Toute l'actualité de la Cybersécurité


Mate Security Grows Over 500% Since Q3 2025 and Pushes Past M in Funding

2026-07-28 19:09:53
Mate Security secures M in Series A funding after 500% growth, as Fortune 500 demand grows for its agentic AI security operations platform worldwide.

Lire la suite »

Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure

2026-07-28 19:07:43
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet...

Lire la suite »

Ubuntu FreeRDP RDP Client Significant Clipboard Regression Fix USN-8561-2

2026-07-28 19:02:55
A regression affecting clipboard functionality in FreeRDP was introduced in an earlier security update. Users should update to resolve the issue in Ubuntu 26.04 LTS and 24.04 LTS.

Lire la suite »

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

2026-07-28 18:59:07
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously...

Lire la suite »

CISA shares advice on isolating vital systems during cyberattacks

2026-07-28 18:41:04
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or...

Lire la suite »

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

2026-07-28 18:32:03
OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain...

Lire la suite »

Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years

2026-07-28 18:24:07
Anthropic researchers using Claude Mythos Preview have uncovered mathematical flaws in major cryptographic algorithms that human experts failed to spot for years. The AI found improved attacks against...

Lire la suite »

vBulletin fixes critical pre-auth RCE flaw with public exploit

2026-07-28 18:08:50
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]

Lire la suite »

USN-8561-2: FreeRDP regression

2026-07-28 18:08:13
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original...

Lire la suite »

JetBrains Urging Customers to Patch Critical TeamCity Flaw that Enables OS Command Execution

2026-07-28 17:46:13
JetBrains has urgently released security updates for a critical vulnerability in TeamCity On-Premises that could allow remote attackers to bypass authentication and execute arbitrary operating system...

Lire la suite »

Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)

2026-07-28 17:40:32
Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth device-code flow abuse and adversary-in-the-middle (AiTM)...

Lire la suite »

PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites

2026-07-28 17:34:10
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.

Lire la suite »

Chrome Extension Monitors AI Conversations Across ChatGPT, Claude, Gemini, and Other Platforms

2026-07-28 17:24:03
A Chrome extension with roughly 100,000 installs is quietly harvesting every prompt and AI response typed across nine major artificial intelligence platforms. Despite its official listing and privacy...

Lire la suite »

Mageia 10 gstreamer1.0-libav Heap Corruption CVE-2026-52717

2026-07-28 17:07:40
A security advisory reported heap corruption in the gst-libav AV protocol pipe, affecting Mageia release 10, linked to CVE-2026-52717.

Lire la suite »

Mageia libslirp Critical TCP OOB Read Info Leak Vulnerability CVE-2026-9539

2026-07-28 17:07:39
Mageia releases 10 and 9 have updates addressing a security vulnerability related to TCP URG OOB Read Information Leak (CVE-2026-9539).

Lire la suite »

Nginx Buffer Overflow Vulnerability Allows Attackers to Execute Arbitrary Code – PoC Released

2026-07-28 16:46:41
A high-severity heap buffer overflow in NGINX Plus and NGINX Open Source can let unauthenticated attackers crash worker processes and, under certain conditions, run arbitrary code. Tracked as CVE-2026-42533,...

Lire la suite »

openSUSE Kernel Important Patch Fixing Five Issues 2026-3319-1

2026-07-28 16:41:54
A security update for SUSE Linux Kernel fixes five vulnerabilities, enhancing system protection via recommended installation methods for affected products including SUSE Linux Enterprise Server and openSUSE...

Lire la suite »

'Certighost' Flaw Haunts Microsoft Active Directory Certificates

2026-07-28 16:38:48
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.

Lire la suite »

ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

2026-07-28 16:28:04
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.

Lire la suite »

Debian hplip Important Escalation and Code Exec Risks DSA-6402-1

2026-07-28 16:13:19
Debian addresses two vulnerabilities in hplip that could lead to privilege escalation or code execution, urging users to upgrade to the fixed version 3.22.10+dfsg0-8.1+deb13u1.

