Toute l'actualité de la Cybersécurité


Hermes AI agent used to automate attack on Thai Finance Ministry

2026-07-24 19:09:09
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

Lire la suite »

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

2026-07-24 17:50:37
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

Lire la suite »

Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers

2026-07-24 11:15:33
Tel Aviv, Israel, 24th July 2026, CyberNewswire

Lire la suite »

Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

2026-07-24 16:35:58
A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active...

Lire la suite »

Cyber actualités ZATAZ de la semaine du 20 au 26 juillet 2026

2026-07-24 16:08:00
Bonjour à toutes et tous, Cette semaine, l'actualité cyber se concentre sur l'automatisation de l'extorsion, les fuites revendiquées et la pression exercée sur les organisations. Titan promet...

Lire la suite »

HackerNoon Projects of the Week: RecallNote , ACHLS Eternal, Rivver Accountant

2026-07-24 16:00:06
Three startups—RecallNote , ACHLS Eternal, and Rivver Accountant—featured in HackerNoon Projects of the Week for proving real-world usefulness.

Lire la suite »

Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers

2026-07-24 15:56:46
Three critical remote code execution (RCE) vulnerabilities in Microsoft’s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing...

Lire la suite »

Deux jeux d'été pour vérifier et déchiffrer

2026-07-24 15:47:00
Deux jeux d'été mêlent fact-checking, détection IA et chiffrement pour entraîner l'esprit critique en famille.

Lire la suite »

Microsoft blames massive Microsoft 365 outage on maintenance bug

2026-07-24 15:41:44
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft...

Lire la suite »

Quatre rendez-vous cyber à suivre jusqu'en octobre

2026-07-24 15:15:20
Barbhack, DEF CON, Cyberbrew et Hackfest rythment la rentrée cyber, de Toulon à Québec, en passant par Lille.

Lire la suite »

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

2026-07-24 15:12:35
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing...

Lire la suite »

World Foundation Raises .5 Million to Scale Proof of Human as AI Transforms the Internet

2026-07-24 15:01:30
World Foundation raised .5 million in a Pantera-led locked WLD sale on its third anniversary. Inside the Vercel, Okta, and Tinder distribution thesis.

Lire la suite »

Don’t get fooled by TikTok resin art scams

2026-07-24 14:56:34
Scammers are using stolen videos and fake artist profiles to trick people into buying resin art that never arrives. Here's how to spot the warning signs.

Lire la suite »

Call of Duty Mobile scam uses fake free points to steal player accounts

2026-07-24 14:54:23
A phishing site posing as a free Call of Duty Points giveaway is stealing Activision logins and two-factor authentication codes.

Lire la suite »

OpenAI’s agent escaped its sandbox during a security test

2026-07-24 14:51:45
An OpenAI agent escaped its sandbox, stole credentials, and broke into Hugging Face. Here's what that actually means.

Lire la suite »

Titan automatise le chantage aux données

2026-07-24 14:37:58
Titan promet d'automatiser l'analyse des fuites, le calcul des rançons et la pression réglementaire.

Lire la suite »

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

2026-07-24 14:15:21
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They...

Lire la suite »

Chick-fil-A data breach affects more than 13,000 customers

2026-07-24 14:04:29
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]

Lire la suite »

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

2026-07-24 14:01:11
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how...

Lire la suite »

The TechBeat: Apple v. OpenAI Trade Secrets Lawsuit: The 42 Most Explosive Allegations & The Internet's Reactions (7/24/2026)

2026-07-24 14:00:51
7/24/2026: Trending stories on Hackernoon today!

Lire la suite »

314 Blog Posts To Learn About Developer Tools

2026-07-24 14:00:12
Learn everything you need to know about Developer Tools via these 314 free HackerNoon blog posts.

Lire la suite »

Meet the Writer: Hacker Noon's Contributor Prakshal Doshi, Site Reliability Engineer

2026-07-24 13:45:08
SRE at Apple writing about AI infrastructure, Kubernetes, and cloud reliability.Real production experience. Building tools & community at AI/DevOps intersection

Lire la suite »

Google wants to store a selfie video of your face

2026-07-24 13:41:45
A new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.

