Veille cyber
Restez un pas devant les menaces : avis de sécurité, alertes et actualité cyber, agrégés en continu depuis les sources de référence.
135 publications · 10 sources · dernière collecte à l'instant
BleepingComputer
Ninja Forms plugin flaw exploited to hack WordPress sitesHackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
BleepingComputer
Hackers exploit 32 zero-days on first day of Pwn2Own IrelandOn the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]
The Hacker News
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA CodesCybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.…
The Hacker News
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and TaiwanLinux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious…
CVE-2026-21589
Atlassian warns of critical file-access flaw in Jira, ConfluenceAtlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
BleepingComputer
ASOS confirms data breach after “HACKED” in-app notificationsUK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
BleepingComputer
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codesA new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
SecurityWeek
FBI Blames Contractor’s Missed Patch for ShinyHunters BreachThe FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek .
BleepingComputer
How to secure RMM software: 8 controls MSPs should testRMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery…
SecurityWeek
FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareAn alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek .
CVE-2024-8176
Hitachi Energy REB500View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to…
CVE-2026-7395
Hitachi Energy Asset SuiteView CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and…
CVE-2026-27872
Johnson Controls EasyIO FGView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware CVSS Vendor Equipment v3 7.7…
CVE-2026-34197
Hitachi Energy SOIView CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality,…
CVE-2026-15340
Savannah lwIP SMTP clientView CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1…
CVE-2026-8065
Hitachi Energy RTU500View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions…
The Hacker News
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro WarningsA malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only…
SecurityWeek
Apple to Tighten Full Disk Access Controls in macOS Amid AI RisksCiting growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks appeared first on SecurityWeek .
BleepingComputer
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia editsThe Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]
The Hacker News
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesThe Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The…
Ninja Forms plugin flaw exploited to hack WordPress sitesHackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
BleepingComputer
Hackers exploit 32 zero-days on first day of Pwn2Own IrelandOn the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]
The Hacker News
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA CodesCybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.…
The Hacker News
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and TaiwanLinux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious…
CVE-2026-21589
Atlassian warns of critical file-access flaw in Jira, ConfluenceAtlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
BleepingComputer
ASOS confirms data breach after “HACKED” in-app notificationsUK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
BleepingComputer
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codesA new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
SecurityWeek
FBI Blames Contractor’s Missed Patch for ShinyHunters BreachThe FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek .
BleepingComputer
How to secure RMM software: 8 controls MSPs should testRMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery…
SecurityWeek
FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareAn alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek .
CVE-2024-8176
Hitachi Energy REB500View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to…
CVE-2026-7395
Hitachi Energy Asset SuiteView CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and…
CVE-2026-27872
Johnson Controls EasyIO FGView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware CVSS Vendor Equipment v3 7.7…
CVE-2026-34197
Hitachi Energy SOIView CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality,…
CVE-2026-15340
Savannah lwIP SMTP clientView CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1…
CVE-2026-8065
Hitachi Energy RTU500View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions…
The Hacker News
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro WarningsA malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only…
SecurityWeek
Apple to Tighten Full Disk Access Controls in macOS Amid AI RisksCiting growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks appeared first on SecurityWeek .
BleepingComputer
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia editsThe Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]
The Hacker News
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesThe Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The…
Les titres et résumés appartiennent à leurs éditeurs respectifs ; chaque lien ouvre la publication d'origine.
