Flux RSS

— Sources secondaires
141articles RSS
Reinitialiser
Is the FCC's Router Ban the Wrong Fix?
Gouvernance & RégulationDark Readingavant-hier

The agency put foreign-made consumer routers on its list of prohibited communications devices, but the ban could create more problems down the road.

Critical Flaw in Langflow AI Platform Under Attack
Gouvernance & RégulationDark Readingavant-hier

Threats actors pounced on the code injection vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.

China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
Gouvernance & RégulationThe Hacker Newsavant-hier

A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that's also tracked as Earth Bluecrow,

Hightower Holding Data Breach Impacts 130,000
Gouvernance & RégulationSecurityWeekavant-hier

The holdings company says hackers stole names, Social Security numbers, and driver’s license numbers from its environment. The post Hightower Holding Data Breach Impacts 130,000 appeared first on SecurityWeek.

BIND Updates Patch High-Severity Vulnerabilities
Vulnérabilités & PatchesSecurityWeekavant-hier

Specially crafted domains could be used to cause out-of-memory conditions, leading to memory leaks in the BIND resolvers. The post BIND Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek.

[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks
Gouvernance & RégulationThe Hacker Newsavant-hier

Most teams have security tools in place. Alerts are firing, dashboards look clean, threat intel is flowing in. On the surface, everything feels under control. But one question usually stays unanswered: Would your defenses actually stop a real attack? That’s where things get shaky. A control exists, so it’s assumed to work. A detection rule is active, so it’s expected to catch something. But very

Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
Gouvernance & RégulationThe Hacker Newsavant-hier

Cybersecurity researchers have disclosed a vulnerability in Anthropic's Claude Google Chrome Extension that could have been exploited to trigger malicious prompts simply by visiting a web page. The flaw "allowed any website to silently inject prompts into that assistant as if the user wrote them," Koi Security researcher Oren Yomtov said in a report shared with The Hacker News. "No clicks, no

Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure
Malware & RansomwareSecurityWeekavant-hier

The state-sponsored threat actor deployed kernel implants and passive backdoors enabling long-term, high-level espionage. The post Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure appeared first on SecurityWeek.

Cisco Patches Multiple Vulnerabilities in IOS Software
Gouvernance & RégulationSecurityWeekavant-hier

The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation. The post Cisco Patches Multiple Vulnerabilities in IOS Software appeared first on SecurityWeek.

Masters of Imitation: How Hackers and Art Forgers Perfect the Art of Deception
GénéralThe Hacker Newsavant-hier

Unmasking impostors is something the art world has faced for decades, and there are valuable lessons from the works of Elmyr de Hory that can apply to the world of defensive cybersecurity. During the 1960s, de Hory gained infamy as a premier forger, passing off counterfeit masterworks of Picasso, Matisse, and Renoir to unsuspecting collectors and renowned museums. Over the next several decades,

ThreatsDay Bulletin: PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More Stories
Gouvernance & RégulationThe Hacker Newsavant-hier

Some weeks in security feel loud. This one feels sneaky. Less big dramatic fireworks, more of that slow creeping sense that too many people are getting way too comfortable abusing things they probably shouldn’t even be touching. There’s a little bit of everything in this one, too. Weird delivery tricks, old problems coming back in slightly worse forms, shady infrastructure doing

Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in Recent Mass Attacks
Gouvernance & RégulationThe Hacker Newsavant-hier

The kernel exploit for two security vulnerabilities used in the recently uncovered Apple iOS exploit kit known as Coruna is an updated version of the same exploit that was used in the Operation Triangulation campaign back in 2023, according to new findings from Kaspersky. "When Coruna was first reported, the public evidence wasn't sufficient to link its code to Triangulation — shared

Alleged RedLine Malware Administrator Extradited to US
Malware & RansomwareSecurityWeekavant-hier

Hambardzum Minasyan of Armenia has been accused of being involved in the development and administration of the infostealer malware. The post Alleged RedLine Malware Administrator Extradited to US appeared first on SecurityWeek.

Commission preliminarily finds Pornhub, Stripchat, XNXX and XVideos in breach of the Digital Services Act for allowing minors to access their services
Gouvernance & RégulationEC Digital Strategyavant-hier

Commission preliminarily finds Pornhub, Stripchat, XNXX and XVideos in breach of the Digital Services Act for allowing minors to access their services Anonymous (not verified) Thu, 03/26/2026 - 09:39 The European Commission preliminarily found Pornhub, Stripchat, XNXX and XVideos in breach of the Digital Services Act (DSA) for failing to protect minors from being exposed to pornographic content on their services. In exercising their right of defence, XVideos, XNXX, Pornhub and Stripchat now have the possibility to examine the documents in the Commission's investigation files and reply in writing to the Commission's preliminary findings. Read the full press release and find further information about the: Digital Services Act - main aspects of the regulation User rights under the Digital Services Act - an overview Protecting and empowering young people online Supervision of the designated very large online platforms and search engines under DSA Related topics Better Internet for Children Strengthening trust and security Online platforms and e-commerce DSA - Digital Services Act {"service":"share","version":"2.0","color":true,"networks":["x","facebook","linkedin","email","more"]}