Lire la suite »

Un faux portail FPR pour piéger des pirates

2026-07-24 13:19:22
Un faux portail FPR imitait la Police nationale pour enregistrer les recherches et identités de pirates.

Lire la suite »

Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot

2026-07-24 13:17:47
Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts often think that requests accepted by a higher...

Lire la suite »

Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading

2026-07-24 13:15:56
A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239,...

Lire la suite »

AMD entre vraiment dans le jeu des racks IA exascale

2026-07-24 13:08:19
AMD intègre ses nouvelles générations de CPU (EPYC Venice) et de GPU (Instinct MI455X) dans des racks Helios AI qui atteignent l'exaflops en inférence FP8. The post AMD entre vraiment dans le jeu...

Lire la suite »

Cl0p Hackers Exploit Windchill Servers to Steal Companies' Secret Product Designs

2026-07-24 13:05:36
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data. The campaign combines software flaws to gain access without credentials,...

Lire la suite »

openSUSE Advisory 2026-0259-1 gh Important Punycode Fix CVE-2026-39821

2026-07-24 13:04:49
openSUSE released a security update for the gh package to address CVE-2026-39821, which involves rejecting certain Punycode labels in the idna package, rated important.

Lire la suite »

Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign

2026-07-24 13:04:41
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation...

Lire la suite »

Frontier AI and the Vulnerability Gap in OT

2026-07-24 13:00:34
The landscape of cyber defense and offense is shifting beneath our feet. Over the past few weeks, the release of “frontier” AI models has accelerated the arms race, forcing a... The post Frontier...

Lire la suite »

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

2026-07-24 13:00:00
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.

Lire la suite »

Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos

2026-07-24 12:57:50
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors...

Lire la suite »

Europol flags 4,340 URLs for removal in 'The Com' crackdown

2026-07-24 12:56:53
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]

Lire la suite »

KnowBe4's Unveils Custom AI Video Builder

2026-07-24 12:52:53
KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of Custom AI Video Builder, a new capability that lets security admins create custom,...

Lire la suite »

L'incident OpenAI–Hugging Face n'est pas la révolution que vous imaginez

2026-07-24 12:52:45
{ Tribune Expert } - Ce que démontre l'incident Hugging Face, ce n'est pas une sophistication supérieure, mais une orchestration infatigable : un opérateur capable d'enchaîner une douzaine d'étapes...

Lire la suite »

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

2026-07-24 12:48:16
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and...

Lire la suite »

openSUSE Avahi Moderate DoS CVE-2025-59529 Advisory 2026-3217-1

2026-07-24 12:33:33
SUSE has released a security update for avahi to address CVE-2025-59529, which allows local denial of service due to a client limit issue in the protocol server.

Lire la suite »

openSUSE avahi Moderate Denial of Service Fix 2026-3218-1

2026-07-24 12:33:26
SUSE released a security update addressing CVE-2025-59529, which causes a local denial of service in avahi. Users are advised to update using recommended installation methods.

Lire la suite »

openSUSE ImageMagick Important Security Fix for Multiple Flaws 2026-3219-1

2026-07-24 12:33:19
SUSE has released an important security update for ImageMagick, addressing 25 vulnerabilities and providing a fix for significant bugs affecting openSUSE Leap and SUSE Linux Enterprise Server.

Lire la suite »

openSUSE nmap Moderate Out-of-Bounds Crash Vulnern 2026-3220-1

2026-07-24 12:32:27
SUSE released a security update for nmap addressing CVE-2026-58058, which resolves a vulnerability that can lead to out-of-bounds reads and crashes in openSUSE Leap 15.4.

Lire la suite »

openSUSE 2026-3224-1 SVT-AV1 Important Remote Code Execution Fix

2026-07-24 12:32:00
A security update addressing four vulnerabilities in SVT-AV1, libyuv0, and libaom3 has been released, affecting several SUSE Linux products; installation instructions are provided.

