Toute l'actualité de la Cybersécurité


Infrastructure as Code with APIs: Automating Cloud Resources the Developer Way

2026-03-22 16:00:30
Infrastructure as Code is a way to manage cloud resources using code. Instead of setting up servers, databases, and networks by hand, you define them in scripts or configuration files. These files describe...

Lire la suite »

AstraZeneca Data Breach – LAPSUS$ Group Allegedly Claims Access to Internal Data

2026-03-22 15:49:49
The notorious hacking collective LAPSUS$ has resurfaced, allegedly claiming responsibility for a significant data breach involving the multinational pharmaceutical and biotechnology company AstraZeneca....

Lire la suite »

How To Redesign Every Web Page You're On (Or: How a Bazooka Subwoofer Inspired My Browser Extension)

2026-03-22 15:45:23
Polish is an open-source tool that lets you change the look of any web page or app. It's powered by AI, and includes built-in tools like Font scaling and Focus Mode. Polish was built to solve a real problem:...

Lire la suite »

Oracle fixes critical RCE flaw CVE-2026-21992 in Identity Manager

2026-03-22 15:37:49
Oracle fixed a critical severity flaw, tracked as CVE-2026-21992, enabling unauthenticated remote code execution in Identity Manager. Oracle released security updates to address a critical vulnerability,...

Lire la suite »

U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog

2026-03-22 14:40:01
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure...

Lire la suite »

VoidStealer malware steals Chrome master key via debugger trick

2026-03-22 14:32:46
An information stealer called VoidStealer uses a new approach to bypass Chrome's Application-Bound Encryption (ABE) and extract the master key for decrypting sensitive data stored in the browser. [...]...

Lire la suite »

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 89

2026-03-22 09:55:07
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter New Payload ransomware – malware analysis  ...

Lire la suite »

Ubuntu Jammy SPIP Security Vulnerability Identified as CVE-2023-4567

2026-03-22 09:40:34
Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1....

Lire la suite »

Infrastructure Pivoting: How CTI Analysts Expand From a Single IOC to a Full Attacker Network

2026-03-22 05:15:25
The field manual for tracing attacker infrastructure — from one domain to dozensContinue reading on InfoSec Write-ups »

Lire la suite »

Ploutus Malware: Uptick in ATM jackpotting incidents prompts FBI warning

2026-03-22 05:14:38
Three weeks ago, renewed activity involving Ploutus ATM malware surfaced, prompting an alert from the Federal Bureau of Investigation (FBI). At the time, we published an initial breakdown covering the...

Lire la suite »

How I Found a Hardcoded RSA Private Key in a Major Crypto Exchange's Frontend

2026-03-22 05:14:17
How I Found a Hardcoded RSA Private Key in a Major Crypto Exchange's Frontend -And What I Learned the Hard WayA Bug Bounty Story About Recon, Excitement, and Harsh RealityIt started like any other...

Lire la suite »

Found a Denial of Service Vulnerability in a Major Company's Production Infrastructure Using Shodan

2026-03-22 05:14:10
A step-by-step story of reconnaissance, discovery, and responsible disclosureBug bounty hunting is rarely glamorous. Most of the time, it's hours of staring at HTTP responses, chasing dead ends, and...

Lire la suite »

Fedora 42 Chromium 146.0.7680.80 Vital Fix for Out of Bounds Write Issue

2026-03-22 01:09:58
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

Lire la suite »

Fedora 42 python-scitokens Path Traversal SQL Fix FEDORA-2026-dec8f790f7

2026-03-22 01:09:57
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation...

Lire la suite »

Fedora 42 python-ujson 5.12.0 Buffer Overflow DoS Advisory 2026-0f099ed388

2026-03-22 01:09:52
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Lire la suite »

Fedora 43 python-scitokens Advisory 2026-727b73bfa0 Path Traversal Fix

2026-03-22 00:54:50
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation...

Lire la suite »

Fedora 43 python-ujson Critical DoS Buffer Overflow 2026-bf741e26e4

2026-03-22 00:54:41
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Lire la suite »

Security Affairs newsletter Round 568 by Pierluigi Paganini – INTERNATIONAL EDITION

2026-03-22 00:48:41
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs...

Lire la suite »

List of 9 new domains

2026-03-22 00:00:00
.fr connexion-1003[.fr] (registrar: PDR Ltd. d/b/a PublicDomainRegistry.com) connexion-10292[.fr] (registrar: PDR Ltd. d/b/a PublicDomainRegistry.com) connexion-12930[.fr] (registrar: PDR Ltd. d/b/a PublicDomainRegistry.com) connexion-1322[.fr]...

Lire la suite »