🛡️ Dernière mise à jour : 22 août 2026 à 05:00 UTC

📡 Alertes 2 articles
🏛️ CERT-FR ⏱ 1 min de lecture 📡

Vulnérabilité dans Microsoft Office (21 août 2026)

Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une atteinte à la confidentialité…

Un article publié par CERT-FR aborde le sujet suivant : Vulnérabilité dans Microsoft Office (21 août 2026). Les détails sont disponibles sur le site source.

🏛️ CERT-FR ⏱ 1 min de lecture 📡

Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)

Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne…

Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...

🔍 Analyses 9 articles
🛡️ Unit 42 ⏱ 1 min de lecture 🔍

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls…

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42 .

💻 BleepingComputer ⏱ 1 min de lecture 🔍

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a…

Un article publié par BleepingComputer aborde le sujet suivant : New SynkLoader malware pushed in Microsoft Teams phishing campaign. Les détails sont disponibles sur le site source.

🔎 Mandiant / Google ⏱ 2 min de lecture 🔍

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage…

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additional two distinct suspected Russian clusters, UNC7005 and UNC5976, which conduct phishing, abuse OAuth flows, and/or deploy malware to victims. UNC7005 in particular is tied to the hospitality captive portal redirects reported on by Reliaquest and Microsoft . While each group conducts their campaigns differently, they all ultimately demonstrate a focus on abuse of legitimate authentication workflows to compromise accounts. These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms. Because these operations abuse legitimate authentication flows which may not immediately seem like phishing attempts to users, GTIG is raising awareness about these social engineering campaigns targeting individuals so that targets can more readily recognize malicious outreach. UNC6293 We assess with moderate confidence that UNC6293 is a sub cluster of ICE RELIC (formerly APT29) responsible for initial access operations . UNC6293 operations were initially reported in June 2025 (also by Citizen Lab ) as an aggressive app password phishing campaign against prominent individuals that are critical of Russia. App passwords are passcodes a user can set which gives a less secure app or device permission to access an account. In cases of app password phishing, attackers attempt to convince targets to set specific app passwords on their accounts, which the attackers then use to gain access to those accounts without needing two-factor authentication (2FA). As part of the previously…

💻 BleepingComputer ⏱ 1 min de lecture 🔍

Hundreds of leaked AWS keys give full control over corporate accounts

More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active…

Un article publié par BleepingComputer aborde le sujet suivant : Hundreds of leaked AWS keys give full control over corporate accounts. Les détails sont disponibles sur le site source.

💻 BleepingComputer ⏱ 1 min de lecture 🔍

Microsoft blames Windows gaming issues on RGB lighting devices

Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may…

Un article publié par BleepingComputer aborde le sujet suivant : Microsoft blames Windows gaming issues on RGB lighting devices. Les détails sont disponibles sur le site source.

💻 BleepingComputer ⏱ 1 min de lecture 🔍

Is Online Privacy Possible? How Digital Identities Can Help

Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to…

Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]

💻 BleepingComputer ⏱ 1 min de lecture 🔍

Microsoft rolls out Classic Outlook theme for New Outlook users

Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook…

Un article publié par BleepingComputer aborde le sujet suivant : Microsoft rolls out Classic Outlook theme for New Outlook users. Les détails sont disponibles sur le site source.

💻 BleepingComputer ⏱ 1 min de lecture 🔍

Hackers abuse FTP server banners to deliver new Windows malware

Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and…

Un article publié par BleepingComputer aborde le sujet suivant : Hackers abuse FTP server banners to deliver new Windows malware. Les détails sont disponibles sur le site source.

💻 BleepingComputer ⏱ 1 min de lecture 🔍

SickKids data breach exposes employee and job applicant info

Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees…

Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]

📋 Vulnérabilités 3 articles
💻 BleepingComputer ⏱ 1 min de lecture 📋

CISA orders feds to patch actively exploited TrueConf Server flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in…

Un article publié par BleepingComputer aborde le sujet suivant : CISA orders feds to patch actively exploited TrueConf Server flaws. Les détails sont disponibles sur le site source.

💻 BleepingComputer ⏱ 1 min de lecture 📋

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited…

Un article publié par BleepingComputer aborde le sujet suivant : Microsoft warns of max severity Entra ID flaw exploited in attacks. Les détails sont disponibles sur le site source.

🏛️ CERT-FR ⏱ 1 min de lecture 📋

Multiples vulnérabilités dans le noyau Linux de SUSE (21 août 2026)

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de…

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

📊 Rapports 1 article
🔐 ANSSI ⏱ 1 min de lecture 📊

L’ANSSI renforce son engagement dans le Pacifique aux côtés du réseau PaCSON

L’ANSSI renforce son engagement dans le Pacifique aux côtés du réseau PaCSON Publié le mercredi 5 août 2026

Un article publié par ANSSI aborde le sujet suivant : L’ANSSI renforce son engagement dans le Pacifique aux côtés du réseau PaCSON. Les détails sont disponibles sur le site source.