Flux RSS

— Sources secondaires
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Vulnérabilités & PatchesThe Hacker Newsil y a 14 heures

Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX's pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry. "The pipeline had a single boolean return value that meant both 'no scanners are configured' and 'all scanners failed to run,'" Koi

TP-Link Patches High-Severity Router Vulnerabilities
Vulnérabilités & PatchesSecurityWeekil y a 16 heures

The security defects could be used to bypass authentication, execute arbitrary commands, and decrypt configuration files. The post TP-Link Patches High-Severity Router Vulnerabilities appeared first on SecurityWeek.

Iran war drives urgent need  to counter underwater attack drones
Vulnérabilités & PatchesThe Register Securityil y a 17 heures

US and UK forces seeking tech tender with an April 3 deadline The UK and US are looking for technology to counter the threat posed by underwater drones to ships, harbors and other critical maritime infrastructure, and are asking industry for answers.…

CISA Flags Critical PTC Vulnerability That Had German Police Mobilized
Vulnérabilités & PatchesSecurityWeekil y a 19 heures

Police in Germany physically warned organizations about the critical PTC Windchill vulnerability tracked as CVE-2026-4681. The post CISA Flags Critical PTC Vulnerability That Had German Police Mobilized appeared first on SecurityWeek.

World Leaks data extortion: What you need to know
Fuites de donnéesGraham Cluleyhier

World Leaks is a cyber extortion operation that steals sensitive data from organizations and threatens to leak it via the dark web if a ransom is not paid. Read more in my article on the Fortra blog.

UK sanctions Xinbi marketplace linked to Asian scam centers
Fuites de donnéesBleepingComputeravant-hier

The United Kingdom's Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language cryptocurrency-based online marketplace that sells stolen data and satellite internet equipment to scam networks in Southeast Asia. [...]

BIND Updates Patch High-Severity Vulnerabilities
Vulnérabilités & PatchesSecurityWeekavant-hier

Specially crafted domains could be used to cause out-of-memory conditions, leading to memory leaks in the BIND resolvers. The post BIND Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek.

iOS, macOS 26.4 Roll Out With Fresh Security Patches
Vulnérabilités & PatchesSecurityWeekil y a 3 jours

Apple released security fixes for older devices as well, in iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, and macOS Sonoma 14.8.5. The post iOS, macOS 26.4 Roll Out With Fresh Security Patches appeared first on SecurityWeek.

Enterprise PCs are unreliable, unpatched, and unloved compared to Macs
Vulnérabilités & PatchesThe Register Securityil y a 3 jours

Omnissa telemetry suggests business buyers are loving Apple and Google End-user compute vendor Omnissa, the company formed by the spin-out of VMware’s virtual desktops, applications, and device management biz, has dug into the telemetry it collects from customers and painted a picture of the world’s enterprise hardware fleet – and the news is better for Google and Apple than it is for Microsoft.…

1K+ cloud environments infected following Trivy supply chain attack
Vulnérabilités & PatchesThe Register Securityil y a 3 jours

Crims 'creating a snowball effect' across open source projects RSAC 2026 Thousands of organizations' cloud environments have been infected with secret-stealing malware as a result of the Trivy supply-chain attack last week, and now the crims that compromised the open source scanners are working with notorious extortion crews like Lapsus$.…