Toute l'actualité de la Cybersécurité
Hermes AI agent used to automate attack on Thai Finance Ministry
2026-07-24 19:09:09
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
2026-07-24 17:50:37
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
2026-07-24 11:15:33
Tel Aviv, Israel, 24th July 2026, CyberNewswire
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain
2026-07-24 16:35:58
A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active...
Cyber actualités ZATAZ de la semaine du 20 au 26 juillet 2026
2026-07-24 16:08:00
Bonjour à toutes et tous, Cette semaine, l'actualité cyber se concentre sur l'automatisation de l'extorsion, les fuites revendiquées et la pression exercée sur les organisations. Titan promet...
HackerNoon Projects of the Week: RecallNote , ACHLS Eternal, Rivver Accountant
2026-07-24 16:00:06
Three startups—RecallNote , ACHLS Eternal, and Rivver Accountant—featured in HackerNoon Projects of the Week for proving real-world usefulness.
Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers
2026-07-24 15:56:46
Three critical remote code execution (RCE) vulnerabilities in Microsoft’s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing...
Deux jeux d'été pour vérifier et déchiffrer
2026-07-24 15:47:00
Deux jeux d'été mêlent fact-checking, détection IA et chiffrement pour entraîner l'esprit critique en famille.
Microsoft blames massive Microsoft 365 outage on maintenance bug
2026-07-24 15:41:44
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft...
Quatre rendez-vous cyber à suivre jusqu'en octobre
2026-07-24 15:15:20
Barbhack, DEF CON, Cyberbrew et Hackfest rythment la rentrée cyber, de Toulon à Québec, en passant par Lille.
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
2026-07-24 15:12:35
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing...
World Foundation Raises .5 Million to Scale Proof of Human as AI Transforms the Internet
2026-07-24 15:01:30
World Foundation raised .5 million in a Pantera-led locked WLD sale on its third anniversary. Inside the Vercel, Okta, and Tinder distribution thesis.
Don’t get fooled by TikTok resin art scams
2026-07-24 14:56:34
Scammers are using stolen videos and fake artist profiles to trick people into buying resin art that never arrives. Here's how to spot the warning signs.
Call of Duty Mobile scam uses fake free points to steal player accounts
2026-07-24 14:54:23
A phishing site posing as a free Call of Duty Points giveaway is stealing Activision logins and two-factor authentication codes.
OpenAI’s agent escaped its sandbox during a security test
2026-07-24 14:51:45
An OpenAI agent escaped its sandbox, stole credentials, and broke into Hugging Face. Here's what that actually means.
Titan automatise le chantage aux données
2026-07-24 14:37:58
Titan promet d'automatiser l'analyse des fuites, le calcul des rançons et la pression réglementaire.
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
2026-07-24 14:15:21
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
They...
Chick-fil-A data breach affects more than 13,000 customers
2026-07-24 14:04:29
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
2026-07-24 14:01:11
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how...
The TechBeat: Apple v. OpenAI Trade Secrets Lawsuit: The 42 Most Explosive Allegations & The Internet's Reactions (7/24/2026)
2026-07-24 14:00:51
7/24/2026: Trending stories on Hackernoon today!
314 Blog Posts To Learn About Developer Tools
2026-07-24 14:00:12
Learn everything you need to know about Developer Tools via these 314 free HackerNoon blog posts.
Meet the Writer: Hacker Noon's Contributor Prakshal Doshi, Site Reliability Engineer
2026-07-24 13:45:08
SRE at Apple writing about AI infrastructure, Kubernetes, and cloud reliability.Real production experience. Building tools & community at AI/DevOps intersection
Google wants to store a selfie video of your face
2026-07-24 13:41:45
A new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.
Un faux portail FPR pour piéger des pirates
2026-07-24 13:19:22
Un faux portail FPR imitait la Police nationale pour enregistrer les recherches et identités de pirates.
Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot
2026-07-24 13:17:47
Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts often think that requests accepted by a higher...
Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading
2026-07-24 13:15:56
A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239,...
AMD entre vraiment dans le jeu des racks IA exascale
2026-07-24 13:08:19
AMD intègre ses nouvelles générations de CPU (EPYC Venice) et de GPU (Instinct MI455X) dans des racks Helios AI qui atteignent l'exaflops en inférence FP8.
The post AMD entre vraiment dans le jeu...
