Ultimate PocketCybersecurite
A verifier
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million « upon entry of an
Lire l’article complet
A verifier
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. « When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process, » TrendAI, Trend Micro’s Origine
Lire l’article complet
A verifier
OWASP Flags Top AI Skill Risks in New Security Blueprint
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons. Origine de l’article : lire l’article original
Lire l’article complet
A verifier
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal
Lire l’article complet
A verifier
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. « The malware spread
Lire l’article complet
A verifier
Calling on Cyber Pros to Help Defend City Hall
Government agencies with smaller budgets need support — and here’s how you can help. Origine de l’article : lire l’article original
Lire l’article complet
A verifier
Calling on Cyber Pros to Help Defend City Hall
Government agencies with smaller budgets need support — and here’s how you can help. Origine de l’article : lire l’article original
Lire l’article complet
A verifier
OpenAI Adds Controls That Should've Been There Already
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping. Origine de l’article : lire l’article original
Lire l’article complet
A verifier
Wazuh and AI For Enhanced SOC Workflows
Artificial Intelligence (AI) has become one of this decade’s defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate Origine de l’article : lire
Lire l’article complet
A verifier
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below –
Lire l’article complet
A verifier
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without
Lire l’article complet
A verifier
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the « Exploited » field under the Exploitability Assessment table as « Yes, » on August 21, 2026, Microsoft corrected the « Exploited » status to « No » after The Hacker News contacted the company for comment. It also noted,
Lire l’article completMultiples vulnérabilités dans Traefik (21 août 2026)
Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. De multiples vulnérabilités ont été découvertes dans Traefik. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité. Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs
Lire l’article completMultiples vulnérabilités dans les produits Microsoft (21 août 2026)
Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un déni de service. Se référer au bulletin de sécurité de
Lire l’article completMultiples vulnérabilités dans Microsoft Edge (21 août 2026)
Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs
Lire l’article completVulnérabilité dans Microsoft Office (21 août 2026)
Agence nationalede la sécurité dessystèmes d'information Une gestion de version détaillée se trouve à la fin de ce document. Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données. Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section
Lire l’article complet
A verifier
New CUSTODY Framework Constrains AI Agents Inside the Network
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face. Origine de l’article : lire l’article original
Lire l’article complet
A verifier
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Lire l’article complet
A verifier
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. « These clusters engage in persistent, adaptive Origine
Lire l’article complet
A verifier
What We Missed: Delta Flight Disrupted With Wi-Fi Hack
In this video, Dark Reading editors discuss some of the news they didn’t get a chance to cover, including some scary airplane security risks and the US government’s newest "hack back" strategy. Origine de l’article : lire l’article original
Lire l’article complet
A verifier
N-able Bug Exposes Password Vault Master Keys
The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely? Origine de l’article : lire l’article original
Lire l’article complet
A verifier
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress. Origine de l’article : lire l’article original
Lire l’article complet
A verifier
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the
Lire l’article complet
A verifier
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an « active threat » targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That Origine de l’article : lire l’article original
Lire l’article complet