Lire la suite »

Click to pray expose les données de plus de 700 000 fidèles

2026-07-28 16:06:07
Click To Pray expose 700 000 comptes via une faille idiote, avec un risque élevé de phishing ciblé et d'usurpation.

Lire la suite »

Rethinking Ransomware Defense at the Filesystem Layer

2026-07-28 16:00:38
Ransomware defense using fanotify and append only archives

Lire la suite »

Formatif Earns a 44 Proof of Usefulness Score by Building a 100% Offline, Local-First Desktop Media Processing Suite

2026-07-28 16:00:16
Formatif earned a 44 Proof of Usefulness score for running 59 media-processing and AI enhancement tools entirely on local hardware.

Lire la suite »

Disrupting supply chain attacks on npm and GitHub Actions

2026-07-28 16:00:00
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm...

Lire la suite »

The Future of Human Work: Finding Our Place in the Age of AI

2026-07-28 15:56:23
As AI takes over more cognitive tasks, are we losing the skills that make us human? Explore how AI is reshaping learning, work, and human purpose.

Lire la suite »

openSUSE Leap 16.0 Chromium Important Use After Free Issues 2026-21453-1

2026-07-28 15:53:18
openSUSE has released a security update for Chromium addressing four vulnerabilities, including out-of-bounds write and use-after-free issues, along with a bug fix for Leap 16.0.

Lire la suite »

openSUSE Leap 16.0 agama-web-ui Important Security Patch SUSE-2026-21448-1

2026-07-28 15:52:39
openSUSE released a security update for agama-web-ui addressing 13 vulnerabilities with 14 bug fixes, focusing on various issues related to data handling and security exploits.

Lire la suite »

SwiftList Earns a 83.84 Proof of Usefulness Score by Building an AI Platform for Generating Complete Property Listings

2026-07-28 15:43:42
SwiftList earned an 83.84 Proof of Usefulness score for turning property photos and details into complete real estate marketing packages.

Lire la suite »

Aembit Joins Snowflake to Tackle AI's Next Security Frontier: Trusted Agent Interoperability

2026-07-28 15:16:19
Silver Spring, MD, USA, 28th July 2026, CyberNewswire

Lire la suite »

openSUSE Tumbleweed valkey Moderate Security Update 2026-11381-1

2026-07-28 15:37:19
An update for openSUSE Tumbleweed addresses two vulnerabilities in the valkey package, rated moderate, with CVSS scores of 7.5 and 8.8.

Lire la suite »

openSUSE Tumbleweed python313-CherryPy Moderate Issue CVE-2019-9740

2026-07-28 15:37:18
An update for python313-CherryPy-18.10.0-4.1 on openSUSE Tumbleweed addresses a vulnerability identified as CVE-2019-9740, rated moderate with a CVSS score of 5.4.

Lire la suite »

openSUSE Libssh Moderate Security Advisory CVE-2026-15370 CVE-2026-59843

2026-07-28 15:37:18
An update for openSUSE Tumbleweed's libssh-config-0.11.5-1.1 addresses nine vulnerabilities with various CVSS scores, enhancing overall security for affected users.

Lire la suite »

openSUSE Ignition Important Security Issues Fix 2026-11376-1

2026-07-28 15:37:18
An update for ignition-2.26.0-5.1 on openSUSE Tumbleweed addresses three security vulnerabilities identified by CVEs, with varying severity ratings and CVSS scores.

Lire la suite »

Designing for Human Confidence: Why Trust Alone Isn't Enough for AI Products

2026-07-28 15:36:06
Trust is the outcome, not the starting point. Discover why confidence should be the primary design objective for AI-native products.

Lire la suite »

Wi-Fi public : ce que votre fournisseur, pirates et marketing peuvent voir

2026-07-28 15:29:46
En voyage, découvrez ce que votre fournisseur ou pirate voient et comment protéger vos données sur un Wi-Fi public.

Lire la suite »

itsfolio.tech Earns a 50 Proof of Usefulness Score by Building an AI-Powered Resume-to-Portfolio Converter

2026-07-28 15:28:04
itsfolio.tech earned a 50 Proof of Usefulness score for turning resume PDFs into fully hosted online portfolios in seconds.