Lire la suite »

B9 : 36 000 profils bancaires annoncés piratés

2026-07-24 12:20:18
B9 fait l'objet d'une fuite présumée de 36 000 profils, illustrant les risques cyber des banques 100 % en ligne.

Lire la suite »

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

2026-07-24 12:10:28
Hunt.io uncovered a cyber-espionage attack on Thailand's Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion...

Lire la suite »

Pokemon Gym : 19 600 comptes exposés

2026-07-24 12:01:24
Fuite Pokemon Gym : 19 600 comptes de joueurs et joueuses, adresses IP et messages privés exposés.

Lire la suite »

New CISA/NSA Advisory Spotlights Russian Attacks on Zimbra Webmail

2026-07-24 12:00:17
Overview of the Advisory On July 23, 2026, CISA, the NSA, the FBI, and their international partners issued a joint cybersecurity advisory alerting organizations to ongoing Russian state-sponsored activity....

Lire la suite »

Beyond the Play Store: How Android threats really spread

2026-07-24 12:00:00
Some threats never pass through the Play Store. Others arrive later in seemingly legitimate updates. Here's how Malwarebytes detects both.

Lire la suite »

Apache Syncope Release Patches for Multiple RCE and SQL Injection Vulnerabilities

2026-07-24 11:58:13
Apache has issued critical security updates for its Syncope identity and access management (IAM) platform to address multiple vulnerabilities, including remote code execution (RCE), SQL injection, privilege...

Lire la suite »

JetBrains Fixes Critical IntelliJ IDEA Code Execution Flaw and Four TeamCity Vulnerabilities

2026-07-24 11:58:10
JetBrains has released security updates to address a critical code execution vulnerability in IntelliJ IDEA, alongside four high-severity vulnerabilities in TeamCity. Development teams and CI administrators...

Lire la suite »

SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files

2026-07-24 11:58:00
SectopRAT is at the center of a highly targeted malvertising campaign abusing Anthropic's Claude platform to deliver a stealthy, HVNC‑enabled RAT that gives attackers deep, persistent access to victims'...

Lire la suite »

FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

2026-07-24 11:54:18
A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software...

Lire la suite »

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

2026-07-24 11:53:55
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous...

Lire la suite »

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

2026-07-24 11:45:17
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing...

Lire la suite »

Examining the Unintended Consequences of the Online Safety Act

2026-07-24 11:43:38
The 25th July 2026 marks one year since the Online Safety Act’s landmark child safety duties came into force, making it a natural moment to assess what’s changed, what’s worked and what...

Lire la suite »

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

2026-07-24 11:30:00
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is...

Lire la suite »

ROCm.ai, ou comment AMD inculque sa stack aux LLM

2026-07-24 11:27:48
Avec ROCm.ai, AMD promet de la programmation GPU assistée par IA, au moyen de skills et d'un système agentique dit Hyperloom. The post ROCm.ai, ou comment AMD inculque sa stack aux LLM appeared first...

Lire la suite »

ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims

2026-07-24 11:26:58
ChonkyChicken is a newly identified remote access trojan designed to turn one infected Windows device into a platform for credential theft, network movement, and surveillance. The malware is part of the...

Lire la suite »

Microsoft Confirms No Bloatware Ads in Windows 11; LG Disables McAfee Pop-ups

2026-07-24 11:26:34
Microsoft has moved quickly to shut down unwanted antivirus advertising after users discovered that connecting an LG monitor could silently install companion software and trigger a McAfee trial pop-up...

Lire la suite »

Man gets six years for hacking 750 women's Snapchat accounts

2026-07-24 11:17:19
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]

Lire la suite »

SourTrade Malvertising Builds Unique Malware Inside Victims' Browsers to Evade Detection

2026-07-24 11:09:16
SourTrade is a long-running malvertising operation that uses fake ads to lure cryptocurrency users toward convincing copies of trading and exchange platforms. The campaign has been active since late 2024...

Lire la suite »

Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

2026-07-24 11:04:51
Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

Lire la suite »

Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions

2026-07-24 10:53:38
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation...

Lire la suite »

Le mouvement vers le cloud va-t-il s'inverser avec l'IA ?

