Lire la suite »

US Bank Investigating Data Breach Following LockBit Ransomware Claim

2026-08-21 13:01:06
US Bank is investigating LockBit's claims of a breach and data theft, with the ransomware group threatening to publish the alleged stolen files on September 3 unless an undisclosed ransom is paid. Lee...

Lire la suite »

Zero Trust In The Age Of AI Driven Cyber Threats (Why Cisos Must Redefine Enterprise Trust Boundaries In 2026)

2026-08-21 13:00:48
Enterprise cybersecurity is undergoing a structural shift driven by two converging forces: the collapse of traditional network perimeters and the rapid weaponization of artificial intelligence by threat...

Lire la suite »

Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes

2026-08-21 13:00:14
A critical vulnerability in N-able Passportal's Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization's entire password vault, including...

Lire la suite »

Your Five-Minute AI Film Does Not Need a 15-Beat Structure

2026-08-21 13:00:02
The classic 15-beat structure is built for a 90-minute feature. Here's how to size a beat sheet for a short AI-generated film instead.

Lire la suite »

C.Hunters, un service pirate testé pour la France

2026-08-21 12:52:57
C.Hunters propose des appels ciblés sur un forum pirate, avec un intérêt explicite pour la France.

Lire la suite »

Binance Launches Agent OS, Letting AI Agents Trade on Your Account With Limits You Set

2026-08-21 12:40:00
Covering AI, Web3, Cybersecurity, Startup Funding & Enterprise SaaS. Top Journalist & Thought Leadership Media Leader

Lire la suite »

Six Maximum-Severity Flaws Found in Cisco Products

2026-08-21 12:30:16
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms...

Lire la suite »

CISA orders feds to patch actively exploited TrueConf Server flaws

2026-08-21 12:25:33
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications...

Lire la suite »

Encore, encore, encore … un nouveau groupe ransomware : SovCali

2026-08-21 12:03:50
Un nouvel acteur du rançongiciel, SovCali, apparaît et affirme détenir des données de Lucid Motors, première cible publiquement revendiquée.

Lire la suite »

The New Russian Playbook: Bypassing MFA Without Cracking Passwords

2026-08-21 12:00:48
OAuth Exploitation Russian threat actors are shifting away from plain old password theft and moving toward legitimate platform features like OAuth permissions. Groups like UNC6293 and UNC7005 take their...

Lire la suite »

Medical records, SSNs, and bank details exposed in CareCloud data breach

2026-08-21 11:50:55
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.

Lire la suite »

Comment Lazarus détourne des offres d'emploi pour infiltrer l'industrie de la défense

2026-08-21 11:38:57
Le groupe nord-coréen Lazarus a combiné ingénierie sociale sophistiquée et exploitation d'une faille inédite pour s'introduire chez des acteurs de la défense et de l'aérospatiale en Europe, en...

Lire la suite »

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

2026-08-21 11:30:16
A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial...

Lire la suite »

Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access

2026-08-21 11:23:51
Cybersecurity researchers have revealed a critical vulnerability in N-able's PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials...

Lire la suite »

Wazuh and AI For Enhanced SOC Workflows

2026-08-21 11:21:39
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive...

Lire la suite »

Fake Conferences, OAuth and WhatsApp: Inside Russia's New Espionage Tactics

2026-08-21 11:11:11
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked...

Lire la suite »

OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing

2026-08-21 11:07:22
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed...

Lire la suite »

Microsoft warns of max severity Entra ID flaw exploited in attacks

2026-08-21 11:04:10
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

Lire la suite »

Hackers abuse FTP server banners to deliver new Windows malware

2026-08-21 11:00:00
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]

Lire la suite »

Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords

2026-08-21 10:27:17
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing...

Lire la suite »

SickKids data breach exposes employee and job applicant info

2026-08-21 10:10:42
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party...

Lire la suite »

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

2026-08-21 10:03:11
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities...

Lire la suite »

Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing

2026-08-21 10:00:46
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender's threat model. Its latest experiment found that autonomous coding agents routinely...

Lire la suite »

GitLab Warns of Active Exploitation of Critical GraphQL Flaw

2026-08-21 09:49:02
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab...

Lire la suite »

Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data

2026-08-21 09:27:56
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind...

Lire la suite »

Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware

2026-08-21 09:17:46
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants....

Lire la suite »

Poland's CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw

2026-08-21 09:14:02
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response...

Lire la suite »

Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape

2026-08-21 08:56:13
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with...

Lire la suite »

Services IT : comment l'IA fait évoluer les contrats de prestation

2026-08-21 08:42:46
Face aux gains de productivité générés par l'IA, les ESN françaises voient leur modèle historique de facturation au temps passé remis en cause. The post Services IT : comment l'IA fait évoluer...

Lire la suite »

Une plateforme de gestion de rendez-vous médicaux piratée : 6,8 millions de profils volés

2026-08-21 08:31:31
Un hacker a revendiqué une cyberattaque contre Alaxione, une plateforme spécialisée dans la gestion des rendez-vous médicaux. Il assure avoir mis la main sur 6,8 millions de profils, qui incluraient...

Lire la suite »

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

2026-08-21 08:22:11
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added...

Lire la suite »

ToxicPanda 2.0 : un cheval de Troie bancaire Android nettement plus puissant découvert par le zLabs de Zimperium

2026-08-21 08:07:32
zLabs, l'équipe de recherche de Zimperium, leader mondial de la sécurité mobile basée sur l'IA, publie une nouvelle étude consacrée à ToxicPanda 2.0, une évolution majeure du cheval de Troie...

Lire la suite »

The invisible passenger in your car

2026-08-21 08:00:29
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.

Lire la suite »

Cyberespionnage : l'arsenal « CAV3RN » évolue et détourne Google Apps Script pour cibler Israël

2026-08-21 08:00:08
Selon de nouvelles recherches menées par l’équipe GReAT de Kaspersky, le kit d’outils de cyberespionnage Project CAV3RN continue d’évoluer et de cibler activement des organisations...

Lire la suite »

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

2026-08-21 07:15:02
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack...

Lire la suite »

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

2026-08-21 07:04:25
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4),...

Lire la suite »

Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

2026-08-21 06:06:11
Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the "Exploited" field under the Exploitability...

Lire la suite »

List of 21 new domains

2026-08-21 00:00:00
.fr betifycasinoo[.fr] (registrar: Telepublicity B.V.) celsiuscasino-connexion[.fr] (registrar: Marcaria.com International Inc.) cora-distribution[.fr] (registrar: GANDI) creditmut-capital[.fr] (registrar:...

Lire la suite »

Multiples vulnérabilités dans Google Chrome (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Lire la suite »

Vulnérabilité dans Python (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Lire la suite »

Vulnérabilité dans SPIP (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans SPIP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que cette vulnérabilité est activement exploitée....

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de SUSE (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans les produits IBM (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Debian (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges.

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Debian LTS (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans Traefik (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans Traefik. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.

Lire la suite »

Multiples vulnérabilités dans Microsoft Edge (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Lire la suite »

Vulnérabilité dans Microsoft Office (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

Lire la suite »

Multiples vulnérabilités dans les produits Microsoft (21 août 2026)

21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un déni de service.

Lire la suite »

Vulnérabilité dans Microsoft Entra ID (21 août 2026)

21/08/2026
Une vulnérabilité a été découverte dans Microsoft Entra ID. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-69836...

Lire la suite »