Toute l'actualité de la Cybersécurité


Water sector example added to the NCSC's Secure connectivity principles

2026-08-11 12:00:00
New guidance is the first content authored by the Industrial Control System COI to appear on ncsc.gov.uk.

Lire la suite »

CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks

2026-08-11 09:48:45
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used...

Lire la suite »

US and South Korea warn of Gunra ransomware targeting govt agencies

2026-08-11 09:47:06
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]

Lire la suite »

DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns

2026-08-11 09:39:02
DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July 2025, it had listed more than 80 alleged victims...

Lire la suite »

LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines

2026-08-11 09:07:48
A LiteLLM compromise has raised concern over how a trusted AI software component can become an entry point into a network. The supply chain incident placed build systems, cloud accounts and source code...

Lire la suite »

Watch out for fake TikTok Shops trying to steal your money

2026-08-11 09:05:57
TikTok Shop is huge, so it's no wonder that impersonation shops have popped up. Here's how to stay safe.

Lire la suite »

Fake popular sites offer a free app, instead take over PCs

2026-08-11 08:55:45
Fake branded download pages are tricking Windows users into installing legitimate remote-access software that's being abused by attackers.

Lire la suite »

Steam : une fuite chez CEVA expose des clients européens

2026-08-11 08:45:37
Des clients Steam européens risquent désormais des campagnes de phishing très ciblées aprés le piratage d'un partenaire de Steam.

Lire la suite »

CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware

2026-08-11 08:35:34
The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being exploited in ransomware attacks and have been...

Lire la suite »

Hackers Pivot Through Private APN to Sabotage Siemens PLCs at Polish Power Plant

2026-08-11 08:12:33
Threat actors used a private cellular access-point-name (APN) network to pivot from a compromised wind farm into the operational technology environment. A Polish combined heat and power plant, where they...

Lire la suite »

Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities

2026-08-11 07:59:20
Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber's honeypots recording increased vCenter fingerprinting activity. The activity includes requests...

Lire la suite »

OpenAI dégaine un nouveau ChatGPT programmé pour traquer les failles de sécurité… et les exploiter

2026-08-11 07:45:26
OpenAI vient d'annoncer GPT-5.6-Cyber, une toute nouvelle intelligence artificielle capable de traquer les failles zero-day et de bâtir des chaînes d'exploitation complètes. Réservé aux professionnels...

Lire la suite »

Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access

2026-08-11 07:27:12
A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open remote viewing sessions, while its modular design...

Lire la suite »

CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files

2026-08-11 07:15:18
Cisco has disclosed seven high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning by submitting specially crafted files. These vulnerabilities...

Lire la suite »

Anthropic Adds Invisible Watermarks to Claude AI-Generated Text and Signed Metadata to Files

2026-08-11 07:03:55
Anthropic has launched a machine-readable content-marking initiative for materials generated by its Claude models. This initiative combines invisible text watermarks with digitally signed provenance metadata...

Lire la suite »

OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains

2026-08-11 06:58:35
OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation,...

Lire la suite »

DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files

2026-08-11 06:53:19
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July...

Lire la suite »

Pass-the-Passkey Attack Exploits Windows and Entra ID to Bypass MFA

2026-08-11 06:23:03
Security researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication...

Lire la suite »

Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack

2026-08-11 06:10:11
What is the Attack? Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations,...

Lire la suite »

Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition

2026-08-11 06:02:48
Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions....

Lire la suite »

Anthropic to Add Invisible Watermarks to All Claude AI Outputs

2026-08-11 05:59:33
Anthropic has announced plans to add invisible watermarks and signed metadata to content created by Claude AI. The move follows the company's decision to sign the European Union AI Act's Article 50(2)...

Lire la suite »

New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp

2026-08-11 05:52:31
A new phishing attack is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is designed to make fraudulent pages look normal at a glance,...

Lire la suite »

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

2026-08-11 05:48:44
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable...

Lire la suite »

New Abyssos RAT Hijacks Browser Sessions, Steals Credentials and Gives Attackers Remote VNC Access

2026-08-11 05:43:59
Abyssos, a modular C++ remote-access trojan that combines credential theft, browser-session hijacking, file exfiltration and hidden VNC control in a single post-compromise framework. Technical analysis...