Cl0p Hackers Exploit Windchill Servers to Steal Companies' Secret Product Designs
2026-07-24 13:05:36
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data. The campaign combines software flaws to gain access without credentials,...
openSUSE Advisory 2026-0259-1 gh Important Punycode Fix CVE-2026-39821
2026-07-24 13:04:49
openSUSE released a security update for the gh package to address CVE-2026-39821, which involves rejecting certain Punycode labels in the idna package, rated important.
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
2026-07-24 13:04:41
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation...
Frontier AI and the Vulnerability Gap in OT
2026-07-24 13:00:34
The landscape of cyber defense and offense is shifting beneath our feet. Over the past few weeks, the release of “frontier” AI models has accelerated the arms race, forcing a...
The post Frontier...
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
2026-07-24 13:00:00
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.
Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos
2026-07-24 12:57:50
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors...
Europol flags 4,340 URLs for removal in 'The Com' crackdown
2026-07-24 12:56:53
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]
KnowBe4's Unveils Custom AI Video Builder
2026-07-24 12:52:53
KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of Custom AI Video Builder, a new capability that lets security admins create custom,...
L'incident OpenAI–Hugging Face n'est pas la révolution que vous imaginez
2026-07-24 12:52:45
{ Tribune Expert } - Ce que démontre l'incident Hugging Face, ce n'est pas une sophistication supérieure, mais une orchestration infatigable : un opérateur capable d'enchaîner une douzaine d'étapes...
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
2026-07-24 12:48:16
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and...
openSUSE Avahi Moderate DoS CVE-2025-59529 Advisory 2026-3217-1
2026-07-24 12:33:33
SUSE has released a security update for avahi to address CVE-2025-59529, which allows local denial of service due to a client limit issue in the protocol server.
openSUSE avahi Moderate Denial of Service Fix 2026-3218-1
2026-07-24 12:33:26
SUSE released a security update addressing CVE-2025-59529, which causes a local denial of service in avahi. Users are advised to update using recommended installation methods.
openSUSE ImageMagick Important Security Fix for Multiple Flaws 2026-3219-1
2026-07-24 12:33:19
SUSE has released an important security update for ImageMagick, addressing 25 vulnerabilities and providing a fix for significant bugs affecting openSUSE Leap and SUSE Linux Enterprise Server.
openSUSE nmap Moderate Out-of-Bounds Crash Vulnern 2026-3220-1
2026-07-24 12:32:27
SUSE released a security update for nmap addressing CVE-2026-58058, which resolves a vulnerability that can lead to out-of-bounds reads and crashes in openSUSE Leap 15.4.
openSUSE 2026-3224-1 SVT-AV1 Important Remote Code Execution Fix
2026-07-24 12:32:00
A security update addressing four vulnerabilities in SVT-AV1, libyuv0, and libaom3 has been released, affecting several SUSE Linux products; installation instructions are provided.
B9 : 36 000 profils bancaires annoncés piratés
2026-07-24 12:20:18
B9 fait l'objet d'une fuite présumée de 36 000 profils, illustrant les risques cyber des banques 100 % en ligne.
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
2026-07-24 12:10:28
Hunt.io uncovered a cyber-espionage attack on Thailand's Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion...
Pokemon Gym : 19 600 comptes exposés
2026-07-24 12:01:24
Fuite Pokemon Gym : 19 600 comptes de joueurs et joueuses, adresses IP et messages privés exposés.
New CISA/NSA Advisory Spotlights Russian Attacks on Zimbra Webmail
2026-07-24 12:00:17
Overview of the Advisory On July 23, 2026, CISA, the NSA, the FBI, and their international partners issued a joint cybersecurity advisory alerting organizations to ongoing Russian state-sponsored activity....
Beyond the Play Store: How Android threats really spread
2026-07-24 12:00:00
Some threats never pass through the Play Store. Others arrive later in seemingly legitimate updates. Here's how Malwarebytes detects both.
Apache Syncope Release Patches for Multiple RCE and SQL Injection Vulnerabilities
2026-07-24 11:58:13
Apache has issued critical security updates for its Syncope identity and access management (IAM) platform to address multiple vulnerabilities, including remote code execution (RCE), SQL injection, privilege...
JetBrains Fixes Critical IntelliJ IDEA Code Execution Flaw and Four TeamCity Vulnerabilities
2026-07-24 11:58:10
JetBrains has released security updates to address a critical code execution vulnerability in IntelliJ IDEA, alongside four high-severity vulnerabilities in TeamCity. Development teams and CI administrators...
SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files
2026-07-24 11:58:00
SectopRAT is at the center of a highly targeted malvertising campaign abusing Anthropic's Claude platform to deliver a stealthy, HVNC‑enabled RAT that gives attackers deep, persistent access to victims'...
