Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 18 septembre 2026Securité

Secure enterprise sharing with access reviews for Microsoft 365

18 septembre 2026 à 16:00
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

Webinar: Which Google Workspace security controls actually matter?

18 septembre 2026 à 15:10
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. [...]

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

18 septembre 2026 à 14:47
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

18 septembre 2026 à 13:01
In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it.  The new owner holds

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

18 septembre 2026 à 13:01
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

18 septembre 2026 à 12:40
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

Comment Claude Opus 5 a aidé des chercheurs à accéder aux dépôts internes d’OpenAI

18 septembre 2026 à 12:15

Une équipe de recherche en cybersécurité a exploité deux failles combinées pour accéder à des comptes d’employés d’OpenAI et atteindre les dépôts de code internes de l'entreprise, avec l'assistance de Claude Opus 5.

Kaspersky : des cybercriminels dissimulent un nouveau logiciel malveillant dans des torrents de films populaires, dont L’Odyssée

Par : UnderNews
18 septembre 2026 à 12:07

Plusieurs centaines de victimes ont déjà été identifiées parmi des utilisateurs particuliers et des organisations dans de nombreux pays. Tribune – L’équipe mondiale de recherche et d’analyse de Kaspersky (GReAT – Global Research and Analysis Team) a découvert une nouvelle campagne sophistiquée à plusieurs étapes ciblant à la fois des utilisateurs particuliers et des organisations.  […]

The post Kaspersky : des cybercriminels dissimulent un nouveau logiciel malveillant dans des torrents de films populaires, dont L’Odyssée first appeared on UnderNews.

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

18 septembre 2026 à 11:18
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

Mistral AI dément un piratage de son code source

18 septembre 2026 à 09:57

La licorne française a communiqué officiellement sur une revendication de piratage visant son code source, publiée la veille sur un forum cybercriminel. L'entreprise Mistral AI dément toute intrusion dans ses systèmes.

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

18 septembre 2026 à 08:17
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

17 septembre 2026 à 20:08
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

17 septembre 2026 à 19:32
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just

❌
❌