Toute l'actualité de la Cybersécurité
Cyberattaque chez un prestataire de Suez : des données sensibles dérobées et mises en ligne
2026-08-21 16:02:44
Un prestataire de Suez Eau France a été victime d'une cyberattaque. Une partie des données a été exfiltrée et mise en ligne sur Internet. Si le fournisseur d'eau ne peut pas encore déterminer...
How I Built a Data Pipeline From Scratch Using Python
2026-08-21 16:00:06
Learn how I built a scalable data pipeline from scratch using Python, covering ingestion, processing, storage, and automation.
Your Screenplay Isn't Too Vague for a Director, but It Is for an AI Model
2026-08-21 16:00:03
AI video models do not infer intent like human crews. This guide shows how to rewrite vague screenplay action into clear, visible instructions for generation.
Pokémon Center touché par la cyberattaque d'un prestataire
2026-08-21 15:56:09
Cyberattaque : des données de clients Pokémon Center exposées et certaines précommandes annulées en Europe.
Hundreds of leaked AWS keys give full control over corporate accounts
2026-08-21 15:55:15
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Target visé par une nouvelle revendication de fuite
2026-08-21 15:41:54
Un pirate renvendique le vol de codes sources à un géant de la grande distribution, sur fond d'une précédente fuite interne.
Des bases de joueurs européens de casino diffusées sur un forum pirate
2026-08-21 15:28:56
Un vendeur propose des bases de joueurs de casino européens contenant coordonnées, téléphones et données de dépôt.
Checker max cible les portefeuilles Solana en masse
2026-08-21 15:12:09
Checker max analyse Solana par lots de 1 000 adresses, une capacité sensible pour le triage de portefeuilles proposé sur un forum de pirates.
How CertiK Found Five Vulnerabilities in Besu and Got Them Fixed in a Fortnight
2026-08-21 15:06:40
CertiK reported five resource exhaustion bugs to the Besu maintainers who shipped the fixes within a fortnight and then published severity ratings that disagree
Microsoft blames Windows gaming issues on RGB lighting devices
2026-08-21 14:54:49
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
AI Code Review: If AI Writes the Code, How Do We Review It at Scale?
2026-08-21 14:54:44
Learn what AI code review is, how it differs from AI code generation, where it fits in the SDLC, and how to evaluate AI review tools for production.
Scammers Use WhatsApp Groups to Coordinate Millions in Victim Trades and Pump Real Stocks
2026-08-21 14:52:11
Scammers are using WhatsApp groups to turn ordinary investors into an unwitting buying force. The operation does not need a hacked trading account or a stolen card. Instead, it persuades people to place...
DYSPHOR1A, nouveau groupe de ransomware maître chanteur
2026-08-21 14:44:23
DYSPHOR1A émerge comme un nouveau groupe ransomware maître chanteur, avec ventes, fuites et retraits payants de données.
Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks
2026-08-21 14:41:55
A Chinese-speaking cybercrime group is using AI-assisted tools to turn vulnerable web servers into entry points. It shows how familiar flaws become more dangerous when attackers automate the work around...
prismsec
2026-08-21 14:34:25
Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting
Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection
2026-08-21 14:14:20
Hackers are using Unicode emoji characters to hide an Agent Tesla JScript dropper in a business email compromise campaign aimed at finance teams. The tactic turns a payment-related attachment into a difficult-to-read...
I Turned My iOS Memory Game Into a Physical Board for Shipaton
2026-08-21 14:08:05
I took Adversary off-screen, turning its core mechanic into a physical prototype as the next step in my Build in Public journey.
agentic-dm-gateway
2026-08-21 14:04:23
Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to block secret leakage and image-beacon exfiltration.
Zombie Card: An expired Visa credit card can be used for purchases
2026-08-21 14:03:48
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.
Le « Legal Engineer », ce nouveau métier à la frontière du droit et de l'IA que Microsoft recrute
2026-08-21 14:02:06
Au sein de la direction juridique, le Principal Legal Engineer devra concevoir et déployer des agents IA, retravailler les prompts et les workflows juridiques mais aussi orchestrer Copilot et Harvey,...
The TechBeat: The Claude Opus 5 Rumor Passed the Screenshot Test, Not the API Contract Test (8/21/2026)
2026-08-21 14:01:05
8/21/2026: Trending stories on Hackernoon today!
Is Online Privacy Possible? How Digital Identities Can Help
2026-08-21 14:00:10
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas...
500 Blog Posts To Learn About Mobile App Development
2026-08-21 14:00:09
Learn everything you need to know about Mobile App Development via these 500 free HackerNoon blog posts.
