Toute l'actualité de la Cybersécurité


Aftercall ads are driving Android users crazy

2026-07-27 19:00:05
A newly uncovered ad fraud campaign is spreading Android apps that display full-screen ads every time you end a phone call.

Lire la suite »

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

2026-07-27 18:10:05
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The...

Lire la suite »

MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data

2026-07-27 17:53:10
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate...

Lire la suite »

Adversaries Don't Need a Zero-Day — They Read Your Rulebook

2026-07-27 17:31:18
Confidence in autonomous security tools is declining, and here's why.

Lire la suite »

Apple sued over fake App Store crypto wallet app stealing .8M in Bitcoin

2026-07-27 17:29:07
Apple is being sued by three people who claim approximately .8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]

Lire la suite »

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

2026-07-27 17:16:28
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid...

Lire la suite »

Ubuntu FreeIPMI Critical Buffer Overflow Denial of Service Advisory 8613-1

2026-07-27 17:13:33
Ubuntu issued a security notice for FreeIPMI vulnerabilities affecting various LTS versions, detailing potential denial of service risks from buffer overflow issues and recommending updates.

Lire la suite »

Microsoft Defender for Endpoint Update Leaves Few Linux Servers Unprotected After Reboot

2026-07-27 17:10:39
A recent Microsoft Defender for Endpoint update briefly disabled antivirus protection on Linux servers following an upgrade and reboot, exposing affected machines to threats before Microsoft rolled out...

Lire la suite »

SUSE glib2 Important Out-of-Bounds Errors Advisory 2026-3235-1

2026-07-27 17:08:42
A security update for glib2 addresses six vulnerabilities, enhancing the security of various SUSE products and improving protection against potential out-of-bounds access and overflow issues.

Lire la suite »

SUSE glib2 Important Issues Resolved July 2026 Advisory 2026-3236-1

2026-07-27 17:07:52
SUSE announced a security update for glib2 addressing six vulnerabilities, including out-of-bounds reads and integer overflows, affecting various SUSE Linux Enterprise Server 12 SP5 products.

Lire la suite »

SUSE 12 SP5 vim Important Code Execution and Out-of-Bounds Fix 2026-3237-1

2026-07-27 17:07:06
SUSE announced a security update for vim addressing three vulnerabilities, enabling the installation of version 9.2.0780 to mitigate risks including arbitrary code execution and out-of-bounds writes.

Lire la suite »

SUSE python-pyasn1 Important Denial of Service Vuln 2026-3238-1

2026-07-27 17:06:07
A security update for python-pyasn1 addresses three vulnerabilities in various SUSE products, improving stability and security by mitigating denial of service risks and resource consumption issues.

Lire la suite »

SUSE Python-Soupsieve Security Update for Memory Exhaustion Issues

2026-07-27 17:05:26
SUSE has announced a security update for python-soupsieve addressing two vulnerabilities, CVE-2026-49476 and CVE-2026-49477, with installation instructions provided for affected products.

Lire la suite »

SUSE Python-Soupsieve Important Memory Exhaustion ReDoS Update 2026-3240-1

2026-07-27 17:04:26
A security update for python-soupsieve addresses two vulnerabilities related to memory exhaustion and denial of service, impacting several SUSE Linux products.

Lire la suite »

SUSE gzip Important Insecure File Handling Vuln 2026-3241-1

2026-07-27 17:03:45
A security update for gzip addressing CVE-2026-41991, involving insecure temporary file handling, is available for several SUSE Linux Enterprise products. Recommended installation methods are provided....

Lire la suite »

Un ancien député-maire ciblé sur un forum pirate

2026-07-27 17:01:50
Un ancien député-maire est ciblé par un pirate opposé à Chat Control, avec la republication annoncée de données trés intimes.

Lire la suite »

Daylight Security Launches Detection Program Visibility

2026-07-27 16:40:31
Daylight Security adds Detection Program Visibility to unify detections, map coverage to MITRE ATT&CK, and help MDR customers spot gaps and improve results.

Lire la suite »

Rethinking security for the age of AI

2026-07-27 16:40:00
Why security needs a new Cyber Stack — Introducing Project Perception The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At...

Lire la suite »

Enhancing AI security through global AI red teaming

2026-07-27 16:25:00
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts,...

