Cybersécurité

Retrouvez toutes les actualités de cette catégorie dans une vue dédiée.

Cybersécurité

Retour aux actualités
WhatsApp says it disrupted new NSO spyware phishing attacks
CYBERSECURITY 08/06/2026 18:40

WhatsApp says it disrupted new NSO spyware phishing attacks

WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. [...]

Source: BleepingComputer

Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order
CYBERSECURITY 08/06/2026 17:08

Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order

Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group. In addition, the tech giant said it's filing a federal court contempt order against the company for violati

Source: The Hacker News

Gogs patches critical zero-day enabling remote code execution
CYBERSECURITY 08/06/2026 16:18

Gogs patches critical zero-day enabling remote code execution

Gogs has patched a critical security zero-day flaw that can allow attackers to compromise Internet-facing instances and access any repositories (including private ones). [...]

Source: BleepingComputer

Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
CYBERSECURITY 08/06/2026 14:17

Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups

Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The vulnerabilit

Source: The Hacker News

Critical UniFi OS bug lets hackers gain root without authentication
CYBERSECURITY 08/06/2026 15:51

Critical UniFi OS bug lets hackers gain root without authentication

Attackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication. [...]

Source: BleepingComputer

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
CYBERSECURITY 08/06/2026 13:19

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

Phishing has always been a numbers game. AI has turned it into a volume machine. Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for

Source: The Hacker News

Reducing security operations complexity with Wazuh Cloud
CYBERSECURITY 08/06/2026 14:01

Reducing security operations complexity with Wazuh Cloud

Security teams are increasingly overwhelmed by alert fatigue, infrastructure maintenance, and complex hybrid environments. This article explores how Wazuh Cloud helps simplify SIEM/XDR operations through managed infrastr

Source: BleepingComputer

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
CYBERSECURITY 08/06/2026 13:18

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More

Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked. A chatbot got fooled. A bot to

Source: The Hacker News

Check Point links VPN zero-day attacks to Qilin ransomware gang
CYBERSECURITY 08/06/2026 13:05

Check Point links VPN zero-day attacks to Qilin ransomware gang

Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...]

Source: BleepingComputer

The Hardest Fork
CYBERSECURITY 08/06/2026 11:53

The Hardest Fork

Mythos is real. I know a big chunk of the industry thinks it's a marketing stunt, and I get why. I get it. But I've seen the findings, and they're bad. These aren't "whoops, this line right here is wrong, and that's RCE.

Source: The Hacker News

Oxford University discloses data breach after careers platform hack
CYBERSECURITY 08/06/2026 11:14

Oxford University discloses data breach after careers platform hack

The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. [...]

Source: BleepingComputer

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
CYBERSECURITY 08/06/2026 10:27

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux syst

Source: The Hacker News

Over 20,000 Instagram accounts stolen in Meta AI support hack
CYBERSECURITY 08/06/2026 06:00

Over 20,000 Instagram accounts stolen in Meta AI support hack

Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]

Source: BleepingComputer

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
CYBERSECURITY 08/06/2026 07:39

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between J

Source: The Hacker News

Hands on with Intelligent Terminal, an AI-powered Windows Terminal
CYBERSECURITY 07/06/2026 23:20

Hands on with Intelligent Terminal, an AI-powered Windows Terminal

Microsoft has created an open-source fork of Windows Terminal called "Intelligent Terminal," and it allows you to use AI directly inside Terminal without interfering with the regular session. [...]

Source: BleepingComputer

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
CYBERSECURITY 08/06/2026 06:08

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackl

Source: The Hacker News

C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
CYBERSECURITY 07/06/2026 14:17

C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]

Source: BleepingComputer

New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
CYBERSECURITY 06/06/2026 13:36

New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and

Source: The Hacker News

Silent Ransom Group targets law firms with fake IT support calls
CYBERSECURITY 07/06/2026 14:09

Silent Ransom Group targets law firms with fake IT support calls

The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according t

Source: BleepingComputer

Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
CYBERSECURITY 06/06/2026 08:29

Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic for a data busi

Source: The Hacker News

Critical Everest Forms Pro flaw exploited to take over WordPress sites
CYBERSECURITY 06/06/2026 14:09

Critical Everest Forms Pro flaw exploited to take over WordPress sites

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]

Source: BleepingComputer

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
CYBERSECURITY 06/06/2026 08:14

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catal

Source: The Hacker News

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
CYBERSECURITY 06/06/2026 07:28

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an a

Source: The Hacker News

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
CYBERSECURITY 06/06/2026 06:58

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organi

Source: The Hacker News