Flux RSS

— Sources secondaires
Fake VS Code alerts on GitHub spread malware to developers
Gouvernance & RégulationBleepingComputeril y a 16 heures

A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code (VS Code) security alerts posted in the Discussions section of various projects, to trick users into downloading malware. [...]

OpenAI Launches Bug Bounty Program for Abuse and Safety Risks
Gouvernance & RégulationSecurityWeekil y a 19 heures

Through the new program, OpenAI will reward reports covering design or implementation issues leading to material harm. The post OpenAI Launches Bug Bounty Program for Abuse and Safety Risks appeared first on SecurityWeek.

AFC Ajax drops ball as flaws let hackers play admin with tickets and bans
Gouvernance & RégulationThe Register Securityil y a 20 heures

Vulns in Dutch football club's systems didn't just expose data – they let outsiders play with accounts, and even lift stadium bans Dutch football giant AFC Ajax has admitted to a data breach after an attacker gained access to its internal systems, in an incident that looks less like a stray pass and more like the gates left wide open.…

Coruna iOS Exploit Kit Likely an Update to Operation Triangulation
Gouvernance & RégulationSecurityWeekil y a 22 heures

Coruna contains the updated version of a kernel exploit used in Operation Triangulation three years ago. The post Coruna iOS Exploit Kit Likely an Update to Operation Triangulation appeared first on SecurityWeek.

Security boffins scoured the web and found hundreds of valid API keys
Gouvernance & RégulationThe Register Securityhier

Global bank's devs have some cleaning up to do after cloud creds found in website code Computer security boffins have conducted an analysis of 10 million websites and found almost 2,000 API credentials strewn across 10,000 webpages.…

CISA: New Langflow flaw actively exploited to hijack AI workflows
Gouvernance & RégulationBleepingComputeravant-hier

The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agents. [...]

Hightower Holding Data Breach Impacts 130,000
Gouvernance & RégulationSecurityWeekavant-hier

The holdings company says hackers stole names, Social Security numbers, and driver’s license numbers from its environment. The post Hightower Holding Data Breach Impacts 130,000 appeared first on SecurityWeek.

Cisco Patches Multiple Vulnerabilities in IOS Software
Gouvernance & RégulationSecurityWeekavant-hier

The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation. The post Cisco Patches Multiple Vulnerabilities in IOS Software appeared first on SecurityWeek.

Brit lawmaker targeted by AI deepfake fails to get answers from US Big Tech
Gouvernance & RégulationThe Register Securityavant-hier

Appearing before Parliament, Meta, Google and X struggle to explain how fake political video circulated for so long A member of the UK Parliament's lower house who was the victim of a deepfake AI campaign this week had a rare chance to confront the Big Tech executives who helped spread it. Their answers disappointed.…

UK wants to know if banning under-16s from social media does anything useful
Gouvernance & RégulationThe Register Securityavant-hier

300 families undergo 6-week trial to test impact on sleep, school, and home life The UK government will trial different levels of restrictions on social media for under-16s with the help of 300 families, alongside a public consultation that has already gathered nearly 30,000 responses.…

Scammers have virtual smartphones on speed dial for fraud
Gouvernance & RégulationThe Register Securityil y a 3 jours

They cleverly mimic most traits of a real phone Smartphones have fast become the basis of our digital identities, securing payment systems and bank accounts. Now virtual devices that pretend to be real handsets have become a key tool for financial scammers, according to one company. …

Onit Security Raises $11 Million for Exposure Management Platform
Gouvernance & RégulationSecurityWeekil y a 3 jours

The startup will invest in product development and go-to-market efforts as it expands into new sectors. The post Onit Security Raises $11 Million for Exposure Management Platform appeared first on SecurityWeek.

EFF has a new boss to lead the fight against privacy-sucking forces of doom
Gouvernance & RégulationThe Register Securityil y a 3 jours

Cyber rights org retools for the days of AI and unrestrained government interview The Electronic Frontier Foundation (EFF) on Tuesday appointed Nicole Ozer to succeed Cindy Cohn as the cyber rights group's executive director when Cohn departs this summer.…

HackerOne slams supplier for delayed breach notice after staff data exposed
Gouvernance & RégulationThe Register Securityil y a 4 jours

Nearly 300 employees caught up in intrusion at benefits provider Navia Almost 300 HackerOne employees are caught up in a data breach, with the bug bounty biz slamming a third-party benefits provider for a weeks-long delay in notification.…

Lightning-fast exploits make it essential to patch fast, ask questions later
Gouvernance & RégulationThe Register Securityil y a 5 jours

Here's where you ought to spend your security billable hours budget this year Strengthen your MFA policies, double-down on anti-phishing training, and for Jobs' sake, patch all your vulns right away. The past year of intelligence collected by Cisco's Talos threat hunters suggests that attackers are moving faster to exploit vulns, and fooling more staff than ever into giving up their credentials. …

Cryptographers engage in war of words over RustSec bug reports and subsequent ban
Gouvernance & RégulationThe Register Securityil y a 7 jours

Rust security maintainers contend Nadim Kobeissi's vulnerability claims are too much Updated Since February, cryptographer Nadim Kobeissi has been trying to get code fixes applied to Rust cryptography libraries to address what he says are critical bugs. For his efforts, he's been dismissed, ignored, and banned from Rust security channels.…