Calling on Cyber Pros to Help Defend City Hall
2026-08-21 14:00:00
Government agencies with smaller budgets need support — and here's how you can help.
Un recrutement VPN français intrigue sur un forum pirate
2026-08-21 13:56:56
Un membre d'un forum pirate russe recrute des francophones pour un VPN, malgré un historique lié au spam et aux RAT.
Data Debt in Production ML Pipelines: Detection and Remediation at Scale
2026-08-21 13:42:19
Learn how to catch data debt before it degrades production ML models using schema checks, null monitoring, PSI, KS tests, and drift detection.
Microsoft rolls out Classic Outlook theme for New Outlook users
2026-08-21 13:39:35
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
A Reference Architecture for AI-Driven Healthcare Data Engineering
2026-08-21 13:30:58
Healthcare data platforms are evolving beyond ETL, using AI for anomaly detection, entity matching, forecasting, compliance, and data quality.
OpenAI Adds Controls That Should've Been There Already
2026-08-21 13:30:00
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.
Claude Opus 5 Routes Around Obfuscated Binaries Instead of Defeating the Protection
2026-08-21 13:26:20
Claude Opus 5 did not crack hardened binaries in a reverse-engineering experiment. Instead, it sought easier ways to recover hidden information, showing AI-assisted analysis can be capable yet unreliable....
Turning Apache DolphinScheduler Into an Agent-Friendly Workflow Platform
2026-08-21 13:19:08
dsctl adds CLI-based automation, workflow-as-code, CI/CD, and controlled AI-agent operations to Apache DolphinScheduler through its REST APIs.
Cybersecurity Ventures and World Economic Forum On The Global Cost of Cybercrime
2026-08-21 13:15:37
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 21, 2026 – Read the full Irish Times Story A special report from The Irish Times declares cyber...
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
2026-08-21 13:08:51
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank...
Deux millions de données françaises mises en vente
2026-08-21 13:08:19
Un forum pirate propose deux millions de données françaises, sans preuve publique sur leur origine.
Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks
2026-08-21 13:06:57
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the...
Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts
2026-08-21 13:06:34
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisements, impersonated financial experts, and coordinated...
Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks
2026-08-21 13:06:02
GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478, a critical unauthenticated code injection vulnerability affecting self-managed...
openSUSE Chromium Critical Buffer Overflow Issues Vuln 2026-0293-1
2026-08-21 13:04:47
openSUSE has released a critical security update for Chromium, addressing 15 vulnerabilities including buffer overflows and type confusion. Users are urged to apply the update promptly.
Sandb0x-Xtract0r
2026-08-21 13:04:01
Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM reports.
US Bank Investigating Data Breach Following LockBit Ransomware Claim
2026-08-21 13:01:06
US Bank is investigating LockBit's claims of a breach and data theft, with the ransomware group threatening to publish the alleged stolen files on September 3 unless an undisclosed ransom is paid. Lee...
Zero Trust In The Age Of AI Driven Cyber Threats (Why Cisos Must Redefine Enterprise Trust Boundaries In 2026)
2026-08-21 13:00:48
Enterprise cybersecurity is undergoing a structural shift driven by two converging forces: the collapse of traditional network perimeters and the rapid weaponization of artificial intelligence by threat...
Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes
2026-08-21 13:00:14
A critical vulnerability in N-able Passportal's Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization's entire password vault, including...
Your Five-Minute AI Film Does Not Need a 15-Beat Structure
2026-08-21 13:00:02
The classic 15-beat structure is built for a 90-minute feature. Here's how to size a beat sheet for a short AI-generated film instead.
C.Hunters, un service pirate testé pour la France
2026-08-21 12:52:57
C.Hunters propose des appels ciblés sur un forum pirate, avec un intérêt explicite pour la France.
Binance Launches Agent OS, Letting AI Agents Trade on Your Account With Limits You Set
2026-08-21 12:40:00
Covering AI, Web3, Cybersecurity, Startup Funding & Enterprise SaaS. Top Journalist & Thought Leadership Media Leader
openSUSE rsync Important Security Fix for 33 Issues Vuln 2026-3657-1
2026-08-21 12:35:51
A SUSE security update for rsync addresses 33 vulnerabilities and includes one security fix, impacting several supported SUSE Linux versions and providing essential installation instructions.
SUSE rsync Important Security Update for 33 Vulnerabilities 2026-3657-1
2026-08-21 12:35:34
A security update for rsync addresses 33 vulnerabilities, enhancing system protection against risks such as directory escape, command injection, and privilege escalations in various SUSE products.
detection-defense-library
2026-08-21 12:34:05
Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD driver intelligence, and Splunk workflows.