Lire la suite »

Agent Memory Has a Lock-In Problem. Open Formats Are How We Fix It.

2026-07-28 15:20:49
AI agents shouldn't lose their memories when you switch platforms. Learn how Open Knowledge Format (OKF) enables portable, version-controlled agent memory.

Lire la suite »

Smart Care Triage Earns a 35.03 Proof of Usefulness Score by Building a Decision-Support Tool for Hospital Intake

2026-07-28 15:19:47
Smart Care Triage earned a 35.03 Proof of Usefulness score for using explainable AI to support faster, safer hospital intake decisions.

Lire la suite »

Debian Samba Important DoS and Privilege Escalation DSA-6401-1

2026-07-28 15:16:55
Debian issued advisory DSA-6401-1 on July 28, 2026, regarding multiple vulnerabilities in Samba that could lead to denial of service, domain takeover, information disclosure, or privilege escalation,...

Lire la suite »

Apple iOS 26.6 Fixes Flaws Enabling Kernel Code Execution, Root Access and Sandbox Escape

2026-07-28 15:15:50
Apple has released iOS 26.6 and iPadOS 26.6 to address a significant number of security vulnerabilities, including flaws that could allow malicious applications to execute code with kernel privileges,...

Lire la suite »

HostLens AI Earns a 55.35 Proof of Usefulness Score by Building an Agentic GraphRAG AI Assistant for Rental Market Insights

2026-07-28 15:14:04
HostLens AI earned a 55.35 Proof of Usefulness score for using GraphRAG and Airbnb data to assess rental ROI and market viability.

Lire la suite »

Votre iPhone doit être mis à jour sans attendre : ce qu'Apple vient de corriger est inquiétant

2026-07-28 15:07:16
Apple déploie une nouvelle mise à jour pour l'iPhone. Derrière quelques changements discrets se cache surtout plus de 75 correctifs de sécurité, un chiffre élevé en partie attribué aux outils...

Lire la suite »

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

2026-07-28 15:01:33
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms...

Lire la suite »

Electric Vehicles Have Gotten Better, But Have They Earned Your Trust Yet?

2026-07-28 15:00:43
Do drivers finally trust electric vehicles? Explore HackerNoon poll results, EV adoption trends, charging concerns, and Tesla prediction markets.

Lire la suite »

The Next AI War Will Be Fought Over Access, Not Models.

2026-07-28 14:56:25
The next AI race won't be won by the smartest model. Discover why compute access, infrastructure, and national AI strategy may define the future instead.

Lire la suite »

Microsoft lance MAI-Cyber-1-Flash et pousse l'IA au cœur du SOC

2026-07-28 14:49:49
MAI-Cyber-1-Flash est le premier modèle d'IA conçu pour la cybersécurité. Intégré à MDASH, il promet d'accélérer la détection des failles tout en réduisant le coût des opérations. The post...

Lire la suite »

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

2026-07-28 14:41:36
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol...

Lire la suite »

The TechBeat: A Developer's Guide to Agentic AI Frameworks and Components (7/28/2026)

2026-07-28 14:01:06
7/28/2026: Trending stories on Hackernoon today!

Lire la suite »

Is Your SSO Protected Against Modern Credential Attacks?

2026-07-28 14:00:10
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening...

Lire la suite »

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

2026-07-28 13:33:47
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository...

Lire la suite »

From Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global Investing

2026-07-28 13:28:34
See how stablecoins, tokenized stocks and fractional investing lower costs and expand global access to US markets through modern financial super apps worldwide.

Lire la suite »

Fake Claude Code Install Guide Uses Google Ads to Deliver MacSync Infostealer

2026-07-28 13:23:35
Fake Google Ads are being used to push a convincing Claude Code installation guide that delivers the MacSync infostealer to macOS users. The campaign turns an ordinary developer search into a path for...

Lire la suite »

Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations

2026-07-28 13:10:52
A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against organizations in the United States, putting Java applications that process untrusted JSON at immediate risk....