Lire la suite »

openSUSE Chromium Important Four Issues Fix Advisory 2026-0264-1

2026-07-27 16:04:43
openSUSE has released a security update for chromium addressing four vulnerabilities, including out of bounds write and use after free issues, applicable to Backports SLE-15-SP7.

Lire la suite »

Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely

2026-07-27 15:49:36
vBulletin has patched CVE-2026-61511, a critical remote code execution flaw that could let unauthenticated attackers execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects...

Lire la suite »

Coca-Cola confirms data theft in Fairlife ransomware attack

2026-07-27 15:39:51
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]

Lire la suite »

openSUSE Tumbleweed mcphost Moderate Update for 2 Issues 2026-11366-1

2026-07-27 15:37:33
An update for mcphost-0.34.0-9.1 on openSUSE Tumbleweed addresses two security vulnerabilities with moderate ratings, allowing installation to enhance system security.

Lire la suite »

openSUSE Tumbleweed opennlp Medium CVE-2026-63317 Advisory 2026-11369-1

2026-07-27 15:37:33
An openSUSE Tumbleweed update addresses a moderate vulnerability in the opennlp-1.9.5-2.1 package, including fixes for associated components and tools.

Lire la suite »

openSUSE Tumbleweed 2026-11364-1 Libknet-devel Moderate Risk Issues

2026-07-27 15:37:32
openSUSE Tumbleweed has released an update for the libknet-devel-1.33-2.1 package addressing three vulnerabilities, enhancing security within the software.

Lire la suite »

EY Data Breach Claimed by ShinyHunters Hacker Group

2026-07-27 15:35:21
The notorious ShinyHunters extortion gang has publicly claimed responsibility for the Ernst & Young (EY) data breach, alleging it stole employee credentials and sensitive files through a supply-chain...

Lire la suite »

GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates

2026-07-27 15:25:08
GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern...

Lire la suite »

How to Track AI Search Share of Voice and Brand Mentions

2026-07-27 15:21:04
Learn what AI Share of Voice is, the formula to calculate it, and how to track brand mentions across ChatGPT, Perplexity, and Google AI Overviews.

Lire la suite »

Ernst & Young data breach claimed by ShinyHunters extortion gang

2026-07-27 15:12:27
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack....

Lire la suite »

OpenAI-Hugging Face Incident: What We Know

2026-07-27 15:12:12
An experimental AI agent powered by OpenAI models has successfully compromised part of Hugging Face’s infrastructure during a controlled cybersecurity evaluation, offering a glimpse into the evolving...

Lire la suite »

Un « kill switch » pour l'IA ? Ce que projette le législateur américain

2026-07-27 15:08:10
Un « AI Kill Switch Act » bipartisan émerge aux États-Unis. Il va, dans sa forme, substantiellement plus loin que l'AI Act. The post Un « kill switch » pour l’IA ? Ce que projette le législateur...

Lire la suite »

A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC

2026-07-27 15:05:05
A new phishing operation, tracked as Operation BlueDash, is tricking users into installing a fake Microsoft Teams update that silently hands attackers not one but two independent ways to remotely control...

Lire la suite »

Sextortion scammers are exploiting ShinyHunters data leaks

2026-07-27 15:00:23
Scammers are posing as ShinyHunters and using leaked email addresses to make their sextortion emails seem more credible.

Lire la suite »

Meet Credyt: HackerNoon Company of the Week

2026-07-27 15:00:11
Credyt, the company offering real-time monetization for AI, is HackerNoon's company of the week.

Lire la suite »

Security Risk Advisors Named a Finalist in CRN's 2026 Best of the Channel Awards

2026-07-27 13:55:53
Philadelphia, Pennsylvania, 27th July 2026, CyberNewswire

Lire la suite »

Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

2026-07-27 14:43:57
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.

Lire la suite »

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

2026-07-27 14:40:00
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account,...

Lire la suite »

What’s your data worth on the dark web? (Lock and Code S07E15)

2026-07-27 14:35:34
This week on the Lock and Code podcast, we discuss just exactly why it is that hackers and scammers want your data—and how you're at risk.

Lire la suite »

USN-8613-1: FreeIPMI vulnerabilities

2026-07-27 14:28:55
Zhihan Zheng discovered that FreeIPMI had several buffer overflow vulnerabilities in ipmi-oem response message handling. A local attacker with control a malicious IPMI device or simulator could possibly...

