Flux RSS

— Sources secondaires
168articles RSS
Reinitialiser
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
Gouvernance & RégulationThe Hacker Newsil y a 3 jours

Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls. "Instead of the usual HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data," Sansec said in a report published this week. The attack,

PolyShell attacks target 56% of all vulnerable Magento stores
Vulnérabilités & PatchesBleepingComputeril y a 3 jours

Attacks leveraging the 'PolyShell' vulnerability in version 2 of Magento Open Source and Adobe Commerce installations are underway, targeting more than half of all vulnerable stores. [...]

LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace
Gouvernance & RégulationThe Hacker Newsil y a 4 jours

The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating and managing a criminal site that allowed stolen

Onit Security Raises $11 Million for Exposure Management Platform
Gouvernance & RégulationSecurityWeekil y a 4 jours

The startup will invest in product development and go-to-market efforts as it expands into new sectors. The post Onit Security Raises $11 Million for Exposure Management Platform appeared first on SecurityWeek.

AI Dominates RSAC Innovation Sandbox
GénéralDark Readingil y a 4 jours

Ten finalists will each have three minutes to make their case for being the most innovative, promising young security company of the year. Geordie AI wins the 2026 contest.

Russian Cybercriminal Gets 2-Year Prison Sentence in US
GénéralSecurityWeekil y a 4 jours

Ilya Angelov was a member of the cybercrime group tracked as TA-551, Shathak, Gold Cabin, Monster Libra, and ATK236. The post Russian Cybercriminal Gets 2-Year Prison Sentence in US appeared first on SecurityWeek.

GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data
Gouvernance & RégulationThe Hacker Newsil y a 4 jours

Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, and

Paid AI Accounts Are Now a Hot Underground Commodity
GénéralBleepingComputeril y a 4 jours

AI accounts are becoming part of the cybercrime supply chain, sold like email accounts or VPS access. Flare Systems shows how underground markets bundle and resell premium AI access at scale. [...]

iOS, macOS 26.4 Roll Out With Fresh Security Patches
Vulnérabilités & PatchesSecurityWeekil y a 4 jours

Apple released security fixes for older devices as well, in iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, and macOS Sonoma 14.8.5. The post iOS, macOS 26.4 Roll Out With Fresh Security Patches appeared first on SecurityWeek.