Skip to content
Rédaction

Cybersécurité

Fuites de données, vulnérabilités, malwares et ceux qui défendent.

57titres16sources internationales1articles maison
Suivre ce thème

Plus de titres

Syndiqué
DSonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
Dark Reading
Syndiqué
Cybersécurité·

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

Lire sur le site source
AI rented a car, and within hours, my driver's license was for sale
Ars Technica
Syndiqué
Cybersécurité·

I rented a car, and within hours, my driver's license was for sale

The FBI is reportedly investigating a massive data breach that is unfolding in real time.

Lire sur le site source
DAI Gives Cybercriminals a Dangerous Time Advantage
Dark Reading
Syndiqué
Cybersécurité·

AI Gives Cybercriminals a Dangerous Time Advantage

Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

OpenLeash Adds a Human Check to Risky AI Agent Actions

The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek .

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]

Lire sur le site source
TMore than 9.5 million patient records affected by Aesto Health data breach: what you need to know
Tom's Guide
Syndiqué
Cybersécurité·

More than 9.5 million patient records affected by Aesto Health data breach: what you need to know

Aesto Health has confirmed a data breach that affects more than 9.5 million patients.

Lire sur le site source
LActualité : Parkside, Silvercrest : Lidl construit une flotte de cargos pour garder ses prix bas
Les Numériques
Syndiqué
Cybersécurité·

Actualité : Parkside, Silvercrest : Lidl construit une flotte de cargos pour garder ses prix bas

Lidl, ce sont surtout des magasins mais aussi des cargos depuis peu. Le leader du hard-discount exploite 11 porte-conteneurs et cinq de plus sont déjà sur son carnet de commandes. Mais alors pourquoi la chaîne de supermarchés investit autant dans le maritime ? On vous explique…

Lire sur le site source
TRussian national facing 20 years for malware campaign that infected 80,000 freelancers
The Record
Syndiqué
Cybersécurité·

Russian national facing 20 years for malware campaign that infected 80,000 freelancers

Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week.

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I…

Lire sur le site source
TAI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
The Register
Syndiqué
Cybersécurité·

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

Adding insult to injury

Lire sur le site source
TInfosec pros say we're not ready to lose control of AI
The Register
Syndiqué
Cybersécurité·

Infosec pros say we're not ready to lose control of AI

Nearly two-thirds of US national security pros surveyed believe AI risks, and government posture toward them, are unacceptable

Lire sur le site source
THealth data of more than 9.5 million people leaked from Aesto record system
The Record
Syndiqué
Cybersécurité·

Health data of more than 9.5 million people leaked from Aesto record system

The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.

Lire sur le site source
DThreat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
Dark Reading
Syndiqué
Cybersécurité·

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

Lire sur le site source
TFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
Syndiqué
Cybersécurité·

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and…

Lire sur le site source
01 million d’ordinateurs piratés : ce gigantesque botnet russe a fait des ravages pendant plus de 20 ans !
01net
Syndiqué
Cybersécurité·

1 million d’ordinateurs piratés : ce gigantesque botnet russe a fait des ravages pendant plus de 20 ans !

Actif depuis plus de vingt ans, un mystérieux botnet russe vient de cesser ses activités. Le réseau criminel a été neutralisé lors d'une opération internationale impliquant Europol, le FBI et les polices de plusieurs pays. Avant de disparaître, le botnet a infecté plus d'un…

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek .

Lire sur le site source
TNew pro-Ukraine hacker group targets Russian companies with custom ransomware
The Record
Syndiqué
Cybersécurité·

New pro-Ukraine hacker group targets Russian companies with custom ransomware

The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.

Lire sur le site source
TRussian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole victims' data via remote access
Tom's Hardware
Syndiqué
Cybersécurité·

Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole victims' data via remote access

Russian national faces US charges over a phishing campaign that allegedly infected 80,000 PCs and stole credentials and personal data

Lire sur le site source
TMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
The Hacker News
Syndiqué
Cybersécurité·

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the…

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]

Lire sur le site source
TBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
Syndiqué
Cybersécurité·

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked…

Lire sur le site source
THackers expose donor data from Russian fundraisers for Ukrainians, political prisoners
The Record
Syndiqué
Cybersécurité·

Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners

Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information.

