Veille live
Veille CyberInfra — Veille cybersecurite : New Windows Defender zero-day blocks Microsoft antivirus updates Veille CyberInfra — Veille cybersecurite : WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Veille CyberInfra — Veille cybersecurite : DORA Year Two: Can Your SOC Actually See the Attack? Veille CyberInfra — Veille cybersecurite : WordPress Click2Shell flaw lets hackers execute PHP on the server Veille CyberInfra — Veille cybersecurite : One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Veille CyberInfra — Veille cybersecurite : SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE Veille CyberInfra — Veille cybersecurite : New Windows Defender zero-day blocks Microsoft antivirus updates Veille CyberInfra — Veille cybersecurite : WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Veille CyberInfra — Veille cybersecurite : DORA Year Two: Can Your SOC Actually See the Attack? Veille CyberInfra — Veille cybersecurite : WordPress Click2Shell flaw lets hackers execute PHP on the server Veille CyberInfra — Veille cybersecurite : One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Veille CyberInfra — Veille cybersecurite : SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

09/09/2026

Source : The Hacker News The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. « Microsoft has failed to properly patch […]

Veille cybersecurite : Google warns of new Chrome zero-day bug exploited in attacks

09/09/2026

Source : BleepingComputer Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

09/09/2026

Source : The Hacker News Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome’s JavaScript and WebAssembly engine. « Out-of-bounds write in V8 […]

Veille cybersecurite : 220 million traveler records exposed in Vietnam-linked APIS leak

08/09/2026

Source : BleepingComputer Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. […] Lire l’article original Vous vous demandez si votre […]

Veille cybersecurite : Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

08/09/2026

Source : The Hacker News Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff […]

Veille cybersecurite : PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

08/09/2026

Source : The Hacker News Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. « Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own […]