Veille live
Veille CyberInfra — Veille cybersecurite : Microsoft: September updates break File History backup feature Veille CyberInfra — Veille cybersecurite : ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure Veille CyberInfra — Veille cybersecurite : Microsoft reminds admins to migrate Entra ID users to passkeys Veille CyberInfra — Veille cybersecurite : Malicious npm packages evade install-script defenses at runtime Veille CyberInfra — Veille cybersecurite : Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors Veille CyberInfra — Veille cybersecurite : Viral AI actress’ hotline face-scans every caller, watches their mood Veille CyberInfra — Veille cybersecurite : Microsoft: September updates break File History backup feature Veille CyberInfra — Veille cybersecurite : ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure Veille CyberInfra — Veille cybersecurite : Microsoft reminds admins to migrate Entra ID users to passkeys Veille CyberInfra — Veille cybersecurite : Malicious npm packages evade install-script defenses at runtime Veille CyberInfra — Veille cybersecurite : Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors Veille CyberInfra — Veille cybersecurite : Viral AI actress’ hotline face-scans every caller, watches their mood
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : Acronis warns of actively exploited flaw in its cPanel backup plugin

16/09/2026

Source : BleepingComputer Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Critical ScreenConnect flaw now actively exploited in attacks

16/09/2026

Source : BleepingComputer Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Google fixes actively exploited Android zero-day on Pixel devices

16/09/2026

Source : BleepingComputer Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

16/09/2026

Source : The Hacker News Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. « This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution, » Wordfence said. The WordPress security company […]

Veille cybersecurite : Threat Intelligence Alone Won’t Close the Exploitation Gap

16/09/2026

Source : The Hacker News A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure […]

Veille cybersecurite : Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

15/09/2026

Source : The Hacker News Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per […]