SUSE MozillaFirefox Important Security Update 2026-3658-1
2026-08-21 12:34:01
SUSE has released a security update for MozillaFirefox addressing 58 vulnerabilities, including critical issues in components like Graphics and JavaScript, with recommended installation methods provided....
openSUSE Kubernetes Old Important Security Update SUSE-SU-2026-3659-1
2026-08-21 12:33:15
SUSE has released a critical security update for kubernetes-old, allowing installation through standard methods like YaST or zypper, aimed at addressing vulnerabilities.
SUSE Kubernetes-Legacy Significant Security Update 2026-3659-1
2026-08-21 12:32:59
A security update for kubernetes-old has been released, addressing vulnerabilities by rebuilding it against the latest go security release, applicable to several SUSE and openSUSE products.
openSUSE Kubernetes Significant Security Patch 2026-3660-1
2026-08-21 12:32:21
A security update for Kubernetes has been released, rebuilding it against the latest Go security release, affecting several SUSE and openSUSE products with recommended installation methods provided.
SUSE Kubernetes Important Security Update Advisory 2026-3660-1
2026-08-21 12:32:05
SUSE released an important security update for Kubernetes, rebuilding it against the latest Go security release, with specific installation instructions for various affected product versions.
SUSE Helm Essential Security Patch Announcement for 2026-3661-1
2026-08-21 12:31:27
SUSE has released a security update for helm, rebuilding it against the latest Go security release, affecting several SUSE Linux Enterprise products and accessible via zypper.
openSUSE Podman Security Advisory CVE-2026-55686 CVE-2026-57231 Guide
2026-08-21 12:30:50
A security update for podman addresses two vulnerabilities in openSUSE Leap 15.3 and SUSE Enterprise Storage 7.1, allowing unauthorized host filesystem access and leaking environment variables.
SUSE Podman Important Security Fix for CVE-2026-55686 CVE-2026-57231
2026-08-21 12:30:33
A security update for podman addresses two vulnerabilities affecting openSUSE Leap 15.3 and SUSE Enterprise Storage 7.1, enabling prevention of directory manipulation and environment variable leaks.
Six Maximum-Severity Flaws Found in Cisco Products
2026-08-21 12:30:16
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms...
CISA orders feds to patch actively exploited TrueConf Server flaws
2026-08-21 12:25:33
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications...
custom-oscp-tooling
2026-08-21 12:04:13
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and payload/credential command generation.
Encore, encore, encore … un nouveau groupe ransomware : SovCali
2026-08-21 12:03:50
Un nouvel acteur du rançongiciel, SovCali, apparaît et affirme détenir des données de Lucid Motors, première cible publiquement revendiquée.
The New Russian Playbook: Bypassing MFA Without Cracking Passwords
2026-08-21 12:00:48
OAuth Exploitation Russian threat actors are shifting away from plain old password theft and moving toward legitimate platform features like OAuth permissions. Groups like UNC6293 and UNC7005 take their...
Medical records, SSNs, and bank details exposed in CareCloud data breach
2026-08-21 11:50:55
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.
Comment Lazarus détourne des offres d'emploi pour infiltrer l'industrie de la défense
2026-08-21 11:38:57
Le groupe nord-coréen Lazarus a combiné ingénierie sociale sophistiquée et exploitation d'une faille inédite pour s'introduire chez des acteurs de la défense et de l'aérospatiale en Europe, en...
Russian Hackers Abuse OAuth and WhatsApp Device Linking to Hijack High-Value Accounts
2026-08-21 11:31:54
Suspected Russian cyber-espionage groups are increasingly turning ordinary sign-in and device-linking features into tools for account takeover. Their latest campaigns do not depend on breaking passwords...
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
2026-08-21 11:30:16
A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial...
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
2026-08-21 11:23:51
Cybersecurity researchers have revealed a critical vulnerability in N-able's PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials...
Wazuh and AI For Enhanced SOC Workflows
2026-08-21 11:21:39
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive...
Fake Conferences, OAuth and WhatsApp: Inside Russia's New Espionage Tactics
2026-08-21 11:11:11
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked...
OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing
2026-08-21 11:07:22
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed...
Microsoft warns of max severity Entra ID flaw exploited in attacks
2026-08-21 11:04:10
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]
mcp-stdio-shellguard v0.1.2
2026-08-21 11:03:56
Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security 200k-server stdio-RCE class (LiteLLM CVE-2025-69256)....