Lire la suite »

Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads

2026-07-28 13:02:24
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses...

Lire la suite »

Origin Confirms Data Breach – Hackers Accessed 900,000 Customers' Data

2026-07-28 13:01:41
Origin Energy, an Australian energy provider, has confirmed that unauthorized access to customer information has affected approximately 900,000 current and former customers. The company has completed...

Lire la suite »

AI Changes the Software Supply Chain and How We Secure It

2026-07-28 13:00:06
Artificial intelligence is expanding the software supply chain beyond traditional software components, introducing new dependencies that require security leaders to rethink how software is governed....

Lire la suite »

Rapid7 Cyber GRC is now available: Turn security action into compliance proof

2026-07-28 13:00:00
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to...

Lire la suite »

The Next Evolution of MDR: Preemptive Defense and Agentic Investigation

2026-07-28 13:00:00
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape...

Lire la suite »

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

2026-07-28 12:56:14
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921...

Lire la suite »

Réseaux sociaux : ce qui changera en 2026 et 2027

2026-07-28 12:56:07
Réseaux sociaux interdits aux moins de 15 ans : calendrier, contrôle d'âge, risques cyber et leçons australiennes.

Lire la suite »

Kimi K3 : comment Moonshot AI est passé à l'échelle

2026-07-28 12:51:32
Le rapport technique de Kimi K3 témoigne d'un chantier sur trois grands axes pour tenir l'échelle des (quasi) 3 milliards de paramètres et 1000 experts. The post Kimi K3 : comment Moonshot AI est passé...

Lire la suite »

We rebuilt Malwarebytes Mobile Security for the scams of today

2026-07-28 12:40:00
Your phone needs more than a lock screen to stay safe. We've rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.

Lire la suite »

Shared Claude chats were searchable on Google

2026-07-28 12:33:11
Reddit users found that by using a specific search query, they could find shared Claude conversations in search results.

Lire la suite »

Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users

2026-07-28 12:32:24
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure...

Lire la suite »

Former Citigroup CISO Blauner on What Makes A Great Security Leader

2026-07-28 12:30:00
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.

Lire la suite »

Public Exploit Lands for vBulletin's Pre-Auth RCE, CVE-2026-61511

2026-07-28 12:18:07
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection works and who still needs to patch. Public Exploit Lands for vBulletin’s...

Lire la suite »

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

2026-07-28 12:10:23
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]

Lire la suite »

When cyber attacks happen: helping organisations recover

2026-07-28 12:00:00
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.

Lire la suite »

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

2026-07-28 11:55:20
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities...

Lire la suite »

USN-8621-1: Samba vulnerabilities

2026-07-28 11:50:00
It was discovered that Samba's pam_winbind incorrectly handled home directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by triggering...

Lire la suite »

CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions

2026-07-28 11:36:44
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings...

Lire la suite »

Update your iPhone, iPad and Mac to fix Apple security holes

2026-07-28 11:35:40
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.

Lire la suite »

Confidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in Use

2026-07-28 11:24:52
Modern AI runs on shared, high-performance infrastructure that processes enormous volumes of sensitive data and valuable model weights.…

Lire la suite »

JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover

2026-07-28 11:17:06
JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after...

Lire la suite »

Vatican’s Click To Pray app exposed personal data from 700,000 users

2026-07-28 11:11:36
Anyone could access other Click To Pray users' personal information. The flaw went unfixed for more than six months after it was reported.

Lire la suite »

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands

2026-07-28 10:58:50
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system...

Lire la suite »

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

2026-07-28 10:50:55
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations

Lire la suite »

Nvidia mise gros sur le mystère Sutskever

2026-07-28 10:40:13
Nvidia investit environ 5 milliards $ dans Safe Superintelligence, le laboratoire très secret d'Ilya Sutskever, pour sécuriser un nouveau client stratégique face à la concurrence. The post Nvidia...

Lire la suite »

Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations

2026-07-28 10:38:26
Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations, with evidence pointing...