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
2026-07-24 11:54:18
A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software...
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
2026-07-24 11:53:55
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous...
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
2026-07-24 11:45:17
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet.
XBOW's testing...
Examining the Unintended Consequences of the Online Safety Act
2026-07-24 11:43:38
The 25th July 2026 marks one year since the Online Safety Act’s landmark child safety duties came into force, making it a natural moment to assess what’s changed, what’s worked and what...
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
2026-07-24 11:30:00
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is...
ROCm.ai, ou comment AMD inculque sa stack aux LLM
2026-07-24 11:27:48
Avec ROCm.ai, AMD promet de la programmation GPU assistée par IA, au moyen de skills et d'un système agentique dit Hyperloom.
The post ROCm.ai, ou comment AMD inculque sa stack aux LLM appeared first...
ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims
2026-07-24 11:26:58
ChonkyChicken is a newly identified remote access trojan designed to turn one infected Windows device into a platform for credential theft, network movement, and surveillance. The malware is part of the...
Microsoft Confirms No Bloatware Ads in Windows 11; LG Disables McAfee Pop-ups
2026-07-24 11:26:34
Microsoft has moved quickly to shut down unwanted antivirus advertising after users discovered that connecting an LG monitor could silently install companion software and trigger a McAfee trial pop-up...
Man gets six years for hacking 750 women's Snapchat accounts
2026-07-24 11:17:19
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]
SourTrade Malvertising Builds Unique Malware Inside Victims' Browsers to Evade Detection
2026-07-24 11:09:16
SourTrade is a long-running malvertising operation that uses fake ads to lure cryptocurrency users toward convincing copies of trading and exchange platforms. The campaign has been active since late 2024...
Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks
2026-07-24 11:04:51
Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
2026-07-24 10:53:38
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation...
Le mouvement vers le cloud va-t-il s'inverser avec l'IA ?
2026-07-24 10:52:37
{ Tribune Expert } - L'intelligence artificielle ne remet pas en cause le cloud. En revanche, elle remet clairement l'infrastructure au cœur des décisions stratégiques.
The post Le mouvement vers le...
Debian LTS DLA-4698-1 Spice-Vdagent Critical DoS Path Traversal
2026-07-24 10:39:31
Debian issued an advisory for spice-vdagent, addressing two vulnerabilities: an integer overflow leading to DoS and a path traversal allowing unauthorized file writes. Updates are recommended.
Motherless : les serveurs saisis au cœur de l'enquête
2026-07-24 10:34:57
La police saisit les serveurs du site pour adultes Motherless dans une enquête européenne sur des contenus vidéos criminels.
USN-8610-1: Linux kernel (Azure CVM) vulnerabilities
2026-07-24 10:34:35
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could...
USN-8575-3: Linux kernel vulnerabilities
2026-07-24 10:30:08
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could...
USN-8609-1: Linux kernel (Azure CVM) vulnerabilities
2026-07-24 10:26:03
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
USN-8608-1: Linux kernel (Azure FIPS) vulnerabilities
2026-07-24 10:23:19
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
Le Pentagone consolide ses licences logicielles Oracle
2026-07-24 10:21:06
Un contrat pouvant atteindre 7 milliards $ sur dix ans doit remplacer une mosaïque d'accords dispersés entre les armées, le renseignement et les gardes-côtes.
The post Le Pentagone consolide ses licences...
USN-8607-1: Linux kernel (Azure CVM) vulnerabilities
2026-07-24 10:20:29
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
USN-8606-1: Linux kernel (Azure) vulnerabilities
2026-07-24 10:17:16
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
2026-07-24 10:15:29
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which...
AI Hack : une fuite chez Darsa AI ?
2026-07-24 10:14:57
Un pirate revendique une fuite chez Darsa AI et multiplie les publications visant des acteurs liés à l'Intelligence Artificielle.
USN-8595-2: Linux kernel (AWS) vulnerabilities
2026-07-24 10:14:09
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
USN-8605-1: Linux kernel (Azure CVM) vulnerabilities
2026-07-24 10:11:06
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
...
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
2026-07-24 10:10:28
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry's reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade...
New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims
2026-07-24 10:09:52
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
2026-07-24 10:09:24
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite...
USN-8604-1: Linux kernel (Azure) vulnerabilities
2026-07-24 10:07:12
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
...
Ubuntu 26.04 LTS Linux Kernel Important Security Flaws USN-8603-1
2026-07-24 10:03:33
Ubuntu 26.04 LTS users are advised to update their kernel due to multiple vulnerabilities affecting AMD processors, including potential privilege escalation and sensitive data exposure.