Lire la suite »

Red Hat Kubernetes Flaw Allows Attackers to Escalate Privileges to Cluster-Admin

2026-08-11 05:43:27
Red Hat has disclosed a privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a low-privileged user to gain full cluster-admin control of an affected...

Lire la suite »

Claude Code Auto Mode Blocks 89% of Dangerous Commands and Prompt Injection Attacks

2026-08-11 05:12:10
Anthropic will make Auto Mode the default setting in Claude Code for Pro, Max, and Team subscribers starting August 14, 2026. This change introduces an automated classifier to replace repetitive manual...

Lire la suite »

Debian Caddy Important Access Control Breaches DSA-6429-1 CVE-2026-27585

2026-08-11 03:36:42
Multiple vulnerabilities in the Caddy web server can lead to unauthorized access and other security issues; users are urged to upgrade to version 2.6.2-12+deb13u1 for protection.

Lire la suite »

OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming

2026-08-11 03:33:12
OpenAI has expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue and Daybreak Red—alongside a new specialized...

Lire la suite »

Fedora 43 Kernel Important Security Fixes Advisory 2026-b54e45f108

2026-08-11 01:14:08
Fedora 43 kernel version 7.1.8 includes important fixes, characterized as security updates, with upcoming CVEs to be assigned, and can be installed via the dnf command.

Lire la suite »

Fedora 43 nghttp2 Critical HTTP Request Smuggling Vuln 2026-91dd0c29d6

2026-08-11 01:14:07
Fedora has released an update for nghttp2, version 1.66.0-3, addressing security vulnerabilities related to HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade...

Lire la suite »

Fedora 43 Chromium Critical Heap Buffer Overflow and Memory Problems

2026-08-11 01:14:07
Fedora has released an update for Chromium version 151.0.7922.108, addressing 41 security vulnerabilities, including multiple use-after-free issues and heap buffer overflows.

Lire la suite »

Fedora 43 p11-kit Important Overflow Fix CVE-2026-18938 Advisory

2026-08-11 01:14:05
Fedora 43 released an update for p11-kit version 0.26.5, fixing a CVE vulnerability affecting 32-bit systems, and enhancing loading and sharing of PKCS#11 modules.

Lire la suite »

Fedora 43 Launches Key Update for libcupsfilters to Fix CPU Exhaustion

2026-08-11 01:14:05
An update to libcupsfilters for Fedora 43 addresses CVE-2026-64611 and CVE-2026-64612, enhancing security for the CUPS daemon and printer applications.

Lire la suite »

Fedora 43 Python WebOb Important Security Update CVE-2024-42353

2026-08-11 01:14:02
Fedora 43 update for python-webob to version 1.8.11 addresses CVE-2024-42353, providing tools for WSGI request and response handling, enhancing HTTP functionality.

Lire la suite »

Fedora 43 mingw-gstreamer1-plugins-good CVE-2026-5056 Buffer Overflow Fix

2026-08-11 01:14:00
Fedora 43 has released an update for mingw-gstreamer1-plugins-good to fix CVE-2026-5056, a vulnerability related to arbitrary code execution from a stack-based buffer overflow.

Lire la suite »

Fedora 43 mingw-python-pip Update CVE-2026-13346 Security Threat Advisory

2026-08-11 01:14:00
Fedora 43 has updated the mingw-python-pip package to version 26.2, addressing potential security issues and enhancing functionality, alongside a link for installation via the dnf program.

Lire la suite »

Fedora 43 mingw-libidn Critical Out-of-bounds Read Update 2026-7ddafb24a3

2026-08-11 01:13:59
Fedora has released an update for mingw-libidn to version 1.44, addressing a CVE related to out-of-bounds reads in ToUnicode APIs, available through the dnf update program.

Lire la suite »

Fedora 43 Suricata Bugfix Update Intrusion Detection 2026-d2a3477900

2026-08-11 01:13:57
Fedora 43 has released an update for Suricata (version 7.0.17), an intrusion detection system featuring multi-threading and automatic protocol detection, addressing security and bug issues.

Lire la suite »

Fedora 43 Xen Security Flaw Critical Buffer Overflow Vulnerabilities Found

2026-08-11 01:13:55
Fedora has released an update for Xen 4.20.4 addressing multiple security issues, including buffer overflows and deprecated features, which can be installed via the dnf update tool.

Lire la suite »