Hackers abuse FTP server banners to deliver new Windows malware
2026-08-21 11:00:00
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
2026-08-21 10:56:24
Cybercriminals are abusing interest in generative AI to trick users into downloading malware. In a newly documented incident, a file posing as a Google Gemini installer delivered the Vidar information...
Puériculture : trois bases clients revendiquées en 2026
2026-08-21 10:34:18
Trois bases liées à la maternité et la puériculture sont revendiquées en 2026, dont Made in Bébé, Allobébé et Babyvista.
oscp-notes-2026
2026-08-21 10:33:30
OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)
Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords
2026-08-21 10:27:17
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing...
SickKids data breach exposes employee and job applicant info
2026-08-21 10:10:42
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party...
cantina
2026-08-21 10:03:48
OSCP-legal network recon orchestrator for port discovery, service classification, and enum-only plugin dispatch across HTTP, SMB, FTP, SNMP, SSH, and more.
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
2026-08-21 10:03:11
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.
Four of the security vulnerabilities...
Rocky Linux 8 Kernel Important Security Bug Fix Advisory RLSA-2026-57253
2026-08-21 10:01:06
A significant update for Rocky Linux 8 addresses various kernel vulnerabilities and includes bug fixes and enhancements, emphasizing essential security improvements for the operating system.
Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing
2026-08-21 10:00:46
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender's threat model. Its latest experiment found that autonomous coding agents routinely...
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
2026-08-21 09:49:02
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab...
Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data
2026-08-21 09:27:56
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind...
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
2026-08-21 09:17:46
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants....
Poland's CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
2026-08-21 09:14:02
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response...
pbtk v1.1.3
2026-08-21 09:03:31
A toolset for reverse engineering and fuzzing Protobuf-based apps
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
2026-08-21 08:56:13
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with...
Services IT : comment l'IA fait évoluer les contrats de prestation
2026-08-21 08:42:46
Face aux gains de productivité générés par l'IA, les ESN françaises voient leur modèle historique de facturation au temps passé remis en cause.
The post Services IT : comment l'IA fait évoluer...
iDescriptor v0.6.2
2026-08-21 08:33:11
A free, open-source, and cross-platform iDevice management tool
Une plateforme de gestion de rendez-vous médicaux piratée : 6,8 millions de profils volés
2026-08-21 08:31:31
Un hacker a revendiqué une cyberattaque contre Alaxione, une plateforme spécialisée dans la gestion des rendez-vous médicaux. Il assure avoir mis la main sur 6,8 millions de profils, qui incluraient...
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
2026-08-21 08:22:11
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added...
ToxicPanda 2.0 : un cheval de Troie bancaire Android nettement plus puissant découvert par le zLabs de Zimperium
2026-08-21 08:07:32
zLabs, l'équipe de recherche de Zimperium, leader mondial de la sécurité mobile basée sur l'IA, publie une nouvelle étude consacrée à ToxicPanda 2.0, une évolution majeure du cheval de Troie...
badkeys v0.0.20
2026-08-21 08:02:46
Tool to find common vulnerabilities in cryptographic public keys
The invisible passenger in your car
2026-08-21 08:00:29
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
Cyberespionnage : l'arsenal « CAV3RN » évolue et détourne Google Apps Script pour cibler Israël
2026-08-21 08:00:08
Selon de nouvelles recherches menées par l’équipe GReAT de Kaspersky, le kit d’outils de cyberespionnage Project CAV3RN continue d’évoluer et de cibler activement des organisations...
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
2026-08-21 07:15:02
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack...
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
2026-08-21 07:04:25
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.
The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4),...
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
2026-08-21 06:06:11
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.
The vulnerability, tracked as...
Multiples vulnérabilités dans Google Chrome (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Vulnérabilité dans Python (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
Vulnérabilité dans SPIP (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans SPIP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que cette vulnérabilité est activement exploitée....
Multiples vulnérabilités dans le noyau Linux de SUSE (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation...
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans les produits IBM (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation...
Multiples vulnérabilités dans le noyau Linux de Debian (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges.
Multiples vulnérabilités dans le noyau Linux de Debian LTS (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité...
Multiples vulnérabilités dans Traefik (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans Traefik. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.
Multiples vulnérabilités dans Microsoft Edge (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Vulnérabilité dans Microsoft Office (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
Multiples vulnérabilités dans les produits Microsoft (21 août 2026)
21/08/2026
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un déni de service.
Vulnérabilité dans Microsoft Entra ID (21 août 2026)
21/08/2026
Une vulnérabilité a été découverte dans Microsoft Entra ID. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-69836...