2026-07-24 10:52:37
{ Tribune Expert } - L'intelligence artificielle ne remet pas en cause le cloud. En revanche, elle remet clairement l'infrastructure au cœur des décisions stratégiques. The post Le mouvement vers le...

Lire la suite »

Debian LTS DLA-4698-1 Spice-Vdagent Critical DoS Path Traversal

2026-07-24 10:39:31
Debian issued an advisory for spice-vdagent, addressing two vulnerabilities: an integer overflow leading to DoS and a path traversal allowing unauthorized file writes. Updates are recommended.

Lire la suite »

Motherless : les serveurs saisis au cœur de l'enquête

2026-07-24 10:34:57
La police saisit les serveurs du site pour adultes Motherless dans une enquête européenne sur des contenus vidéos criminels.

Lire la suite »

USN-8610-1: Linux kernel (Azure CVM) vulnerabilities

2026-07-24 10:34:35
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could...

Lire la suite »

USN-8575-3: Linux kernel vulnerabilities

2026-07-24 10:30:08
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could...

Lire la suite »

USN-8609-1: Linux kernel (Azure CVM) vulnerabilities

2026-07-24 10:26:03
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

USN-8608-1: Linux kernel (Azure FIPS) vulnerabilities

2026-07-24 10:23:19
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

Le Pentagone consolide ses licences logicielles Oracle

2026-07-24 10:21:06
Un contrat pouvant atteindre 7 milliards $ sur dix ans doit remplacer une mosaïque d'accords dispersés entre les armées, le renseignement et les gardes-côtes. The post Le Pentagone consolide ses licences...

Lire la suite »

USN-8607-1: Linux kernel (Azure CVM) vulnerabilities

2026-07-24 10:20:29
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

USN-8606-1: Linux kernel (Azure) vulnerabilities

2026-07-24 10:17:16
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

2026-07-24 10:15:29
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which...

Lire la suite »

AI Hack : une fuite chez Darsa AI ?

2026-07-24 10:14:57
Un pirate revendique une fuite chez Darsa AI et multiplie les publications visant des acteurs liés à l'Intelligence Artificielle.

Lire la suite »

USN-8595-2: Linux kernel (AWS) vulnerabilities

2026-07-24 10:14:09
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

USN-8605-1: Linux kernel (Azure CVM) vulnerabilities

2026-07-24 10:11:06
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); ...

Lire la suite »

SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design

2026-07-24 10:10:28
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry's reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade...

Lire la suite »

New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims

2026-07-24 10:09:52
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.

Lire la suite »

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

2026-07-24 10:09:24
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite...

Lire la suite »

USN-8604-1: Linux kernel (Azure) vulnerabilities

2026-07-24 10:07:12
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); ...

Lire la suite »

Ubuntu 26.04 LTS Linux Kernel Important Security Flaws USN-8603-1

2026-07-24 10:03:33
Ubuntu 26.04 LTS users are advised to update their kernel due to multiple vulnerabilities affecting AMD processors, including potential privilege escalation and sensitive data exposure.

Lire la suite »

UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations

2026-07-24 09:54:53
UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing...

Lire la suite »

USN-8603-1: Linux kernel (Azure) vulnerabilities

2026-07-24 09:51:53
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

Code, Skins, and Cash: The Most Trusted CS2 Skin Swap Sites Checked for 2026

2026-07-24 09:47:17
Compare the best CS2 skin trading platforms in 2026. Learn how automated trading, Steam API security, fees, and bot inventories affect safer skin swaps.

Lire la suite »

JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity

2026-07-24 09:23:49
JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized actions in development...

Lire la suite »

Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data

2026-07-24 09:03:29
Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for one of Australia's largest...

Lire la suite »

L'Europe ne questionne plus sa dépendance à l'IA américaine, elle la subit…

2026-07-24 08:55:53
{ Tribune } - Une souveraineté technologique sans souveraineté des compétences équivaut à posséder une centrale nucléaire sans disposer d'ingénieurs pour la faire fonctionner. The post L’Europe...

Lire la suite »

Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code

2026-07-24 08:54:04
Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service...

