threat-intel Zéro Logement Vacant visé par une fuite massive ? A hacker claims to have compromised Zéro Logement Vacant, a service of beta.gouv.fr, and extracted approximately 149 million lines of data, including information attributed to the DGFiP. The attack exploited a compromised Metabase administrator account and a PostgreSQL password stored in plain text. The hacker alleges… ZATAZ · 12h ago High FRmetabasepostgresqldata breach
vulnerability Multiples vulnérabilités dans PostgreSQL (14 août 2026) Multiple vulnerabilities have been discovered in PostgreSQL, impacting versions 15.x through 18.x and prior to 14.24. These vulnerabilities include potential for data confidentiality breaches, policy bypasses, denial of… CERT-FR · Aug 14, 2026 High CVE-2026-14662CVE-2026-14663CVE-2026-14664postgresqlvulnerabilitysecurity
threat-intel AI Hack : une fuite chez Darsa AI ? A French security news outlet, ZATAZ, has reported a potential data breach at Darsa AI, a company specializing in AI security solutions. A hacker claims to have stolen 90-100GB of data, including source code, databases,… ZATAZ · Jul 24, 2026 High data breachaimicrosoft
threat-intel Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors, linked to the Contagious Interview campaign (REF9403), are using fake coding tests and SVG images containing steganography to deliver a multi-stage malware payload – OtterCookie – to software… The Hacker News · Jul 17, 2026 High KPsteganographysupply chaindeveloper
threat-intel Dutch Raid Fails to Dent Russian Bulletproof Host A Dutch law enforcement operation targeting THE.Hosting, a bulletproof hosting network linked to Russian cybercrime, resulted in the seizure of 800 servers and arrests of two operators but failed to significantly disrupt… Dark Reading · May 28, 2026 High NLRUDKbulletproof hostingcybercrimesanctions evasion
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa