Veille live
Veille CyberInfra — Veille cybersecurite : New Windows Defender zero-day blocks Microsoft antivirus updates Veille CyberInfra — Veille cybersecurite : WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Veille CyberInfra — Veille cybersecurite : DORA Year Two: Can Your SOC Actually See the Attack? Veille CyberInfra — Veille cybersecurite : WordPress Click2Shell flaw lets hackers execute PHP on the server Veille CyberInfra — Veille cybersecurite : One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Veille CyberInfra — Veille cybersecurite : SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE Veille CyberInfra — Veille cybersecurite : New Windows Defender zero-day blocks Microsoft antivirus updates Veille CyberInfra — Veille cybersecurite : WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Veille CyberInfra — Veille cybersecurite : DORA Year Two: Can Your SOC Actually See the Attack? Veille CyberInfra — Veille cybersecurite : WordPress Click2Shell flaw lets hackers execute PHP on the server Veille CyberInfra — Veille cybersecurite : One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Veille CyberInfra — Veille cybersecurite : SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

10/09/2026

Source : The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below – CVE-2026-20079 (CVSS score: […]

Veille cybersecurite : Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

10/09/2026

Source : BleepingComputer Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : CISA: WatchGuard RCE flaw now exploited in ransomware attacks

10/09/2026

Source : BleepingComputer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte […]

Veille cybersecurite : Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

09/09/2026

Source : BleepingComputer A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez […]

Veille cybersecurite : The EU CRA’s Real Question: What Shipped, and When Did You Know?

09/09/2026

Source : BleepingComputer The EU Cyber Resilience Act’s vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. […] Lire l’article original Vous vous demandez […]

Veille cybersecurite : New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access

09/09/2026

Source : BleepingComputer An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named « ShieldCrash » right after Microsoft rolled out its September 2026 Patch Tuesday security updates. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

09/09/2026

Source : The Hacker News SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory […]