Veille cyber

Restez un pas devant les menaces : avis de sécurité, alertes et actualité cyber, agrégés en continu depuis les sources de référence.

135 publications · 10 sources · dernière collecte à l'instant

BleepingComputer ActuBleepingComputer Ninja Forms plugin flaw exploited to hack WordPress sitesHackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...] BleepingComputer ActuBleepingComputer Hackers exploit 32 zero-days on first day of Pwn2Own IrelandOn the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...] The Hacker News ActuThe Hacker News Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA CodesCybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.… The Hacker News ActuThe Hacker News Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and TaiwanLinux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious… CVE-2026-21589 ActuBleepingComputer Atlassian warns of critical file-access flaw in Jira, ConfluenceAtlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...] CVE-2026-21589BleepingComputer ActuBleepingComputer ASOS confirms data breach after “HACKED” in-app notificationsUK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...] BleepingComputer ActuBleepingComputer Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codesA new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...] SecurityWeek ActuSecurityWeek FBI Blames Contractor’s Missed Patch for ShinyHunters BreachThe FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek . BleepingComputer ActuBleepingComputer How to secure RMM software: 8 controls MSPs should testRMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery… SecurityWeek ActuSecurityWeek FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareAn alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek . CVE-2024-8176 AvisCISA · Advisories Hitachi Energy REB500View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to… CVE-2024-8176CVE-2025-59375CVE-2026-7395 AvisCISA · Advisories Hitachi Energy Asset SuiteView CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and… CVE-2026-7395CVE-2026-11796CVE-2026-27872 AvisCISA · Advisories Johnson Controls EasyIO FGView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware CVSS Vendor Equipment v3 7.7… CVE-2026-27872CVE-2026-27873CVE-2026-34197 AvisCISA · Advisories Hitachi Energy SOIView CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality,… CVE-2026-34197CVE-2026-15340 AvisCISA · Advisories Savannah lwIP SMTP clientView CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1… CVE-2026-15340CVE-2026-8065 AvisCISA · Advisories Hitachi Energy RTU500View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions… CVE-2026-8065CVE-2026-8066CVE-2026-8067The Hacker News ActuThe Hacker News LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro WarningsA malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only… SecurityWeek ActuSecurityWeek Apple to Tighten Full Disk Access Controls in macOS Amid AI RisksCiting growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks appeared first on SecurityWeek . BleepingComputer ActuBleepingComputer Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia editsThe Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...] The Hacker News ActuThe Hacker News Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesThe Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The…

Les titres et résumés appartiennent à leurs éditeurs respectifs ; chaque lien ouvre la publication d'origine.