Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Hier — 1 août 2026Flux principal

Arch Linux freezes AUR package adoptions after malware wave

Par : IT News
1 août 2026 à 12:57
Arch Linux freezes AUR package adoptions after malware wave
Arch Linux has temporarily frozen package adoptions in the Arch User Repository (AUR) after attackers used maintainer takeovers and orphaned packages to push malicious updates. The campaign reportedly affects dozens of packages and delivers a Linux infostealer with remote access and SSH-worm capabilities.

Source

Hijacked hotel Wi-Fi pushes fake browser updates delivering CornFlake RAT

Par : IT News
1 août 2026 à 12:57
Hijacked hotel Wi-Fi pushes fake browser updates delivering CornFlake RAT
Attackers are using compromised hotel and conference-center Wi-Fi gateways to redirect guests to fake browser or operating-system updates. The campaign delivers CornFlake, a surveillance-focused remote access trojan attributed by Microsoft to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard.

Source

Security and AI expert dismisses concerns about autonomous AI hacking as exaggerated

Par : IT News
31 juillet 2026 à 21:52
Security and AI expert dismisses concerns about autonomous AI hacking as exaggerated
Snehal Antani, CEO of Horizon3.ai, a cybersecurity firm that uses AI to autonomously probe organizations for real-world vulnerabilities, argues that claims of AI models hacking companies on their own are overstated. Currently, these systems perform well in controlled cyber range tests but face challenges against defended and deceptive production networks. Their limitations include greedy decision-making, poor adaptation in protected environments, overdependence on limited training data, and a tendency to interact with suspicious decoys even after recognizing them as traps. Nonetheless, the threat continues to grow as human hackers have access to virtually unlimited "AI interns" for uncovering vulnerabilities. Additionally, the rapid rise of vibe-coded applications and AI agents is expanding the pool of insecure systems vulnerable to attack.

Source

À partir d’avant-hierFlux principal

Azure makes CIS auditing native for Linux VMs

Par : IT News
31 juillet 2026 à 17:41
Azure makes CIS auditing native for Linux VMs
Microsoft has made native CIS Benchmark auditing generally available for Linux virtual machines, eliminating the need for separate compliance tools. Azure Machine Configuration now continuously checks Azure and Azure Arc-enabled Linux systems against CIS-certified benchmarks and surfaces the results through Azure management services.

Source

OpenAI maps its Frontier Governance Framework to the EU AI Act

Par : IT News
31 juillet 2026 à 17:41
OpenAI maps its Frontier Governance Framework to the EU AI Act
OpenAI has endorsed the EU’s voluntary GPAI Code of Practice and its transparency code for AI-generated content, while detailing how its internal governance frameworks map to those requirements. The company is also expanding provenance measures beyond images as European AI Act implementation advances.

Source

ESET tracks rise in malicious AI skills and adaptable malware

31 juillet 2026 à 16:01
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...]

Google says AI helped Chrome fix 1,072 bugs

Par : IT News
31 juillet 2026 à 15:21
Google says AI helped Chrome fix 1,072 bugs
Google says AI-assisted security tools helped Chrome 149 and Chrome 150 fix 1,072 vulnerabilities—more than the 1,036 fixed across the previous 23 stable releases combined. The company is now using AI across Chrome’s vulnerability workflow and plans more frequent security updates, including a pilot for twice-weekly releases.

Source

Elastic and OpenAI use Elasticsearch to cut AI token use by 75%

Par : IT News
31 juillet 2026 à 15:21
Elastic and OpenAI use Elasticsearch to cut AI token use by 75%
Elastic says its expanded collaboration with OpenAI can reduce AI input-token consumption by up to 75% while increasing benchmark accuracy from 60% to 92%. The partnership uses Elasticsearch as a governed context layer for AI agents working with unstructured enterprise data, including documents, tickets, logs, metrics, traces, and security alerts.

Source

Hermes, powered by DeepSeek, launched autonomous cyberattacks

Par : IT News
31 juillet 2026 à 15:21
Hermes, powered by DeepSeek, launched autonomous cyberattacks
A threat actor used DeepSeek inside the open-source Hermes Agent framework to autonomously discover and attack internet-facing systems through Telegram commands. The operation was ultimately exposed when the agent started an HTTP file server that revealed API keys, exploit code, target lists, shell history, and session logs.

Source

Device code phishing hits industrial scale with 25+ active kits

Par : IT News
31 juillet 2026 à 15:21
Device code phishing hits industrial scale with 25+ active kits
Device code phishing has moved from a niche technique to an industrialized threat, with more than 25 active kits and new campaigns appearing rapidly. The OAuth 2.0 attack can bypass MFA and passkeys by stealing access tokens after users authenticate on legitimate identity-provider pages.

Source

Anthropic: Claude models breached three companies after sandbox misconfiguration

Par : IT News
31 juillet 2026 à 11:24
Anthropic: Claude models breached three companies after sandbox misconfiguration
Anthropic found that three Claude models reached the public internet from supposedly isolated security-test environments and gained unauthorized access to live systems at three organizations. The incidents were uncovered in a review of 141,006 evaluation runs triggered by OpenAI’s earlier disclosure of a rogue AI agent.

Source

Two-minute Teams calls can trigger Chaos ransomware attacks

Par : IT News
31 juillet 2026 à 11:24
Two-minute Teams calls can trigger Chaos ransomware attacks
A Microsoft Teams voice-phishing campaign tracked as STAC4749 is turning brief fake IT-support calls into ransomware incidents. Attackers used remote-access tools and custom `.top` domains to compromise dozens of organizations in the United States and Canada, with one attack reaching ransomware deployment in under 17 hours.

Source

❌
❌