🔐 Security flaws and vulnerabilities
CERT-FR (Government Center for Monitoring, Alerting and Response to Computer Attacks)
- De multiples vulnérabilités ont été découvertes dans CPython. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.
- De multiples vulnérabilités ont été découvertes dans Redmine. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).
- De multiples vulnérabilités ont été découvertes dans Mozilla Thunderbird. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.
- Une vulnérabilité a été découverte dans Cisco Catalyst SD-WAN. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité. Cisco indique que la vulnérabilité CVE-2026-76504 est activement exploitée.
- Face à l’intensification des attaques cybercriminelles liées à des violations de données affectant les services de l’État, le Premier ministre a demandé le 1er septembre 2026 à l’Agence nationale de la sécurité des systèmes d’information (ANSSI) de mettre en place une capacité renforcée de…
Exploit Database (Offensive Security)
- InvoicePlane 1.7.1 – RCE
- POMS oretnom23v1.0 – SQLi vulnerabilities
- Krayin CRM 2.2.4 – IDOR
- SuiteCRM 8.10.1 – Authenticated SSRF
- Ecava_ntegraXor IGX_16.0.701.10 – RCE
🛡️ Ongoing attacks and active campaigns
The Hacker News
- Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. […]
- This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the […]
- Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing […]
- Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, […]
- OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in […]
🛠️ Microsoft Security Update Guide (Patch Tuesday & other updates)
This feed lists security bulletins (CVE, monthly patches) released by Microsoft. It is the official source for Windows, Office, Azure security updates, etc.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.