Veille live
Veille CyberInfra — Veille cybersecurite : Ryuk ransomware member sentenced to 24 months in prison Veille CyberInfra — Veille cybersecurite : ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Veille CyberInfra — Veille cybersecurite : Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input Veille CyberInfra — Veille cybersecurite : Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape Veille CyberInfra — Veille cybersecurite : ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Veille CyberInfra — Veille cybersecurite : Arista patches actively exploited VeloCloud Orchestrator zero-day Veille CyberInfra — Veille cybersecurite : Ryuk ransomware member sentenced to 24 months in prison Veille CyberInfra — Veille cybersecurite : ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Veille CyberInfra — Veille cybersecurite : Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input Veille CyberInfra — Veille cybersecurite : Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape Veille CyberInfra — Veille cybersecurite : ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Veille CyberInfra — Veille cybersecurite : Arista patches actively exploited VeloCloud Orchestrator zero-day
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : Hackers target WordPress sites in miniOrange auth bypass attacks

25/08/2026

Source : BleepingComputer Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? […]

Veille cybersecurite : Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

25/08/2026

Source : BleepingComputer An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? […]

Veille cybersecurite : WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

25/08/2026

Source : The Hacker News Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ […]

Veille cybersecurite : Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

25/08/2026

Source : The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access […]

Veille cybersecurite : Named Pipes Under Attack: Securing Windows Interprocess Communication

23/08/2026

Source : BleepingComputer Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type […]

Veille cybersecurite : Hackers infect Android car head units with proxy botnet malware

23/08/2026

Source : BleepingComputer A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel […]

Veille cybersecurite : 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

22/08/2026

Source : The Hacker News Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. « When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background […]