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
2026-07-24 09:54:53
UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing...
USN-8603-1: Linux kernel (Azure) vulnerabilities
2026-07-24 09:51:53
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information....
Code, Skins, and Cash: The Most Trusted CS2 Skin Swap Sites Checked for 2026
2026-07-24 09:47:17
Compare the best CS2 skin trading platforms in 2026. Learn how automated trading, Steam API security, fees, and bot inventories affect safer skin swaps.
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity
2026-07-24 09:23:49
JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized actions in development...
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data
2026-07-24 09:03:29
Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for one of Australia's largest...
L'Europe ne questionne plus sa dépendance à l'IA américaine, elle la subit…
2026-07-24 08:55:53
{ Tribune } - Une souveraineté technologique sans souveraineté des compétences équivaut à posséder une centrale nucléaire sans disposer d'ingénieurs pour la faire fonctionner.
The post L’Europe...
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
2026-07-24 08:54:04
Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service...
The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating
2026-07-24 08:52:38
Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93%...
Debian LTS Imagemagick Critical Denial of Service Code Exec Vuln DLA-4696-1
2026-07-24 08:41:53
Debian issued an advisory for imagemagick, addressing multiple security vulnerabilities that could cause denial of service or arbitrary code execution; updates are available for Debian 11 and 12.
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
2026-07-24 08:31:42
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency...
Cross-Border Payments on Crypto Infrastructure: The 7 Billion Opportunity
2026-07-24 08:15:15
Explore how stablecoins and crypto super apps are reshaping the 7B remittance market with faster, cheaper cross-border payments.
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
2026-07-24 07:41:06
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review...
Clop ransomware targets Windchill, FlexPLM in data theft attacks
2026-07-24 07:36:39
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]
Zoomex X Space Recap With Fernando Llorente and The World Cup Final Panel
2026-07-24 07:20:51
The session also marked the conclusion of the five-part charity initiative that accompanied every
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
2026-07-24 07:10:55
Dolphin X is an AI-powered Windows stealer and RAT that targets 300+ apps, crypto wallets, SSH keys and cloud credentials while ranking victims by value.
The Database That Forgets on Purpose: Reviving Pinba, a 15-Year-Old MySQL Monitoring Engine
2026-07-24 07:00:08
Part 1 of a three-part series on Pinba — a free, self-hosted, real-time monitoring stack for PHP and web applications. Part 2 covers the PHP extension
Europe's Multilingual Reality Exposes AI Security Gaps
2026-07-24 07:00:00
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
2026-07-24 06:58:27
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
All four chains require RESTORE. The Streams chains...
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
2026-07-24 06:50:57
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems.
The...
Nobody Needs an AI That Writes Tests. We Need One That Reads Failures.
2026-07-24 06:38:16
Everyone is building AI that writes tests. The real opportunity is AI that reads failures, automates triage, and learns from every diagnosis.
The Strategic Shift: Moving from a Reporting System to a Decision System
2026-07-24 06:37:31
Business Intelligence success is traditionally measured by technical inputs like dashboard counts and data velocity, but the true product of any BI initiative i
Mageia 10 - Xonotic Bugfix Advisory for the Year 2026-0063
2026-07-24 03:58:53
Mageia 10 has released updated Xonotic packages to address issues with broken online statistics support, as detailed in the bug report.
List of 39 new domains
2026-07-24 00:00:00
.fr accounts-electrodepot[.fr] (registrar: GANDI)
adomiassistance[.fr] (registrar: GRANSY s.r.o.)
ariatfrance[.fr] (registrar: GRANSY s.r.o.)
casino-en-ligne-sans-verification[.fr] (registrar: EURODNS...
Multiples vulnérabilités dans MongoDB (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans MongoDB. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, un déni de service et un problème de...
Vulnérabilité dans NetApp ONTAP 9 (24 juillet 2026)
24/07/2026
Une vulnérabilité a été découverte dans NetApp ONTAP 9. Elle permet à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte...
Multiples vulnérabilités dans Microsoft Edge (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Multiples vulnérabilités dans Google Chrome (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une...
Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une...
Multiples vulnérabilités dans le noyau Linux de Debian LTS (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans le noyau Linux de Debian (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des...
Vulnérabilité dans les produits Moxa (24 juillet 2026)
24/07/2026
Une vulnérabilité a été découverte dans les produits Moxa. Elle permet à un attaquant de provoquer une élévation de privilèges.
Multiples vulnérabilités dans les produits ESET (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges.
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
24/07/2026
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...