vulnerability Multiples vulnérabilités dans les produits Apple (28 juillet 2026) Multiple vulnerabilities have been discovered in Apple products, including iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. Several of these vulnerabilities allow for arbitrary code execution, privilege escalation, and d… CERT-FR · Jul 28, 2026 High CVE-2025-43325CVE-2026-20672CVE-2026-23918securityvulnerabilitypatch
vulnerability Multiples vulnérabilités dans Samba (28 juillet 2026) Multiple vulnerabilities have been discovered in Samba, potentially leading to denial of service, data confidentiality breaches, and policy bypasses. These vulnerabilities affect older versions of the Samba server softwa… CERT-FR · Jul 28, 2026 Medium CVE-2026-58216CVE-2026-58218CVE-2026-58221vulnerabilitysecurityserver
vulnerability 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure Two significant ‘confused deputy’ vulnerabilities persist in Google Cloud Platform (GCP) and Microsoft Azure, allowing attackers to escalate privileges and bypass security controls. Despite reporting these flaws to both… Dark Reading · Jul 27, 2026 High cloud securityidentity managementaccess control
threat-intel Outdated VPNs should be purged from federal agencies, senator says Senator Ron Wyden is urging federal agencies to remove outdated and insecure VPNs from their systems, citing a growing threat of foreign adversaries exploiting these vulnerabilities to gain access to sensitive U.S. gover… The Record · Jul 27, 2026 High RUCHvpnzero-trustremote access
vulnerability Microsoft's solution to AI security: more AI and more acronyms Microsoft is facing a zero-day vulnerability in its on-prem SharePoint system, allowing attackers to exploit the flaw. This follows a broader trend of security challenges related to Microsoft products and a wider increas… The Register · Jul 27, 2026 High USIRSWvulnerabilitysharepointzero-day
threat-intel NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework NVIDIA has formed the Open Secure AI Alliance, a 37-member group focused on developing open technologies and tools for securing AI agents and software. The alliance’s core contribution, NOOA, is a Python framework design… The Hacker News · Jul 27, 2026 High UNaiagentsecurity
threat-intel Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack Tech giants, including AMD and Cerebras, have jointly urged the US government to prioritize the development and use of open-weight AI models, in response to a recent attack targeting Hugging Face using open-weight AI. Th… The Register · Jul 27, 2026 Medium IRUSaiopen-sourcesecurity
vulnerability Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update A recent update to Microsoft Defender for Endpoint introduced a vulnerability that left some Linux systems exposed to attack. The flaw stems from a misconfigured feature within the endpoint protection software, allowing… The Register · Jul 27, 2026 Medium linuxendpoint securityvulnerability
vulnerability PTC Windchill Vulnerability Exploited in Ransomware Campaign A critical remote code execution vulnerability in PTC's Windchill and FlexPLM PLM platforms has been exploited by a Cl0p ransomware affiliate in a targeted campaign. The attackers are leveraging a chain of vulnerabilitie… SecurityWeek · Jul 27, 2026 Critical CVE-2026-12569rcevulnerabilityransomware
vulnerability n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process N8n, a workflow automation platform, had a high-severity expression-sandbox escape that could allow authenticated workflow editors to execute operating system commands on the server. The vulnerability stemmed from a flaw… The Hacker News · Jul 27, 2026 High CVE-2026-27577expression-sandboxworkflowjavascript
threat-intel Nvidia and Tech Giants Launch AI Security Alliance Nvidia and a coalition of tech giants have launched the Open Secure AI Alliance, an initiative focused on developing and sharing open-source tools and techniques to bolster the security of AI systems and agents. The alli… SecurityWeek · Jul 27, 2026 High aisecurityopen source
threat-intel What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out Lookout has launched a new Mobile Security Exposure Center (MSEC) designed to provide organizations with a deeper understanding of the vulnerabilities hidden within their mobile apps. MSEC creates a ‘software bill of mat… SecurityWeek · Jul 27, 2026 High CHmobile-securitysbomvulnerability
threat-intel Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits Anthropic’s Opus 5 AI model excels at finding software vulnerabilities, nearly matching Mythos 5’s capabilities, but it cannot automatically generate exploits. Anthropic deliberately limits Opus 5’s exploit generation ab… SecurityWeek · Jul 27, 2026 Medium aivulnerabilitycybersecurity
threat-intel Google goes it alone with a new cybercrime crew taxonomy This article is a collection of security news snippets from The Register. It highlights a Microsoft vulnerability in on-prem SharePoint, a phishing campaign impersonating Signal support, and a broader trend of increasing… The Register · Jul 27, 2026 High RUphishingvulnerabilitycybercrime
vulnerability ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Jul 27, 2026 Critical log4jjndiremote code execution
vulnerability Vulnérabilité dans Traefik (27 juillet 2026) A security vulnerability has been identified in Traefik, allowing attackers to bypass security policies. This affects older versions of the popular reverse proxy and load balancer, requiring immediate patching to prevent… CERT-FR · Jul 27, 2026 Medium traefikvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026) Multiple vulnerabilities have been discovered in Atlassian products, including Confluence Data Center and Jira Service Management. These vulnerabilities allow for remote code execution, privilege escalation, denial of se… CERT-FR · Jul 27, 2026 High CVE-2022-37599CVE-2022-37601CVE-2022-37603vulnerabilitysupply-chaindata-breach
vulnerability Multiples vulnérabilités dans GLPI (27 juillet 2026) Multiple vulnerabilities have been discovered in GLPI, including potential for privilege escalation, data integrity compromise, and SQL injection. These vulnerabilities affect GLPI versions prior to 11.0.8 and 10.0.26. U… CERT-FR · Jul 27, 2026 High CVE-2026-47678CVE-2026-47679CVE-2026-52848glpivulnerabilitysql injection
vulnerability Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities are detailed in a series of security… CERT-FR · Jul 27, 2026 Medium CVE-2026-57978CVE-2026-57989CVE-2026-57990vulnerabilitymicrosoftedge
vulnerability Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th) A scan targeting ESAFENET CDG, a Chinese-focused document management system, revealed weak default passwords and vulnerabilities, including SQL injection and XSS. Threat actors are leveraging existing exploit scripts to… SANS Internet Storm Center · Jul 26, 2026 Medium CNdefault passwordsql injectionxss