Flux RSS

— Sources secondaires
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Vulnérabilités & PatchesThe Hacker Newsil y a 14 heures

Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX's pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry. "The pipeline had a single boolean return value that meant both 'no scanners are configured' and 'all scanners failed to run,'" Koi

TP-Link Patches High-Severity Router Vulnerabilities
Vulnérabilités & PatchesSecurityWeekil y a 16 heures

The security defects could be used to bypass authentication, execute arbitrary commands, and decrypt configuration files. The post TP-Link Patches High-Severity Router Vulnerabilities appeared first on SecurityWeek.

Iran war drives urgent need  to counter underwater attack drones
Vulnérabilités & PatchesThe Register Securityil y a 17 heures

US and UK forces seeking tech tender with an April 3 deadline The UK and US are looking for technology to counter the threat posed by underwater drones to ships, harbors and other critical maritime infrastructure, and are asking industry for answers.…

CISA Flags Critical PTC Vulnerability That Had German Police Mobilized
Vulnérabilités & PatchesSecurityWeekil y a 19 heures

Police in Germany physically warned organizations about the critical PTC Windchill vulnerability tracked as CVE-2026-4681. The post CISA Flags Critical PTC Vulnerability That Had German Police Mobilized appeared first on SecurityWeek.

BIND Updates Patch High-Severity Vulnerabilities
Vulnérabilités & PatchesSecurityWeekavant-hier

Specially crafted domains could be used to cause out-of-memory conditions, leading to memory leaks in the BIND resolvers. The post BIND Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek.

Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure
Malware & RansomwareSecurityWeekavant-hier

The state-sponsored threat actor deployed kernel implants and passive backdoors enabling long-term, high-level espionage. The post Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure appeared first on SecurityWeek.

Suspected RedLine infostealer malware admin extradited to US
Malware & RansomwareBleepingComputeravant-hier

An Armenian suspect was extradited to the United States to face criminal charges for allegedly helping manage RedLine, one of the most prolific infostealer malware operations in recent years. [...]

Alleged RedLine Malware Administrator Extradited to US
Malware & RansomwareSecurityWeekavant-hier

Hambardzum Minasyan of Armenia has been accused of being involved in the development and administration of the infostealer malware. The post Alleged RedLine Malware Administrator Extradited to US appeared first on SecurityWeek.