Lire la suite »

AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation

2026-07-28 10:34:07
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in...

Lire la suite »

Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal

2026-07-28 09:47:56
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence,...

Lire la suite »

New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide

2026-07-28 09:35:40
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed...

Lire la suite »

Anthropic et les modèles open-weight : oui, mais…

2026-07-28 09:24:25
Non signataire de la lettre ouverte par laquelle la tech US défend les modèles open-weight, Anthropic expose sa position. The post Anthropic et les modèles open-weight : oui, mais… appeared first...

Lire la suite »

Suitable AI : 15 176 comptes exposés via GraphQL

2026-07-28 09:16:47
Suitable AI : une fuite revendiquée expose 15 176 candidats et des failles critiques à grande échelle.

Lire la suite »

Fake ShinyHunters Emails Give Victims 48 Hours to Pay ,000 Bitcoin Ransom

2026-07-28 09:14:09
Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom...

Lire la suite »

Data breach at medical billing firm MCBS affects 1.26 million people

2026-07-28 09:10:03
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]

Lire la suite »

Anthropic dévoile Claude Opus 5

2026-07-28 09:09:05
Anthropic poursuit sa stratégie d’industrialisation de l’IA générative avec le lancement de Claude Opus 5, une récente (...)

Lire la suite »

KomikoAI : une fuite relie courriels et prompts

2026-07-28 09:01:19
Des données personnelles d'un professionnel de l'IA piratés : courriels, identifiants, contenus générés et prompts d'utilisateurs.

Lire la suite »

How I found an IDOR in Google Classroom on Day 3 of my Hunting?

2026-07-28 08:56:56
Hello Guys,Hope you are well. This is my first writeup and I will tell you how I found IDOR on Google Classroom on Day 3 of my hunting on Google. I hope it will inspire you.I selected my first target...

Lire la suite »

U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

2026-07-28 08:19:29
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure...

Lire la suite »

LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives

2026-07-28 08:16:39
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing...

Lire la suite »

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

2026-07-28 08:11:22
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The...

Lire la suite »

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

2026-07-28 08:04:44
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free...

Lire la suite »

Mirage Kitten targets Middle East and Africa region with new malware

2026-07-28 08:00:20
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Lire la suite »

Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success

2026-07-28 08:00:00
Claudia Zoon is Senior Manager, Channel Sales at Rapid7.Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly...

Lire la suite »

TryHackMe(RootMe)- Write-Up

2026-07-28 07:56:04
IntroHey everyone! Today we're solving the TryHackMe room RootMe — a great beginner-friendly box that covers web enumeration, exploiting a file upload vulnerability to get a reverse shell, and...

Lire la suite »

Tryhackme Room — W1seGuy | by Sahil Malvi

2026-07-28 07:53:58
Tryhackme Room — W1seGuy | by Sahil MalviHere's a link to the room: https://tryhackme.com/r/room/w1seguyTASK [1] Source CodeYes, it's me again with another crypto challenge!Have a look at...

Lire la suite »

The Invisible Hack: How a Linux Bug Lets Anyone Become Root — Without Leaving a Single Trace

2026-07-28 07:53:45
A deep dive into CVE-2026–31431 — the vulnerability that breaks the most fundamental rule of computer security: that what's on disk is what runs.Imagine you hire a security guard for your house....

Lire la suite »

Proxy — TryHackMe Active Directory Write-up

2026-07-28 07:48:54
By: Kavin Jindal (@Klevr)Check out the challenge: TryHackMe | ProxyIn this write-up, I will give you a detailed walkthrough of ‘Proxy ', which is an Active Directory based machine on TryHackMe where...

Lire la suite »

Avec iOS 26.6, Apple corrige près de 90 failles de sécurité, mettez à jour votre iPhone !

2026-07-28 07:45:24
Apple vient de déployer iOS 26.6 sur iPhone et iPad. Cette mise à jour intermédiaire corrige un impressionnant total de 87 failles de sécurité dans le code d'iOS, y compris dans le noyau du système...