Lire la suite »

NVIDIA Launches Open Secure AI Alliance to Build Open-Source Defenses for AI Agents

2026-07-27 14:26:59
A coalition of over 30 technology industry leaders, including NVIDIA, Microsoft, CrowdStrike, Cisco, IBM, Palo Alto Networks, and Red Hat, has launched the Open Secure AI Alliance. The initiative aims...

Lire la suite »

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

2026-07-27 14:10:54
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers...

Lire la suite »

Shadow AI agents are multiplying. Here's how to find and secure them.

2026-07-27 14:01:11
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before...

Lire la suite »

The TechBeat: AI Coding Tip 028 - Wire a Skill Into Your Company's Live Systems (7/27/2026)

2026-07-27 14:00:56
7/27/2026: Trending stories on Hackernoon today!

Lire la suite »

62 Blog Posts To Learn About Docker Compose

2026-07-27 14:00:14
Learn everything you need to know about Docker Compose via these 62 free HackerNoon blog posts.

Lire la suite »

Open Secure AI Alliance : Nvidia veut fédérer le standard de sécurité de l'IA

2026-07-27 13:57:14
À l'initiative de Nvidia, plus de 35 entreprises technologiques lancent l'Open Secure AI Alliance (OSAA) destinée à développer des outils ouverts de sécurisation de l'IA. The post Open Secure...

Lire la suite »

NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security

2026-07-27 13:57:12
NVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing...

Lire la suite »

The CISO's Dilemma: Preparing for Post Quantum Migration While Securing Gasless Transactions

2026-07-27 13:46:52
A practical security playbook connecting post-quantum migration, crypto agility, gasless transactions, and trust-boundary management.

Lire la suite »

Hackers Can Use MedusaHVNC to Control Your PC on a Desktop You Cannot See

2026-07-27 13:34:37
A newly discovered remote access Trojan called MedusaHVNC lets attackers open a hidden virtual desktop on a victim’s own computer, quietly loading their real browser profile, cookies, and logged-in...

Lire la suite »

Après la « première cyberattaque » menée par l'IA, la victime demande des comptes à OpenAI

2026-07-27 13:29:17
Deux modèles d'OpenAI se sont échappés et se sont lancés à l'assaut de Hugging Face, la célèbre plateforme d'IA open source. Le PDG de Hugging Face, Clem Delangue, exige désormais une « transparence...

Lire la suite »

SAP's 2027 Deadline Is Revealing a Bigger Enterprise Security Problem

2026-07-27 13:17:24
Why SAP's 2027 support deadline should prompt enterprises to treat vendor dependency as a security and resilience risk.

Lire la suite »

Vatican's Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw

2026-07-27 13:12:56
The Vatican's official Click to Pray app has exposed the personal information of more than 700,000 users through an unauthenticated API flaw. The issue allowed anyone with a web browser to retrieve...

Lire la suite »

DentaQuest disclosed a data breach that impacted +23 million individuals

2026-07-27 13:05:49
DentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach...

Lire la suite »

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

2026-07-27 13:05:15
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes...

Lire la suite »

Wrench Attacks Bypass Encryption by Forcing Victims to Unlock Crypto Wallets

2026-07-27 12:53:57
Cryptocurrency theft is increasingly moving beyond the screen. Criminals are using violence, threats, home invasions, and kidnapping attempts to force victims to unlock wallets or approve transfers while...

Lire la suite »

Intelligent Deep Learning for Smarter Phishing Detection in Modern Web Platforms

2026-07-27 12:52:52
Discover how hybrid CNN-LSTM deep learning models improve phishing detection accuracy using URL feature engineering, PhishTank data, and AI-driven analysis.

Lire la suite »

How a 67-Year-Old Woman Went From Romance Scam Victim To Podcast Rebel

2026-07-27 12:50:31
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn,...

Lire la suite »

Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts

2026-07-27 12:49:02
A critical access control vulnerability in the Vatican's official “Click to Pray” platform has exposed the personal data of more than 700,000 users, highlighting once again how basic web security...

Lire la suite »

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

2026-07-27 12:37:49
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim...

Lire la suite »

Claude Cowork pouvait fouiller tout votre Mac sans jamais demander la moindre permission

2026-07-27 12:37:22
Un dossier connecté, un message envoyé, et l'agent d'Anthropic s'est promené dans l'intégralité du disque. Aucune fenêtre d'autorisation, aucune alerte.

Lire la suite »

USN-8612-1: Roc Toolkit vulnerability

2026-07-27 12:33:35
It was discovered that Roc Toolkit incorrectly handled WAV files with a malformed "smpl" chunk. An attacker could use this issue to cause Roc Toolkit to crash, resulting in a denial of service, or possibly...

Lire la suite »

USN-8611-1: GNU C Library vulnerabilities

2026-07-27 12:24:25
It was discovered that the GNU C Library iconv function incorrectly handled certain IBM character sets. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-4046) It was...

Lire la suite »

How to Build a Private Microsoft Teams Clone

2026-07-27 12:24:01
A step-by-step guide to building an on-premises Microsoft Teams alternative with messaging, calls, meetings, and file sharing.

Lire la suite »

Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation

2026-07-27 12:22:12
Claude Opus 5, the latest flagship AI model from Anthropic, represents a significant shift in how advanced systems can be safely utilized in cybersecurity. This model can proactively identify software...

Lire la suite »

How to Design a Human-in-the-Loop AI Agent for Follow-Up Workflows

2026-07-27 12:13:10
Learn how to design a human-in-the-loop AI agent for follow-up workflows using triggers, CRM data, approval gates, and escalation rules.

Lire la suite »

Europol Launches Project COMPASS to Disrupt ‘The Com' Cybercrime Network Targeting Minors

2026-07-27 11:36:17
Europol has launched Project COMPASS, a coordinated transnational initiative aimed at disrupting “The Com,” a highly dangerous cybercrime and nihilistic extremist network that systematically...

Lire la suite »

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain

2026-07-27 11:20:35
Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution...

Lire la suite »

EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency

2026-07-27 11:16:54
EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that's...

Lire la suite »

Insight Partners And Glilot Capital Lead M Investment in Way Security

2026-07-27 11:13:17
The million investment reflects the belief from Insight Partners and Glilot Capital that this execution gap represents a significant market opportunity.

Lire la suite »

vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution

2026-07-27 11:11:46
A critical pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511, could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable forum servers....

Lire la suite »

Insight Partners and Glilot Capital Co-Lead M Investment in Way Security

2026-07-27 11:10:38
Way Security raises M from Insight Partners and Glilot Capital to automate costly IAM operations with AI and help enterprises get more from existing tools.

Lire la suite »

Airbus mise sur SAP Sovereign Cloud

2026-07-27 11:07:34
Airbus franchit une étape de plus dans la stratégie du groupe pour garder la main sur ses données les plus sensibles, de la conception des aéronefs à sa production. The post Airbus mise sur SAP Sovereign...

Lire la suite »

Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware

2026-07-27 10:59:58
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in...

Lire la suite »

Google Indexed Claude AI Shared Chats Before Results Were Removed

2026-07-27 10:56:48
Google Search indexed public Claude AI chat links, letting people find shared conversations through the site query before those listings disappeared soon after.

Lire la suite »

Les planètes s'alignent pour les modèles d'IA open-weight

2026-07-27 10:53:15
La tech US s'est massivement ralliée en faveur des modèles à poids ouverts, dans un contexte qui incite Washington à y restreindre l'accès. The post Les planètes s’alignent pour les modèles...

Lire la suite »

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

2026-07-27 10:51:45
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated...

Lire la suite »

GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies

2026-07-27 10:37:10
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as...

Lire la suite »

Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks

2026-07-27 10:05:58
Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,” marking a shift from purely digital exploitation...

Lire la suite »

My eJPTv2 Journey — 82%

2026-07-27 09:39:44
My eJPTv2 Journey — 82%Ever since I was in 11th standard, I've been deeply curious about computers — how they work, how systems connect, and yes, how they can be cracked (ethically, of course)....

Lire la suite »

Unauthenticated Disclosure of A/B Test Data in Convert Pro — How Two Forgotten AJAX Endpoints…

2026-07-27 09:38:59
Unauthenticated Disclosure of A/B Test Data in Convert Pro — How Two Forgotten AJAX Endpoints Leaked Every Split-Test on a SiteAuthor: Shikhali Jamalzade GitHub: alisalive LinkedIn: camalzadsThis...