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek .

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Dropbox accounts breached through Lenovo email verification flaw

Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]

Lire sur le site source
TMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
The Hacker News
Syndiqué
Cybersécurité·

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said…

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Exploit Published for Fresh Cleo Harmony Vulnerability

The security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek .

Lire sur le site source
TSality, one of the longest-running botnets, finally gets disrupted
The Record
Syndiqué
Cybersécurité·

Sality, one of the longest-running botnets, finally gets disrupted

U.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators.

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Malicious Virtualizor Update Served via BGP Hijacking

Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek .

Lire sur le site source
THow to Secure Enterprise AI: From Adoption to Incident Readiness
The Hacker News
Syndiqué
Cybersécurité·

How to Secure Enterprise AI: From Adoption to Incident Readiness

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of…

Lire sur le site source
TAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
The Hacker News
Syndiqué
Cybersécurité·

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are…

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days

The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days appeared first on SecurityWeek .

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Microsoft Defender flags legitimate Google search links as malicious

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Chrome and Firefox Updates Patch Dozens of Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

US charges Russian for infecting 80,000 freelancers with malware

A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Sality botnet infrastructure dismantled in joint global takedown

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]

Lire sur le site source
DOld, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Dark Reading
Syndiqué
Cybersécurité·

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.

Lire sur le site source
KFBI Probes Service Selling 153M+ Drivers Licenses
Krebs on Security
Syndiqué
Cybersécurité·

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it…

Lire sur le site source
DAttackers Pounce on Critical Artifactory Bug Following Disclosure
Dark Reading
Syndiqué
Cybersécurité·

Attackers Pounce on Critical Artifactory Bug Following Disclosure

CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

Lire sur le site source
DStronger Security Drives Ransomware Groups to Recruit From Within
Dark Reading
Syndiqué
Cybersécurité·

Stronger Security Drives Ransomware Groups to Recruit From Within

Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.

Lire sur le site source
DCritical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
Dark Reading
Syndiqué
Cybersécurité·

Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Leaked Russian Cyber-Operations Training Materials

This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […]…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Rewiring Democracy Series on The Renovator

Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator . I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about the Japanese digital democracy party,…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Is Someone Hacking DoD Refrigerators?

It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force Base , Calif., according to announcements made…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Hiding Prompt Injection in Legal Filing

Someone hid AI instructions into a legal filing. Alternate link .

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

Ugh : A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squid.…

Lire sur le site source
AAuthorities arrest 2 alleged members of prolific hacking group TeamPCP
Ars Technica
Syndiqué
Cybersécurité·

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.

Lire sur le site source
KTwo Alleged ‘TeamPCP’ Hackers Arrested in Australia
Krebs on Security
Syndiqué
Cybersécurité·

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police…

Lire sur le site source
AMicrosoft Copilot reveals secret input that allowed it to be hacked
Ars Technica
Syndiqué
Cybersécurité·

Microsoft Copilot reveals secret input that allowed it to be hacked

Secret parameter allowed hackers to steal passwords when a target clicked on a link.

Lire sur le site source
KMicrosoft Plugs Nearly 400 Security Holes
Krebs on Security
Syndiqué
Cybersécurité·

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Lire sur le site source

Les titres ci-dessous sont agrégés depuis des éditeurs indépendants et renvoient aux articles d'origine. Compare Robots n'est pas affilié à ces sources.

Sources cybersécurité

Les éditeurs indépendants que nous agrégeons, chacun lié à l'original.

Dark Reading8BleepingComputer8SecurityWeek7Schneier on Security7The Hacker News6The Record5Ars Technica3Krebs on Security3Tom's Guide2The Register2The Next Web1Gizmodo1Engadget1Les Numériques101net1Tom's Hardware1

Parcourir par thème