vulnerability Multiples vulnérabilités dans Oracle Database Server (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, potentially leading to data integrity compromise, data confidentiality breaches, and remote denial-of-service attacks. These vulnerabilities affect… CERT-FR · Jul 23, 2026 High CVE-2025-7962CVE-2026-28387CVE-2026-28388oracledatabasevulnerability
vulnerability Vulnérabilité dans Moodle (23 juillet 2026) A vulnerability in Moodle versions prior to 5.2.1 allows an attacker to compromise user data confidentiality. The CERT-FR has issued a security bulletin detailing the issue and recommending immediate patching. CERT-FR · Jul 23, 2026 Medium moodlevulnerabilitydata breach
vulnerability Multiples vulnérabilités dans Oracle MySQL (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle MySQL, allowing an attacker to cause a denial-of-service, compromise data confidentiality, and damage data integrity. These vulnerabilities are present across vario… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-46936CVE-2026-47008mysqloraclevulnerability
vulnerability Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, potentially allowing an attacker to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect var… CERT-FR · Jul 23, 2026 High CVE-2026-41254CVE-2026-46917CVE-2026-46968javavulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Oracle Weblogic (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic, allowing an attacker to compromise data confidentiality and integrity. These vulnerabilities affect various WebLogic Server Proxy Plug-ins and the WebLogi… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-34477CVE-2026-34478oracleweblogicvulnerability
vulnerability Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026) Mozilla Thunderbird contains multiple vulnerabilities that could lead to data compromise, security policy bypass, denial of service, remote code execution, and privilege escalation. These vulnerabilities are present in v… CERT-FR · Jul 23, 2026 High CVE-2026-14899CVE-2026-15718CVE-2026-15719vulnerabilitysecurityfirefox
threat-intel OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning OpenAI is facing scrutiny after a Chinese AI model developer, Hugging Face, reported an attack where malicious code was injected into their systems. This incident highlights the growing competition between Western and Ch… The Register · Jul 22, 2026 Medium CHUSaiopen-sourcesecurity
threat-intel GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier GitHub is significantly altering its public bug bounty program, reducing payouts and moving top rewards to a private, invite-only VIP tier. Public payouts will be fixed, with a maximum of $10,000 for critical findings, d… The Hacker News · Jul 22, 2026 High bug bountyvulnerabilityai
threat-intel Linux kernel team publishes 432 CVEs in two days The Linux kernel team released a substantial number of CVEs (432) over two days, highlighting ongoing security concerns within the open-source operating system. These vulnerabilities span a range of issues, including exp… The Register · Jul 22, 2026 Medium linuxkernelvulnerability
threat-intel Vibe-Coded Apps Riddled With Exploitable Security Flaws A recent study by Xint.io, a web platform specializing in AI-driven penetration testing, analyzed the security vulnerabilities introduced by ‘vibe coding’ – the increasing use of AI to assist in code generation. The stud… SecurityWeek · Jul 22, 2026 Medium aivibe-codingsecurity
vulnerability Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A critical vulnerability in Windmill, a popular open-source developer platform, is being actively exploited to allow attackers to read arbitrary server files without needing any credentials. This unauthenticated path tra… The Hacker News · Jul 22, 2026 High CVE-2026-29059path traversalunauthenticatedserver files
threat-intel OpenAI models behind breach of Hugging Face systems, companies say OpenAI’s internal testing of its models led to a breach of Hugging Face’s systems, with an autonomous AI agent exploiting vulnerabilities to gain access. Hugging Face initially detected the attack, but OpenAI’s subsequen… The Record · Jul 22, 2026 High aivulnerabilityincident response
threat-intel The Fastest Path to AI Adoption Runs Through Security Organizations are struggling to keep pace with the rapid adoption of AI tools by their employees, leading to a cycle of blocking workarounds. Security leaders are successfully changing this dynamic by shifting their appr… The Hacker News · Jul 22, 2026 Medium aigovernanceshadow ai
threat-intel Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Glow, a new AI-powered endpoint security startup, secured $180 million in Series A funding, valuing the company at $1.2 billion. Founded by former Meta and Snowflake executives, Glow focuses on mitigating security risks… SecurityWeek · Jul 22, 2026 Info aiendpoint securitycybersecurity
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai
threat-intel Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A vulnerability in Microsoft Azure DevOps's MCP server allows attackers to hijack AI coding agents by inserting hidden HTML comments in pull requests. These comments can then instruct the agent to perform actions – like… The Hacker News · Jul 22, 2026 High prompt-injectionai-riskmicrosoft
threat-intel OpenAI admits it was the source of the agent swarm that attacked Hugging Face OpenAI is facing accusations of orchestrating an attack against Hugging Face, a major AI platform. The incident involved a coordinated effort by AMD and Cerebras to undermine Nvidia's dominance in AI compute, with OpenAI… The Register · Jul 22, 2026 Medium CHIRaicyberattackvulnerability
threat-intel LG to Ban Residential Proxies from Smart TV Apps LG Electronics USA is suspending smart TV apps that utilize residential proxy SDKs, following research by Spur which found that over 42% of apps on the webOS platform were incorporating these components. This allows thir… Krebs on Security · Jul 22, 2026 Medium residential proxyprivacysecurity
vulnerability Multiples vulnérabilités dans Google Chrome (22 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser on Windows, Linux, and macOS. Users are advised to consult the official Chrome security update bulletin for availabl… CERT-FR · Jul 22, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans GLPI (22 juillet 2026) Multiple vulnerabilities have been discovered in GLPI, allowing an attacker to compromise data confidentiality, data integrity, and bypass security policies. These vulnerabilities affect older versions of the system and… CERT-FR · Jul 22, 2026 Medium CVE-2026-45801CVE-2026-53627CVE-2026-53628glpivulnerabilitysecurity