Lire la suite »

One Header Away from 10+ GB of Customer Documents (PII) — K Bounty

2026-07-27 09:38:35
Sample Document LeakedAn anonymous attacker could fully enumerate, read, and overwrite the production customer-service attachment bucket of a major insurer's China operation.The bucket backs the file-upload...

Lire la suite »

Plus de 4000 URL à supprimer : la police européenne s'attaque à nouveau aux pirates sans scrupule de « The Com »

2026-07-27 09:38:07
Les polices de neuf pays d'Europe ont mené une opération coordonnée contre « The Com », un réseau extrémiste décentralisé qui recrute et manipule des mineurs en ligne. Au terme de l'opération,...

Lire la suite »

How I Found a Bug Worth ,500 — In a Feature Nobody Was Watching.

2026-07-27 09:37:44
A storage-exhaustion flaw. A stored XSS that waited for an admin. Both hiding in the same “boring” file upload form that hadn't been touched in years.What happens when nobody stress-tests the upload...

Lire la suite »

Unprotected admin functionality with unpredictable URL — PortSwigger Access Control Lab 2

2026-07-27 09:36:25
Unprotected admin functionality with unpredictable URL — PortSwigger Access Control Lab 2Finding ID: BAC-Portswigger-002Title: Unprotected admin functionality with unpredictable URLRisk (Severity):...

Lire la suite »

LetsDefend: SOC169 — Possible IDOR Attack Detected (Walkthrough)

2026-07-27 09:36:11
Investigating an IDOR Vullneron a WebServerAlert Overview|--------------------|----------------------------------------|| Alert Name | SOC169 - Possible IDOR Attack Detected || Event ID ...

Lire la suite »

LetsDefend Challenge: Memory Analysis (Walkthrough)

2026-07-27 09:36:05
Analysing Memory Dump extracted from a compromised Windows HostScenarioA Windows Endpoint was recently compromised. Thanks to our cutting-edge EDR/IDS solution we immediately noticed it. The alert was...

Lire la suite »

VulnNet: Roasted Tryhackme ctf walkthrough

2026-07-27 09:31:45
VulnNet: Roasted | Tryhackme walkthroughVulnNet Entertainment just deployed a new instance on their network with the newly-hired system administrators. Being a security-aware company, they as always hired...

Lire la suite »

Pickle Rick Tryhackme CTF

2026-07-27 09:31:38
This Rick and Morty-themed challenge requires you to exploit a web server and find three ingredients to help Rick make his potion and transform himself back into a human from a pickle.Pickle RickReconnaissanceStarted...

Lire la suite »

Tryhackme New Room — FLIP

2026-07-27 09:30:14
Tryhackme Room — FLIP | by Sahil MalviHere's a link to the room: https://tryhackme.com/room/flipTASK [1] Source CodeFirst, go ahead and review the source code before moving on to Task 2.You...

Lire la suite »

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

2026-07-27 08:48:47
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment...

Lire la suite »

Sasi Kumar Kolla Examines Multimodal Foundation Models for Precision Medicine Research

2026-07-27 08:45:19
Sasi Kumar Kolla examines how multimodal foundation models can integrate genomics, imaging, and clinical data to advance precision medicine research.

Lire la suite »

Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure

2026-07-27 08:39:40
Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation,...

Lire la suite »

The AI Resistance: Engineers vs The Machines

2026-07-27 08:15:35
Explore the debate around GitHub Copilot, AI-assisted development, trust, productivity, and the future of software engineering.

Lire la suite »

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

2026-07-27 08:01:23
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option...

Lire la suite »

A week in security (July 20 – July 26)

2026-07-27 07:01:00
A list of topics we covered in the week of July 20 to July 26 of 2026

Lire la suite »

LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations

2026-07-27 06:00:34
A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one...

Lire la suite »

List of 7 new domains

2026-07-27 00:00:00
.fr contact-electrodepot[.fr] (registrar: GANDI) golden-gooses[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) salomonfrancesoldes[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) serviceclientbuylive[.fr]...

Lire la suite »

Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026)

27/07/2026
De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...

Lire la suite »

Multiples vulnérabilités dans GLPI (27 juillet 2026)

27/07/2026
De multiples vulnérabilités ont été découvertes dans GLPI. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à l'intégrité des données...

Lire la suite »

Vulnérabilité dans Traefik (27 juillet 2026)

27/07/2026
Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Lire la suite »

Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026)

27/07/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, un contournement de la politique...

Lire la suite »