Skip to content
Rédaction

Cybersécurité

Fuites de données, vulnérabilités, malwares et ceux qui défendent.

49titres11sources internationales1articles maison
Suivre ce thème

Plus de titres

Syndiqué
DAttackers Pounce on Critical Artifactory Flaw Following Disclosure
Dark Reading
Syndiqué
Cybersécurité·

Attackers Pounce on Critical Artifactory Flaw Following Disclosure

CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

Lire sur le site source
DStronger Security Drives Ransomware Groups to Recruit From Within
Dark Reading
Syndiqué
Cybersécurité·

Stronger Security Drives Ransomware Groups to Recruit From Within

Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]

Lire sur le site source
DCritical Langflow Flaw Exploited as Attacks on AI Platform Rise
Dark Reading
Syndiqué
Cybersécurité·

Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

Lire sur le site source
TChina's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks
The Record
Syndiqué
Cybersécurité·

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

A hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Palo Alto Networks Acquires AI Agent Platform Console

The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek .

Lire sur le site source
DAI Model Evaluator METR Hit by Credential Theft, Probing
Dark Reading
Syndiqué
Cybersécurité·

AI Model Evaluator METR Hit by Credential Theft, Probing

In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Aesto Health says data breach affects over 9.5 million patients

Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Coast Guard Establishes Office of Maritime Cybersecurity Policy

The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime Cybersecurity Policy appeared first on SecurityWeek .

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]

Lire sur le site source
TAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
The Hacker News
Syndiqué
Cybersécurité·

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving…

Lire sur le site source
TBreeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
The Hacker News
Syndiqué
Cybersécurité·

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Leaked Russian Cyber-Operations Training Materials

This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […]…

Lire sur le site source
THealthcare facilities operator Nutex says patient, employee data stolen in August incident
The Record
Syndiqué
Cybersécurité·

Healthcare facilities operator Nutex says patient, employee data stolen in August incident

Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Novocure data breach affects more than 1,400 cancer patients

Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]

Lire sur le site source
T13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
The Hacker News
Syndiqué
Cybersécurité·

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS…

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Why Even the Best Edge Security Still Misses High-Risk Sessions

Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make…

Lire sur le site source
TIranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Hacker News
Syndiqué
Cybersécurité·

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote…

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek .

Lire sur le site source
TIranian cyber spies target aviation, fintech developers with new malware
The Record
Syndiqué
Cybersécurité·

Iranian cyber spies target aviation, fintech developers with new malware

In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.

Lire sur le site source
TCyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns
The Record
Syndiqué
Cybersécurité·

Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns

Andrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies.”

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Hackers Start Exploiting Critical Langflow Vulnerability

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek .

Lire sur le site source
TThreat Actors Don’t Want Better Attacks. They Want Repeatable Ones
The Hacker News
Syndiqué
Cybersécurité·

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique…

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek .

Lire sur le site source
S
SecurityWeek
Syndiqué
Cybersécurité·

Ransomware Gang Claims Nutex Health Data Breach

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek .

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Rewiring Democracy Series on The Renovator

Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator . I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about the Japanese digital democracy party,…

Lire sur le site source
B
BleepingComputer
Syndiqué
Cybersécurité·

Five Venezuelans plead guilty to ATM jackpotting attacks in US

Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]

Lire sur le site source
TRussia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
The Hacker News
Syndiqué
Cybersécurité·

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in…

Lire sur le site source
TAttackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
The Hacker News
Syndiqué
Cybersécurité·

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability…

Lire sur le site source
DAnthropic Users Hit by Infostealer Attacks, Session Thefts
Dark Reading
Syndiqué
Cybersécurité·

Anthropic Users Hit by Infostealer Attacks, Session Thefts

A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.

Lire sur le site source
TFive plead guilty in latest federal ATM jackpotting case
The Record
Syndiqué
Cybersécurité·

Five plead guilty in latest federal ATM jackpotting case

Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.

Lire sur le site source
D'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
Dark Reading
Syndiqué
Cybersécurité·

'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Is Someone Hacking DoD Refrigerators?

It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force Base , Calif., according to announcements made…

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Hiding Prompt Injection in Legal Filing

Someone hid AI instructions into a legal filing. Alternate link .

Lire sur le site source
S
Schneier on Security
Syndiqué
Cybersécurité·

Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

Ugh : A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squid.…

Lire sur le site source
AAuthorities arrest 2 alleged members of prolific hacking group TeamPCP
Ars Technica
Syndiqué
Cybersécurité·

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.

Lire sur le site source
KTwo Alleged ‘TeamPCP’ Hackers Arrested in Australia
Krebs on Security
Syndiqué
Cybersécurité·

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police…

Lire sur le site source
AMicrosoft Copilot reveals secret input that allowed it to be hacked
Ars Technica
Syndiqué
Cybersécurité·

Microsoft Copilot reveals secret input that allowed it to be hacked

Secret parameter allowed hackers to steal passwords when a target clicked on a link.

Lire sur le site source
AVulnerability giving attackers full control of Macs is under active exploitation
Ars Technica
Syndiqué
Cybersécurité·

Vulnerability giving attackers full control of Macs is under active exploitation

Screen-sharing bug lets remote hackers log in without a password.

Lire sur le site source
KMicrosoft Plugs Nearly 400 Security Holes
Krebs on Security
Syndiqué
Cybersécurité·

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Lire sur le site source

Les titres ci-dessous sont agrégés depuis des éditeurs indépendants et renvoient aux articles d'origine. Compare Robots n'est pas affilié à ces sources.

Sources cybersécurité

Les éditeurs indépendants que nous agrégeons, chacun lié à l'original.

BleepingComputer8SecurityWeek7Dark Reading7The Hacker News7Schneier on Security6The Record5Krebs on Security3Ars Technica301net1Interesting Engineering1The Register1

Parcourir par thème