Veille live
Veille CyberInfra — Veille cybersecurite : Microsoft: September updates break File History backup feature Veille CyberInfra — Veille cybersecurite : ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure Veille CyberInfra — Veille cybersecurite : Microsoft reminds admins to migrate Entra ID users to passkeys Veille CyberInfra — Veille cybersecurite : Malicious npm packages evade install-script defenses at runtime Veille CyberInfra — Veille cybersecurite : Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors Veille CyberInfra — Veille cybersecurite : Viral AI actress’ hotline face-scans every caller, watches their mood Veille CyberInfra — Veille cybersecurite : Microsoft: September updates break File History backup feature Veille CyberInfra — Veille cybersecurite : ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure Veille CyberInfra — Veille cybersecurite : Microsoft reminds admins to migrate Entra ID users to passkeys Veille CyberInfra — Veille cybersecurite : Malicious npm packages evade install-script defenses at runtime Veille CyberInfra — Veille cybersecurite : Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors Veille CyberInfra — Veille cybersecurite : Viral AI actress’ hotline face-scans every caller, watches their mood
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

19/09/2026

Source : The Hacker News SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of […]

Veille cybersecurite : Brevo supply-chain attack injected ClickFix scripts on customer sites

18/09/2026

Source : BleepingComputer Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte […]

Veille cybersecurite : New RatHat Android malware uses AI to automate device control

18/09/2026

Source : BleepingComputer A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

18/09/2026

Source : The Hacker News The Iran-linked « hacktivist » persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. « HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, Lire […]

Veille cybersecurite : WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

18/09/2026

Source : The Hacker News Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and […]

Veille cybersecurite : RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

18/09/2026

Source : The Hacker News Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. « Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses […]