Veille live
Veille CyberInfra — Veille cybersecurite : Ryuk ransomware member sentenced to 24 months in prison Veille CyberInfra — Veille cybersecurite : ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Veille CyberInfra — Veille cybersecurite : Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input Veille CyberInfra — Veille cybersecurite : Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape Veille CyberInfra — Veille cybersecurite : ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Veille CyberInfra — Veille cybersecurite : Arista patches actively exploited VeloCloud Orchestrator zero-day Veille CyberInfra — Veille cybersecurite : Ryuk ransomware member sentenced to 24 months in prison Veille CyberInfra — Veille cybersecurite : ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Veille CyberInfra — Veille cybersecurite : Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input Veille CyberInfra — Veille cybersecurite : Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape Veille CyberInfra — Veille cybersecurite : ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Veille CyberInfra — Veille cybersecurite : Arista patches actively exploited VeloCloud Orchestrator zero-day
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

02/09/2026

Source : The Hacker News Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely […]

Veille cybersecurite : Critical Langflow flaw exploited to steal OpenAI and AWS keys

02/09/2026

Source : BleepingComputer Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

02/09/2026

Source : The Hacker News Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. « JFrog Artifactory contains an authentication weakness that, […]

Veille cybersecurite : Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

02/09/2026

Source : The Hacker News SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall’s William Perry and Adam Babis, are listed below – CVE-2026-83548 (CVSS score: 10.0) –  A pre-authentication SSRF […]

Veille cybersecurite : North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

01/09/2026

Source : The Hacker News Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of […]

Veille cybersecurite : Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

01/09/2026

Source : The Hacker News METR (short for Model Evaluation and Threat Research and pronounced « Meter »), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered « two notable security incidents » where external actors attempted to gain unauthorized access to its systems. No […]

Veille cybersecurite : Microsoft warns of TerminalFix attacks deploying reverse tunnels

01/09/2026

Source : BleepingComputer A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Cronos blockchain restarts after $74 million Tectonic exploit

01/09/2026

Source : BleepingComputer The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.