Lire la suite »

The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating

2026-07-24 08:52:38
Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93%...

Lire la suite »

Debian LTS Imagemagick Critical Denial of Service Code Exec Vuln DLA-4696-1

2026-07-24 08:41:53
Debian issued an advisory for imagemagick, addressing multiple security vulnerabilities that could cause denial of service or arbitrary code execution; updates are available for Debian 11 and 12.

Lire la suite »

US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers

2026-07-24 08:31:42
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency...

Lire la suite »

Cross-Border Payments on Crypto Infrastructure: The 7 Billion Opportunity

2026-07-24 08:15:15
Explore how stablecoins and crypto super apps are reshaping the 7B remittance market with faster, cheaper cross-border payments.

Lire la suite »

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

2026-07-24 07:41:06
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review...

Lire la suite »

Clop ransomware targets Windchill, FlexPLM in data theft attacks

2026-07-24 07:36:39
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]

Lire la suite »

Zoomex X Space Recap With Fernando Llorente and The World Cup Final Panel

2026-07-24 07:20:51
The session also marked the conclusion of the five-part charity initiative that accompanied every

Lire la suite »

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

2026-07-24 07:10:55
Dolphin X is an AI-powered Windows stealer and RAT that targets 300+ apps, crypto wallets, SSH keys and cloud credentials while ranking victims by value.

Lire la suite »

The Database That Forgets on Purpose: Reviving Pinba, a 15-Year-Old MySQL Monitoring Engine

2026-07-24 07:00:08
Part 1 of a three-part series on Pinba — a free, self-hosted, real-time monitoring stack for PHP and web applications. Part 2 covers the PHP extension

Lire la suite »

Europe's Multilingual Reality Exposes AI Security Gaps

2026-07-24 07:00:00
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.

Lire la suite »

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

2026-07-24 06:58:27
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains...

Lire la suite »

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

2026-07-24 06:50:57
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The...

Lire la suite »

Nobody Needs an AI That Writes Tests. We Need One That Reads Failures.

2026-07-24 06:38:16
Everyone is building AI that writes tests. The real opportunity is AI that reads failures, automates triage, and learns from every diagnosis.

Lire la suite »

The Strategic Shift: Moving from a Reporting System to a Decision System

2026-07-24 06:37:31
Business Intelligence success is traditionally measured by technical inputs like dashboard counts and data velocity, but the true product of any BI initiative i

Lire la suite »

Mageia 10 - Xonotic Bugfix Advisory for the Year 2026-0063

2026-07-24 03:58:53
Mageia 10 has released updated Xonotic packages to address issues with broken online statistics support, as detailed in the bug report.

Lire la suite »

List of 39 new domains

2026-07-24 00:00:00
.fr accounts-electrodepot[.fr] (registrar: GANDI) adomiassistance[.fr] (registrar: GRANSY s.r.o.) ariatfrance[.fr] (registrar: GRANSY s.r.o.) casino-en-ligne-sans-verification[.fr] (registrar: EURODNS...

Lire la suite »

Multiples vulnérabilités dans MongoDB (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans MongoDB. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, un déni de service et un problème de...

Lire la suite »

Vulnérabilité dans NetApp ONTAP 9 (24 juillet 2026)

24/07/2026
Une vulnérabilité a été découverte dans NetApp ONTAP 9. Elle permet à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte...

Lire la suite »

Multiples vulnérabilités dans Microsoft Edge (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Lire la suite »

Multiples vulnérabilités dans Google Chrome (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Lire la suite »

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Debian LTS (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...

Lire la suite »

Multiples vulnérabilités dans le noyau Linux de Debian (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des...

Lire la suite »

Vulnérabilité dans les produits Moxa (24 juillet 2026)

24/07/2026
Une vulnérabilité a été découverte dans les produits Moxa. Elle permet à un attaquant de provoquer une élévation de privilèges.

Lire la suite »

Multiples vulnérabilités dans les produits ESET (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges.

Lire la suite »

Multiples vulnérabilités dans les produits IBM (24 juillet 2026)

24/07/2026
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...

Lire la suite »