Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 21 septembre 2026Flux principal

VMware pulls SmartNIC firewall as customer demand stalls

Par : IT News
21 septembre 2026 à 11:49
VMware pulls SmartNIC firewall as customer demand stalls
VMware has stopped selling its SmartNIC-based distributed firewall after customers showed interest but failed to buy, marking a retreat from the company’s push to bring hyperscaler-style hardware acceleration to private clouds. The Distributed Services Engine remains supported in Cloud Foundation, so existing SmartNIC integrations are not being abandoned outright.

Source

À partir d’avant-hierFlux principal

Check Point rushes LivePatch for critical Security Management flaw

Par : IT News
18 septembre 2026 à 10:56
Check Point rushes LivePatch for critical Security Management flaw
Check Point is urging immediate patching for CVE-2026-91843, a critical flaw in Security Management and Log Servers that can let attackers execute code as root through an oversized login username. The vulnerability affects R82.20, standalone deployments, Log Servers, and Multi-Domain systems; Check Point says there is no evidence of exploitation, but R82.20 has no protective Jumbo Hotfix yet.

Source

Cisco rushes patches for actively exploited CVSS 10 ISE zero-day

Par : IT News
18 septembre 2026 à 10:56
Cisco rushes patches for actively exploited CVSS 10 ISE zero-day
Cisco has released emergency fixes for CVE-2026-76460 after confirming that the Cisco ISE zero-day is under active attack. The maximum-severity flaw lets unauthenticated remote attackers bypass web management authentication and potentially obtain root access, making immediate patching a priority.

Source

BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash

Par : IT News
17 septembre 2026 à 18:43
BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash
BIND 9.20.29 and 9.21.26 fix 14 security vulnerabilities, including a high-severity flaw that lets an unauthenticated attacker crash the `named` DNS process through a single malicious DNS-over-HTTPS request. ISC says it has seen no active exploitation, but administrators should upgrade because the release also addresses resolver crashes, resource exhaustion, DNSSEC validation errors, and unauthorized zone data.

Source

Critical Unbound DNS flaw enables possible RCE through malicious zones

Par : IT News
17 septembre 2026 à 18:43
Critical Unbound DNS flaw enables possible RCE through malicious zones
Unbound DNS resolver versions up to 1.26.0 contain a critical DNSSEC heap overflow that attackers can trigger by controlling a malicious DNS zone and querying a vulnerable resolver. NLnet Labs released Unbound 1.26.1 to fix CVE-2026-81642 and eight other vulnerabilities, but no exploitation has been reported.

Source

Microsoft Entra Private Access offers a phased path beyond VPNs

Par : IT News
17 septembre 2026 à 11:55
Microsoft Entra Private Access offers a phased path beyond VPNs
Microsoft is outlining a practical route for replacing traditional VPN access with Microsoft Entra Private Access, using identity, device health, and application-level policies instead of broad network tunnels. The phased approach starts with discovering VPN-dependent resources and ends with incremental decommissioning, helping administrators modernize remote access without disrupting critical applications.

Source

Cisco Secure Email Gateway zero-day gets patches after root-level attacks

Par : IT News
15 septembre 2026 à 12:05
Cisco Secure Email Gateway zero-day gets patches after root-level attacks
Cisco has patched CVE-2026-76461, a critical Cisco Secure Email Gateway zero-day that attackers are exploiting to run commands as root through specially crafted email messages. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by September 17.

Source

1.6T Ethernet moves from standards work to live interoperability tests

Par : IT News
11 septembre 2026 à 22:59
1.6T Ethernet moves from standards work to live interoperability tests
1.6T Ethernet is moving beyond specifications and into hardware interoperability testing, as the Ethernet Alliance prepares to demonstrate switches, optical modules, and cables from more than a dozen vendors at ECOC. In parallel, the Optical Internetworking Forum’s 1600ZR standard will carry a complete 1.6T Ethernet connection over one coherent wavelength for data-center interconnects spanning up to 120 kilometers.

Source

Axis cameras move into the Cisco Meraki dashboard

Par : IT News
10 septembre 2026 à 16:09
Axis cameras move into the Cisco Meraki dashboard
Axis Communications and Cisco are bringing supported Axis cameras into the Cisco Meraki Dashboard through Axis Cloud Connect, giving administrators a shared view of physical security and IT infrastructure. The integration shows device availability, connectivity, AXIS OS versions, and maintenance needs from Cisco Cloud Control instead of requiring separate checks at each site.

Source

Cisco FMC flaws now fueling Sandworm and Qilin attacks

Par : IT News
10 septembre 2026 à 16:09
Cisco FMC flaws now fueling Sandworm and Qilin attacks
Cisco Secure Firewall Management Center (FMC) is under active attack through CVE-2026-20079 and CVE-2026-20316, with campaigns ranging from credential theft to ransomware deployment. Cisco Talos has identified three intrusion clusters abusing the flaws, prompting the company to urge customers to install available hotfixes immediately rather than wait for next week’s broader hardening release.

Source

Check Point rushes fixes for two CVSS 9.8 Quantum VPN certificate RCEs

Par : IT News
10 septembre 2026 à 16:09
Check Point rushes fixes for two CVSS 9.8 Quantum VPN certificate RCEs
Check Point has released same-day fixes for two CVSS 9.8 vulnerabilities in Quantum VPN certificate processing that could let unauthenticated remote attackers execute code on Security Gateways and Security Management Servers. The flaws are triggered during the VPN handshake, before a user is authenticated, although Check Point says it has found no evidence of exploitation.

Source

OpenSSL 4.1.0 alpha brings DTLS 1.3 and faster post-quantum crypto

Par : IT News
10 septembre 2026 à 11:42
OpenSSL 4.1.0 alpha brings DTLS 1.3 and faster post-quantum crypto
OpenSSL 4.1.0 alpha 1 gives security teams an early test build with DTLS 1.3 and hardware-accelerated post-quantum cryptography. The release improves performance on several server architectures, but it also removes legacy platform and configuration options that may affect existing build pipelines.

Source

Microsoft 365 redirects to Copilot domain, putting network allowlists to the test

Par : IT News
10 septembre 2026 à 11:42
Microsoft 365 redirects to Copilot domain, putting network allowlists to the test
Microsoft 365 is redirecting users from `m365.cloud.microsoft` to `copilot.cloud.microsoft`, and organizations that have blocked the new address will be redirected later in October anyway. The change follows Microsoft’s move to shift Teams web to the cloud.microsoft domain, but this rollout gives administrators a more immediate network-access deadline.

Source

Cisco patch bundle hits critical Nexus 9000 and IOS XR flaws

Par : IT News
9 septembre 2026 à 12:19
Cisco patch bundle hits critical Nexus 9000 and IOS XR flaws
Cisco’s latest security release includes a critical remote-code-execution flaw in Silicon One-based Nexus 9000 switches as well as seven vulnerabilities in IOS XR, including two rated CVSS 9.8. The Nexus issue can let unauthenticated attackers run code as root, while the IOS XR flaws affect all releases and have no workaround.

Source

Intel 24.70.0 drivers add 6 GHz compliance and security fixes for Windows 10 and 11

Par : IT News
8 septembre 2026 à 18:17
Intel 24.70.0 drivers add 6 GHz compliance and security fixes for Windows 10 and 11
Intel has released Wi-Fi and Bluetooth driver packages 24.70.0 for Windows 10 and Windows 11, bringing security updates, stability improvements, and updated 6 GHz regulatory support. The release covers current Wi-Fi 7 and Wi-Fi 6E adapters as well as several older Wireless-AC models, making it relevant to a broad range of systems.

Source

Cloudflare makes post-quantum origin handshakes faster for 45 billion daily connections

Par : IT News
8 septembre 2026 à 16:04
Cloudflare makes post-quantum origin handshakes faster for 45 billion daily connections
Cloudflare’s Automatic Key Exchange is now reducing TLS 1.3 origin handshake delays while automatically shifting eligible connections to post-quantum protection. The rollout has cut HelloRetryRequests from about 52% to 3.7%, lowered p90 handshake latency by more than 150 ms, and helped post-quantum origin traffic grow to roughly 45 billion connections per day.

Source

Cisco’s Unified Edge brings AI inference to distributed sites

Par : IT News
5 septembre 2026 à 15:08
Cisco’s Unified Edge brings AI inference to distributed sites
Cisco is turning edge locations into full AI infrastructure with Unified Edge, a modular platform that combines compute, networking, and storage for real-time inference outside the data center. The system supports CPUs and GPUs, up to 120 TB of storage, redundant power and cooling, and 25-gigabit networking, while Cisco Intersight provides centralized management across distributed deployments.

Source

❌
❌