Skip to content
Rédaction

Cybersécurité

Fuites de données, vulnérabilités, malwares et ceux qui défendent.

48titres10sources internationales1articles maison
Suivre ce thème

Plus de titres

Syndiqué
TTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
The Hacker News
Syndiqué
Cybersécurité·

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order…

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek .

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Lire sur le site source
TAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
The Hacker News
Syndiqué
Cybersécurité·

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Friday Squid Blogging: Squid on a Stick at the New York State Fair

Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

IDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Using a VM to Contain an AI Agent

It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not…

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts,…

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek .

Lire sur le site source
TPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News
Syndiqué
Cybersécurité·

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure…

Lire sur le site source
TUS, Britain to coordinate on scam center takedowns
The Record
Syndiqué
Cybersécurité·

US, Britain to coordinate on scam center takedowns

The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]

Lire sur le site source
TPostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
The Hacker News
Syndiqué
Cybersécurité·

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical…

Lire sur le site source
TUK account-hack losses surge as new reporting system exposes hidden cases
The Record
Syndiqué
Cybersécurité·

UK account-hack losses surge as new reporting system exposes hidden cases

In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier.

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Microsoft says some users can’t open the Teams desktop client

Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries…

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Sangoma Switchvox Vulnerabilities Exploited in the Wild

Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]

Lire sur le site source
DAI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
Dark Reading
Syndiqué
Cybersécurité·

AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?

A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.

Lire sur le site source
TG7 urges organizations to prepare for quantum cyber threats
The Record
Syndiqué
Cybersécurité·

G7 urges organizations to prepare for quantum cyber threats

In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Exchange Online outage causes email delays, 'Server busy' errors

Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]

Lire sur le site source
DInsurers Search for Answers to Rein in Rogue AI
Dark Reading
Syndiqué
Cybersécurité·

Insurers Search for Answers to Rein in Rogue AI

As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek .

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Catch Raises $5 Million for AI Executive Assistant With Guardrails

Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The post Catch Raises $5 Million for AI Executive Assistant With Guardrails appeared first on SecurityWeek .

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

VMware Workstation and Fusion Updates Patch Critical Vulnerability

The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWeek .

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Security Vulnerability in a Voting System

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses…

Lire sur le site source
TUS offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure
The Record
Syndiqué
Cybersécurité·

US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure

Amir Yaryab is the leader of the IRGC's cyber unit and oversees hacker groups such as the CyberAv3ngers, the State Department said in posting a reward for information about him.

Lire sur le site source
DLarge Enterprises Targeted in Fake Merger & Acquisition Scams
Dark Reading
Syndiqué
Cybersécurité·

Large Enterprises Targeted in Fake Merger & Acquisition Scams

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.

Lire sur le site source
DWhat We Missed: Did ShinyHunters 'Breach' ReliaQuest?
Dark Reading
Syndiqué
Cybersécurité·

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

Lire sur le site source
DWhat the AI Warning Letter Completely Missed
Dark Reading
Syndiqué
Cybersécurité·

What the AI Warning Letter Completely Missed

The recent AI warning letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.

Lire sur le site source
DAI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
Dark Reading
Syndiqué
Cybersécurité·

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.

Lire sur le site source
D'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Dark Reading
Syndiqué
Cybersécurité·

'Breeze Comet' Tears Into Brazilian & Global Financial Systems

Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Researching Employment Scams

Researchers built a fake company to study fake employee scams .

Lire sur le site source
AI rented a car, and within hours, my driver's license was for sale
Ars Technica
Syndiqué
Cybersécurité·

I rented a car, and within hours, my driver's license was for sale

The FBI is reportedly investigating a massive data breach that is unfolding in real time.

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I…

Lire sur le site source
KFBI Probes Service Selling 153M+ Drivers Licenses
Krebs on Security
Syndiqué
Cybersécurité·

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving…

Lire sur le site source
AAuthorities arrest 2 alleged members of prolific hacking group TeamPCP
Ars Technica
Syndiqué
Cybersécurité·

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.

Lire sur le site source
KTwo Alleged ‘TeamPCP’ Hackers Arrested in Australia
Krebs on Security
Syndiqué
Cybersécurité·

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police…

Lire sur le site source
AMicrosoft Copilot reveals secret input that allowed it to be hacked
Ars Technica
Syndiqué
Cybersécurité·

Microsoft Copilot reveals secret input that allowed it to be hacked

Secret parameter allowed hackers to steal passwords when a target clicked on a link.

Lire sur le site source
KMicrosoft Plugs Nearly 400 Security Holes
Krebs on Security
Syndiqué
Cybersécurité·

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Lire sur le site source
KCanadian Man Pleads Guilty in Snowflake Extortions
Krebs on Security
Syndiqué
Cybersécurité·

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley…

Lire sur le site source

Les titres ci-dessous sont agrégés depuis des éditeurs indépendants et renvoient aux articles d'origine. Compare Robots n'est pas affilié à ces sources.

Sources cybersécurité

Les éditeurs indépendants que nous agrégeons, chacun lié à l'original.

BleepingComputer8The Hacker News7SecurityWeek7Dark Reading7Schneier on Security6The Record4Krebs on Security4Ars Technica301net1The Next Web1

Parcourir par thème