Tech, mobile, IA, cybersécurité et culture numérique

Cybersecurite

A verifier

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and

Lire l’article complet
05/10 11:55 The Hacker News
A verifier

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. « Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel, » Nozomi Networks said in

Lire l’article complet
05/10 11:46 The Hacker News
A verifier

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it’s taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. « Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing

Lire l’article complet
05/10 10:38 The Hacker News
A verifier

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then

Lire l’article complet
05/10 08:09 The Hacker News
A verifier

Multiples vulnérabilités dans Google Chrome (05 octobre 2026)

Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs

Lire l’article complet
05/10 00:00 CERT-FR Avis
A verifier

Vulnérabilité dans Microsoft Exchange Server (05 octobre 2026)

Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. Une vulnérabilité a été découverte dans Microsoft Exchange Server. Elle permet à un attaquant de provoquer une élévation de privilèges. Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Origine

Lire l’article complet
05/10 00:00 CERT-FR Avis
A verifier

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias « Rey, » has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with

Lire l’article complet
04/10 07:22 The Hacker News
A verifier

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert

Lire l’article complet
04/10 07:20 The Hacker News
A verifier

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The U.K.’s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing’s state security service. In a « Security Service Espionage Alert » issued on September 30, 2026, MI5 said the « primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is

Lire l’article complet
03/10 14:38 The Hacker News
A verifier

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. « In the Origine de l’article

Lire l’article complet
03/10 14:36 The Hacker News
A verifier

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of Origine de l’article

Lire l’article complet
03/10 11:00 The Hacker News
A verifier

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

Lire l’article complet
02/10 17:33 The Hacker News
A verifier

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below – CVE-2026-63688 (CVSS score: 10.0) – A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an Origine

Lire l’article complet
02/10 17:02 The Hacker News
Traduction