Toute l'actualité de la Cybersécurité


Data analyst sent to prison for stealing data, extorting employer

2026-08-14 08:27:18
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a .5 million extortion scheme. [...]

Lire la suite »

Meet Huntress at International Cyber Expo 2026

2026-08-14 08:26:07
Huntress will be heading to International Cyber Expo 2026, where visitors can meet the team on Stand K94 and discover how the company is helping organisations tackle increasingly complex cyber threats...

Lire la suite »

24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services

2026-08-14 08:11:22
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows that customers can now buy payload obfuscation,...

Lire la suite »

New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL

2026-08-14 08:11:19
Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows Protected Process Light (PPL) protections,...

Lire la suite »

GeoServer 0-Day Vulnerability Enables Remote Code Execution Attacks

2026-08-14 07:50:12
A newly disclosed zero-day vulnerability in GeoServer is being targeted by attackers, raising concern for organizations that publish or manage geospatial data through internet-facing deployments. The...

Lire la suite »

OpenAI Unveils Ultrafast Mode in GPT‑5.6 Sol That Works 14× Faster Than Standard Mode

2026-08-14 07:47:13
OpenAI has introduced Ultrafast, a new service tier for GPT-5.6 Sol that it says can run up to 14× faster than Standard processing. The feature launches first via the OpenAI API and is currently available...

Lire la suite »

New DRAM Scrambling Attack Unlocks AMD CPU PSP, SMM and Microcode

2026-08-14 07:43:54
Security researcher Christopher Domas has released a proof-of-concept project called “skitter-creek-bath-salts,” which demonstrates a vulnerability in AMD’s DRAM-controller configuration that...

Lire la suite »

Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2

2026-08-14 07:33:42
Aeternum is a new botnet loader designed to resist takedowns. It stores instructions on Polygon, a public blockchain, creating a widely replicated control channel that is difficult to remove. The malware...

Lire la suite »

Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attacks

2026-08-14 07:27:48
Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of government-grade mercenary spyware. These notifications...

Lire la suite »

Download More RAM Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing

2026-08-14 07:19:42
A new attack dubbed “Download More RAM” can bypass Windows Virtualization-Based Security (VBS), weaken Hypervisor-Enforced Code Integrity (HVCI), and disable Microsoft Defender. Microsoft tracked...

Lire la suite »

US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks

2026-08-14 07:14:57
Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump signed a national security memorandum on August...

Lire la suite »

PATCHCORD Infrastructure Hosts SuperShell C2 for Remote Commands and Webshell Management

2026-08-14 06:59:27
A newly uncovered espionage operation targeting Afghan telecom providers and South Asian critical infrastructure has exposed a layered attacker ecosystem built around custom implants, spoofed delivery...

Lire la suite »

Alerte rouge sur l'iPhone : Apple prévient des centaines d'utilisateurs d'une opération espionnage

2026-08-14 06:26:38
Apple a de nouveau alerté ses utilisateurs d'iPhone, d'iPad et de Mac d'une cyberattaque sophistiquée. Une nouvelle salve de notifications urgentes a été envoyée à des personnes réparties dans...

Lire la suite »

Hackers Steal One AI Key, Resell the Compute, and Leave Victims With a Million-Dollar Bill

2026-08-14 06:22:27
A rapidly expanding financial cybercrime model called AI token jacking, where threat actors steal developer API keys for popular AI platforms, consume the victim's allocated model capacity, and resell...

Lire la suite »

Près de 300 extensions Chrome se font passer pour des VPN populaires

2026-08-14 06:01:01
Des centaines de faux VPN squattent le Chrome Web Store en singeant les grands noms du secteur, et votre trafic part faire un détour que vous n'avez jamais demandé. Le grand ménage de Google attendra....

Lire la suite »

The Endpoint-to-Cloud Privilege Security Checklist: 21 Controls to Eliminate Standing Access

2026-08-14 05:55:08
PAM secured the endpoint; privilege moved on. Work through these 21 controls to find out where standing access is accumulating in your cloud, SaaS, and AI estate — and how to shut it down without slowing...

Lire la suite »

Fortinet FortiWeb and FortiClient Flaws Let Unauthenticated Attackers Gain Access and Execute Arbitrary Code

2026-08-14 05:54:40
Fortinet has released security updates to address high-severity vulnerabilities in FortiWeb and FortiClient for Windows. These vulnerabilities could allow unauthenticated attackers to access appliance...

Lire la suite »

Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can't Erase Them

2026-08-14 05:38:30
A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to distribute botnet instructions without relying...

Lire la suite »

Trezor Shipping Provider Data Breach Exposes Personal Data of 13,689 Customers

2026-08-14 05:37:32
Hardware wallet manufacturer Trezor has recently disclosed a data breach at ShipMonk, a third-party shipping provider. This breach exposed the personal information of 13,689 customers. Importantly, Trezor’s...

Lire la suite »

Beacon CRM Data Breach Exposes Customer Data via Compromised AWS Access Key

2026-08-14 05:23:05
Beacon CRM has confirmed that a threat actor likely downloaded a complete copy of its customer database after gaining access to its Amazon Web Services (AWS) environment using a compromised AWS access...

Lire la suite »

10 Best Secure Web Gateway Vendors In 2026

2026-08-14 03:44:33
A secure web gateway inspects outbound web traffic blocking malicious sites, enforcing acceptable-use policy, decrypting TLS, and stopping malware before it reaches a browser. Zscaler leads on scale and...

Lire la suite »

Top 10 Best Microsegmentation Tools in 2026

2026-08-14 03:35:23
Microsegmentation tools stop attackers from moving sideways. Once ransomware operators land on one machine, everything that follows credential harvesting, domain escalation, mass encryption depends on...

Lire la suite »

New DRAM Scrambling Attack Exposes CPU's Most Protected Memory Zones

2026-08-14 03:26:34
A new attack technique that manipulates a computer’s memory controller to bypass some of the strongest hardware security boundaries built into modern processors, including protections around System...

Lire la suite »

Apple Urges Mercenary Spyware Targets to Enable Lockdown Mode Immediately

2026-08-14 02:05:01
Apple has quietly rolled out a new wave of high-confidence “Apple Threat Notification” alerts, warning selected iPhone users in 110 countries that their devices may be targeted by government-grade...

Lire la suite »

Apple sends new ‘Threat Notification' alerts over mercenary spyware attacks

2026-08-14 01:19:12
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]

Lire la suite »