Veille live
Veille CyberInfra — Veille cybersecurite : New Windows Defender zero-day blocks Microsoft antivirus updates Veille CyberInfra — Veille cybersecurite : WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Veille CyberInfra — Veille cybersecurite : DORA Year Two: Can Your SOC Actually See the Attack? Veille CyberInfra — Veille cybersecurite : WordPress Click2Shell flaw lets hackers execute PHP on the server Veille CyberInfra — Veille cybersecurite : One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Veille CyberInfra — Veille cybersecurite : SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE Veille CyberInfra — Veille cybersecurite : New Windows Defender zero-day blocks Microsoft antivirus updates Veille CyberInfra — Veille cybersecurite : WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Veille CyberInfra — Veille cybersecurite : DORA Year Two: Can Your SOC Actually See the Attack? Veille CyberInfra — Veille cybersecurite : WordPress Click2Shell flaw lets hackers execute PHP on the server Veille CyberInfra — Veille cybersecurite : One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Veille CyberInfra — Veille cybersecurite : SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

12/09/2026

Source : The Hacker News Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, […]

Veille cybersecurite : GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

12/09/2026

Source : The Hacker News GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary […]

Veille cybersecurite : Artifactory flaws chained in attacks deploying backdoor malware

12/09/2026

Source : BleepingComputer Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.

Veille cybersecurite : Passkey-themed phishing attacks lead to Microsoft 365 data theft

12/09/2026

Source : BleepingComputer Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un […]

Veille cybersecurite : Florida confirms DMV database breached via stolen police account

12/09/2026

Source : BleepingComputer The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type de faille ? […]