📰After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot...
📰Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. The post Volexity spots another China-aligned threat...
🔥Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker...
🔥WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further,...
🔥Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their...
🔥Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out...
🔥Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server...
📰Citing China, President Trump doubles down on hands-off approach to AI regulation
Following a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations. The post Citing China,...
📰Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. The post Microsoft and...
🖥️En utilisant Claude, des chercheurs ont réussi à pirater OpenAI en moins de 72 heures
En utilisant Claude, trois chercheurs en cybersécurité sont parvenus à compromettre le forum d'OpenAI, puis des comptes ChatGPT et Codex de salariés. …
🖥️Sécurité : des millions d’utilisateurs d’iPhone font cette erreur sans le savoir
Vous pensez être protégé alors que ce n'est pas le cas.
🖥️Comment agir en cas de cyber attaque ?
Les entreprises sont parfois victimes de piratages informatiques. Malik Douaoui détaille les différentes bonnes pratiques que les entreprises doivent …
🖥️L'UE a dépensé des milliards dans un bouclier anti-cyberattaques, sans vérifier son efficacité
L'UE a mis en place un système d'alerte précoce pour détecter la prochaine cyberattaque majeure avant qu'elle ne se propage. Près de 20 mois plus tard, les auditeurs constatent qu'il n'est...
📰Another worry for water systems: infostealer exposure
SpyCloud’s study found 1,787 of the approximately 10,000 U.S. organizations had it, including one infected device that saved logins for 167 utility metering tenants. The post Another worry for...
🖥️Il a réglé la facture de son artisan sur le RIB reçu par mail : ce que sa banque lui a répondu ne dépendait pas du montant
Il a réglé la facture de son artisan sur le RIB reçu par mail, en toute fin de chantier, juste pour solder les travaux avant la rentrée. Quelques …
📰After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot...
📰Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. The post Volexity spots another China-aligned threat...
🔥Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker...
🔥WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further,...
🔥Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their...
🔥Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out...
🔥Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server...
📰Citing China, President Trump doubles down on hands-off approach to AI regulation
Following a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations. The post Citing China,...
📰Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. The post Microsoft and...
🖥️En utilisant Claude, des chercheurs ont réussi à pirater OpenAI en moins de 72 heures
En utilisant Claude, trois chercheurs en cybersécurité sont parvenus à compromettre le forum d'OpenAI, puis des comptes ChatGPT et Codex de salariés. …
🖥️Sécurité : des millions d’utilisateurs d’iPhone font cette erreur sans le savoir
Vous pensez être protégé alors que ce n'est pas le cas.
🖥️Comment agir en cas de cyber attaque ?
Les entreprises sont parfois victimes de piratages informatiques. Malik Douaoui détaille les différentes bonnes pratiques que les entreprises doivent …
🖥️L'UE a dépensé des milliards dans un bouclier anti-cyberattaques, sans vérifier son efficacité
L'UE a mis en place un système d'alerte précoce pour détecter la prochaine cyberattaque majeure avant qu'elle ne se propage. Près de 20 mois plus tard, les auditeurs constatent qu'il n'est...
📰Another worry for water systems: infostealer exposure
SpyCloud’s study found 1,787 of the approximately 10,000 U.S. organizations had it, including one infected device that saved logins for 167 utility metering tenants. The post Another worry for...
🖥️Il a réglé la facture de son artisan sur le RIB reçu par mail : ce que sa banque lui a répondu ne dépendait pas du montant
Il a réglé la facture de son artisan sur le RIB reçu par mail, en toute fin de chantier, juste pour solder les travaux avant la rentrée. Quelques …