Lire la suite »

Samba Spy — LetsDefend (Walkthrough)

2026-07-28 07:44:48
Investigating a Malicious .jar fileHello guys, I'm back with another writeup. First of all, can you tell me why Ronaldo is out of the World cup? I could not sleep that day. Anyways.. that was just...

Lire la suite »

Unprotected admin functionality — PortSwigger Access control vulnerabilities Lab 1

2026-07-28 07:43:06
Unprotected admin functionality — PortSwigger Access control vulnerabilities Lab 1Finding ID: BAC-Portswigger-001Title: Unprotected Admin FunctionalityRisk (Severity): HighRationale:The application...

Lire la suite »

How an Unpatched N-Day Let Any Anonymous Visitor Rewrite WooCommerce Prices in ND Booking

2026-07-28 07:42:03
Author: Shikhali Jamalzade GitHub: alisalive LinkedIn: camalzads Type: Independent Security Research | WordPress Plugin CVE ResearchThis is a write-up of a vulnerability I independently discovered in...

Lire la suite »

PeekList: How Brave's Playlist bypassed FaceID Protection for Private Tabs

2026-07-28 07:41:35
Brave Browser LogoTL;DRBrave for iOS lets you lock Private Tabs behind Face ID or a device passcode. That protection can be completely bypassed using the built-in Brave Playlist feature. Adding any video...

Lire la suite »

Discovering an Time-Based Blind SQL Injection in a Tamil Nadu Government Web Portal (TANGEDCO)

2026-07-28 07:38:42
Hunting an Oracle Time-Based Blind SQL Injection: A Real Bug Bounty JourneyBy karthithehackerIntroductionRecently, while performing security testing as part of a bug bounty program, I discovered an Oracle...

Lire la suite »

USN-8620-1: Linux kernel vulnerabilities

2026-07-28 07:31:41
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could...

Lire la suite »

USN-8619-1: Linux kernel (HWE) vulnerabilities

2026-07-28 07:28:45
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

USN-8595-3: Linux kernel (AWS) vulnerabilities

2026-07-28 07:25:50
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

USN-8574-3: Linux kernel vulnerabilities

2026-07-28 07:23:25
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information....

Lire la suite »

USN-8570-2: Linux kernel (Oracle) vulnerabilities

2026-07-28 07:19:37
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); ...

Lire la suite »

USN-8618-1: Linux kernel vulnerabilities

2026-07-28 07:16:49
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a...

Lire la suite »

USN-8617-1: Linux kernel (KVM) vulnerabilities

2026-07-28 06:46:54
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this...

Lire la suite »

USN-8616-1: Linux kernel (IBM) vulnerabilities

2026-07-28 06:43:49
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem...

Lire la suite »

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

2026-07-28 06:07:22
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4,...

Lire la suite »

Houston City College - 831,642 breached accounts

2026-07-28 06:05:24
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email...

Lire la suite »

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

2026-07-28 04:43:53
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS...

Lire la suite »

Cloud Security Alliance CISO Community Releases Emergency Guidance After Autonomous AI Model Breached Hugging Face's Production Systems During a Security Evaluation

2026-07-28 04:38:03
New report analyzes the first publicly documented fully autonomous cyberattack and delivers practical steps security leaders should take to strengthen their AI resilience today SEATTLE – July 28, 2026...

Lire la suite »

AI Agent Drives Espionage Attack on Thai Ministry of Finance

2026-07-28 01:00:00
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.

Lire la suite »

List of 33 new domains

2026-07-28 00:00:00
.fr asus-offrespromotionnelles[.fr] (registrar: NETIM) billionairesp1n[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) blockchain-support[.fr] (registrar: Hosting Concepts B.V. d/b/a Openprovider) cas1nozerzz[.fr]...

Lire la suite »

Multiples vulnérabilités dans les produits Apple (28 juillet 2026)

28/07/2026
De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges...

Lire la suite »

Multiples vulnérabilités dans Samba (28 juillet 2026)

28/07/2026
De multiples vulnérabilités ont été découvertes dans Samba. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des...

Lire la suite »