Tech, mobile, IA, cybersécurité et culture numérique

Cybersecurite

A verifier

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that

Lire l’article complet
11/09 11:30 The Hacker News
A verifier

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. « These are Regular Maintenance Releases (MR)

Lire l’article complet
11/09 06:46 The Hacker News
A verifier

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass Origine de

Lire l’article complet
11/09 06:19 The Hacker News
A verifier

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (11 septembre 2026)

Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à l'intégrité des

Lire l’article complet
11/09 00:00 CERT-FR Avis
A verifier

Multiples vulnérabilités dans le noyau Linux de Debian LTS (11 septembre 2026)

Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni

Lire l’article complet
11/09 00:00 CERT-FR Avis
A verifier

Multiples vulnérabilités dans le noyau Linux de SUSE (11 septembre 2026)

Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à

Lire l’article complet
11/09 00:00 CERT-FR Avis
A verifier

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only « under specific conditions » that it has not described. One flaw affects Check Point’s Security Gateways, its firewall appliances. The other affects those

Lire l’article complet
10/09 11:45 The Hacker News
A verifier

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from « 45.142.193[.]132, » an IP address that has been

Lire l’article complet
10/09 11:41 The Hacker News
A verifier

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below – CVE-2026-20079 (CVSS score: 10.0) – An authentication Origine

Lire l’article complet
10/09 10:36 The Hacker News
A verifier

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway’s administrator credential. Anyone who holds it

Lire l’article complet
10/09 07:12 The Hacker News
Traduction