threat-intel YARA-X 1.20.0 Release, (Sun, Aug 30th) The YARA-X threat intelligence platform released version 1.20.0, incorporating several improvements and bug fixes. Simultaneously, YARA itself received multiple updates (4.5.6, 4.5.7, and 4.5.8) addressing a significant number of bugs. These updates are primarily focused on enhancing the YARA rule engine's stability an… SANS Internet Storm Center · 11h ago Info yarathreat-intelrule-engine
threat-intel Android Malware Hijacks Update System for Car Head Units Threat actors, linked to the BadBox click-fraud botnet, are exploiting legitimate update mechanisms in car head units to spread malware. This marks the first known instance of malware targeting automotive infotainment sy… Dark Reading · 4d ago High CHandroidbotnetmalware
threat-intel Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet A new malware family, dubbed JarService, is targeting Android car head units developed by DoFun, leveraging the built-in update mechanism to spread ad fraud and proxy botnet capabilities. The campaign is attributed to th… The Hacker News · Aug 21, 2026 High CNandroidcarmalware
threat-intel Multiples vulnérabilités dans les produits Mozilla (19 août 2026) Mozilla has disclosed multiple vulnerabilities across its Firefox and Thunderbird products. These vulnerabilities include potential for remote code execution, denial of service, and information disclosure. Affected versi… CERT-FR · Aug 19, 2026 High CVE-2026-74934CVE-2026-74935CVE-2026-74936vulnerabilityfirefoxthunderbird
vulnerability Multiples vulnérabilités dans Microsoft Office (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Office, some of which allow an attacker to trigger arbitrary code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities are p… CERT-FR · Aug 12, 2026 High CVE-2026-58651CVE-2026-62842CVE-2026-62882vulnerabilitysecuritymicrosoft
vulnerability Multiples vulnérabilités dans les produits Intel (12 août 2026) Multiple vulnerabilities have been discovered in Intel products, impacting a range of their processors. These vulnerabilities could lead to privilege escalation, data confidentiality breaches, and denial of service attac… CERT-FR · Aug 12, 2026 High intelvulnerabilitysecurity
vulnerability Vulnérabilité dans Docker (11 août 2026) A vulnerability has been identified in Docker Desktop, allowing an attacker to compromise data integrity. Users of versions prior to 4.86.0 should immediately update to mitigate the risk. CERT-FR · Aug 11, 2026 Medium CVE-2026-17106dockervulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Google Chrome (07 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, potentially allowing an attacker to trigger a security issue. These vulnerabilities affect Chrome versions prior to 151.0.7922.108 on Windows and Linux, and… CERT-FR · Aug 7, 2026 High CVE-2026-19137CVE-2026-19138CVE-2026-19139chromevulnerabilitysecurity
threat-intel Multiples vulnérabilités dans les produits IBM (07 août 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect a wide range of IBM products, including da… CERT-FR · Aug 7, 2026 High CVE-2023-53781CVE-2024-34459CVE-2024-4741vulnerabilitysecuritycybersecurity
vulnerability Multiples vulnérabilités dans Google Android (04 août 2026) Google Android is experiencing multiple vulnerabilities, as reported by CERT-FR. The exact nature of these vulnerabilities is not specified, but users are urged to apply the security patch released on August 3, 2026, to… CERT-FR · Aug 4, 2026 Medium androidvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (03 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge. Some of these allow an attacker to cause arbitrary code execution, data confidentiality breaches, and data integrity issues. These vulnerabilities are part… CERT-FR · Aug 3, 2026 High CVE-2026-17650CVE-2026-17651CVE-2026-17652vulnerabilitysecuritymicrosoft
vulnerability Multiples vulnérabilités dans Google Chrome (30 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, potentially allowing an attacker to cause a security issue. These vulnerabilities are spread across various Chrome versions and are related to a range of is… CERT-FR · Jul 30, 2026 High CVE-2026-17650CVE-2026-17651CVE-2026-17652chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (29 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing an attacker to cause data integrity issues and a security problem not specified by the vendor. These vulnerabilities are part of a lar… CERT-FR · Jul 29, 2026 High CVE-2026-62828CVE-2026-13282CVE-2026-13283vulnerabilitysecuritymicrosoft
vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Some of these vulnerabilities allow for data confidentiality and integrity breaches, as well as bypassing security policies and causing denial of se… CERT-FR · Jul 24, 2026 High CVE-2023-20585CVE-2025-10263CVE-2025-39894linuxkernelsecurity
vulnerability Multiples vulnérabilités dans Google Chrome (17 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser. The exact nature of the security issue is not specified by the publisher, but users are advised to update to the la… CERT-FR · Jul 17, 2026 Medium CVE-2026-15899CVE-2026-15900CVE-2026-15901vulnerabilitychromesecurity
vulnerability ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances ServiceNow has disclosed a security incident where an unknown threat actor exploited a vulnerability to gain unauthorized access to customer instances. The flaw, initially discovered and internally tracked by ServiceNow… The Hacker News · Jun 10, 2026 High AUsecurityvulnerabilityaccess
threat-intel Windows 11 KB5089573 update released with performance improvements This article reports on the release of Windows 11 KB5089573, a non-security preview update for Windows 11 versions 25H2 and 24H2. The update focuses on performance improvements and reliability enhancements, including sha… BleepingComputer · May 27, 2026 Low windows 11performancereliability
vulnerability ABB B&R Automation Studio ABB has issued a security advisory regarding vulnerabilities in its B&R Automation Studio software. The issues, stemming from SQLite versions, could lead to memory corruption and heap buffer overflows, potentially allowi… CISA Advisories · May 21, 2026 High CVE-2025-6965CVE-2025-3277CVE-2023-7104CHsqliteheap-overflowmemory-corruption
threat-intel Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare Drupal has announced an upcoming core security release scheduled for May 20, 2026, urging users to prepare and update their systems proactively. The release addresses potential vulnerabilities that could be exploited qui… The Hacker News · May 19, 2026 High drupalsecurityupdate
other Friday Squid Blogging: Bigfin Squid This article is a blog post update from Schneier on Security, serving as a platform for discussing current security news. It directs readers to utilize the post to discuss relevant security stories and highlights the blo… Schneier on Security · May 16, 2026 Info blogsecuritynews