Veille cyber
Restez un pas devant les menaces : avis de sécurité, alertes et actualité cyber, agrégés en continu depuis les sources de référence.
135 publications · 10 sources · dernière collecte il y a 2 h
CVE-2026-21589
Atlassian warns of critical file-access flaw in Jira, ConfluenceAtlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
BleepingComputer
ASOS confirms data breach after “HACKED” in-app notificationsUK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
BleepingComputer
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codesA new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
SecurityWeek
FBI Blames Contractor’s Missed Patch for ShinyHunters BreachThe FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek .
BleepingComputer
How to secure RMM software: 8 controls MSPs should testRMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery…
SecurityWeek
FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareAn alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek .
CVE-2024-8176
Hitachi Energy REB500View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to…
CVE-2026-7395
Hitachi Energy Asset SuiteView CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and…
CVE-2026-27872
Johnson Controls EasyIO FGView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware CVSS Vendor Equipment v3 7.7…
CVE-2026-34197
Hitachi Energy SOIView CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality,…
CVE-2026-15340
Savannah lwIP SMTP clientView CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1…
CVE-2026-8065
Hitachi Energy RTU500View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions…
The Hacker News
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro WarningsA malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only…
SecurityWeek
Apple to Tighten Full Disk Access Controls in macOS Amid AI RisksCiting growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks appeared first on SecurityWeek .
BleepingComputer
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia editsThe Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]
The Hacker News
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesThe Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The…
The Hacker News
Welcome to the Jungle: What We Found Inside 15,465 Public MCP ServersIn 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.…
SecurityWeek
Cybersecurity M&A Roundup: 39 Deals Announced in September 2026Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind. The post Cybersecurity M&A Roundup: 39 Deals Announced in September 2026 appeared first on SecurityWeek .
SecurityWeek
Long-Running NPM Malware Campaign Accumulates 40,000 DownloadsSince August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek .
SecurityWeek
8.8 Million Impacted by Data Breach at Denmark’s Central Person RegisterHackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens. The post 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register appeared first on SecurityWeek .
Atlassian warns of critical file-access flaw in Jira, ConfluenceAtlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
BleepingComputer
ASOS confirms data breach after “HACKED” in-app notificationsUK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
BleepingComputer
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codesA new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
SecurityWeek
FBI Blames Contractor’s Missed Patch for ShinyHunters BreachThe FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek .
BleepingComputer
How to secure RMM software: 8 controls MSPs should testRMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery…
SecurityWeek
FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareAn alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek .
CVE-2024-8176
Hitachi Energy REB500View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to…
CVE-2026-7395
Hitachi Energy Asset SuiteView CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and…
CVE-2026-27872
Johnson Controls EasyIO FGView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware CVSS Vendor Equipment v3 7.7…
CVE-2026-34197
Hitachi Energy SOIView CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality,…
CVE-2026-15340
Savannah lwIP SMTP clientView CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1…
CVE-2026-8065
Hitachi Energy RTU500View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions…
The Hacker News
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro WarningsA malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only…
SecurityWeek
Apple to Tighten Full Disk Access Controls in macOS Amid AI RisksCiting growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks appeared first on SecurityWeek .
BleepingComputer
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia editsThe Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]
The Hacker News
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesThe Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The…
The Hacker News
Welcome to the Jungle: What We Found Inside 15,465 Public MCP ServersIn 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.…
SecurityWeek
Cybersecurity M&A Roundup: 39 Deals Announced in September 2026Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind. The post Cybersecurity M&A Roundup: 39 Deals Announced in September 2026 appeared first on SecurityWeek .
SecurityWeek
Long-Running NPM Malware Campaign Accumulates 40,000 DownloadsSince August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek .
SecurityWeek
8.8 Million Impacted by Data Breach at Denmark’s Central Person RegisterHackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens. The post 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register appeared first on SecurityWeek .
Les titres et résumés appartiennent à leurs éditeurs respectifs ; chaque lien ouvre la publication d'origine.
