bedtime sunny

Restez informé(e)s

des cybermenaces

avec les dernières informations cyber

Modèle cyber
Cyber actualités ZATAZ de la semaine du 20 au 26 juillet 2026
Cyber actualités ZATAZ de la semaine du 20 au 26 juillet 2026
Bonjour à toutes et tous, Cette semaine, l’actualité cyber se concentre sur l’automatisation de l’extorsion, les fuites revendiquées et la pression exercée sur les organisations. Titan promet d’analyser les données volées et de calculer les rançons, tandis qu…
 
Zataz.com 24/07/2026
Deux jeux d’été pour vérifier et déchiffrer
Deux jeux d’été pour vérifier et déchiffrer
Deux jeux d’été mêlent fact-checking, détection IA et chiffrement pour entraîner l’esprit critique en famille.
 
Zataz.com 24/07/2026
Quatre rendez-vous cyber à suivre jusqu’en octobre
Quatre rendez-vous cyber à suivre jusqu’en octobre
Barbhack, DEF CON, Cyberbrew et Hackfest rythment la rentrée cyber, de Toulon à Québec, en passant par Lille.
 
Zataz.com 24/07/2026
Titan automatise le chantage aux données
Titan automatise le chantage aux données
Titan promet d’automatiser l’analyse des fuites, le calcul des rançons et la pression réglementaire.
 
Zataz.com 24/07/2026
B9 : 36 000 profils bancaires annoncés piratés
B9 : 36 000 profils bancaires annoncés piratés
B9 fait l’objet d’une fuite présumée de 36 000 profils, illustrant les risques cyber des banques 100 % en ligne.
 
Zataz.com 24/07/2026
Pokemon Gym : 19 600 comptes exposés
Pokemon Gym : 19 600 comptes exposés
Fuite Pokemon Gym : 19 600 comptes de joueurs et joueuses, adresses IP et messages privés exposés.
 
Zataz.com 24/07/2026
Motherless : les serveurs saisis au cœur de l’enquête
Motherless : les serveurs saisis au cœur de l’enquête
La police saisit les serveurs du site pour adultes Motherless dans une enquête européenne sur des contenus vidéos criminels.
 
Zataz.com 24/07/2026
L’IA fait exploser les bénéfices de Google de 298 % : son action dégringole dans la foulée
L’IA fait exploser les bénéfices de Google de 298 % : son action dégringole dans la foulée
Alphabet revendique des chiffres qui donnent le vertige : 119,8 milliards de dollars de revenus et un bénéfice net historique de 112,1 milliards. Mais les investisseurs se montrent de plus en plus frileux face à une facture IA qui ne cesse de grimper.
 
Presse-citron 23/07/2026
Des modèles d’IA d’OpenAI se sont échappés d’un environnement de test et ont piraté la plateforme Hugging Face : une première cyberattaque autonome qui inquiète les experts
Des modèles d’IA d’OpenAI se sont échappés d’un environnement de test et ont piraté la plateforme Hugging Face : une première cyberattaque autonome qui inquiète les experts
Lors d'un test en interne qui a mal tourné, deux modèles d'IA sur lesquels travaillaient OpenAI ont réussi à s'affranchir de leur confinement pour aller compromettre, en toute autonomie, des serveurs d'Hugging Face.
 
Presse-citron 22/07/2026
Ce matin, Gemini devient plus rapide et plus performant : une mise à jour gratuite lance 2 nouveaux modèles d’IA pensés pour l’efficacité au travail
Ce matin, Gemini devient plus rapide et plus performant : une mise à jour gratuite lance 2 nouveaux modèles d’IA pensés pour l’efficacité au travail
Bonne nouvelle pour les utilisateurs de la version gratuite de Gemini. Google vient de lancer les modèles Gemini 3.6 Flash et Gemini 3.5 Flash-Lite. La firme indique également qu’elle est déjà en train de tester Gemini 3.5 Pro, une IA très attendue qui devrai…
 
Presse-citron 22/07/2026
Anubis menace Coca-Cola via Fairlife
Anubis menace Coca-Cola via Fairlife
Anubis menace Coca-Cola après une cyberattaque revendiquée contre Fairlife et fixe un ultimatum au 27 juillet.
 
Zataz.com 21/07/2026
Coinbase Cartel menace Caterpillar
Coinbase Cartel menace Caterpillar
Coinbase Cartel menace Caterpillar, expose une stratégie d’extorsion cyber publique et alerte sur des pirates qui usurpent le groupe pirate !
 
Zataz.com 21/07/2026
Une usurpation cible les services communication
Un escroc usurpe Damien Bancal et ZATAZ pour cibler les services communication par ingénierie sociale.
 
Zataz.com 21/07/2026
Fuite revendiquée au Rassemblement national ?
Fuite revendiquée au Rassemblement national ?
Un pirate affirme vendre des données présumés volés au Rassemblement national qui révélerait des données internes, sans preuve publique permettant d’authentifier la fuite à ce stade.
 
Zataz.com 21/07/2026
Hugging Face frappé par un agent cyber autonome
Hugging Face frappé par un agent cyber autonome
Une attaque autonome contre Hugging Face révèle les risques cyber des pipelines de données et des agents IA.
 
Zataz.com 21/07/2026
Europol flags 4,340 'horrific' URLs linked to The Com
Europol flags 4,340 'horrific' URLs linked to The Com
Stop the spread (of online recruiting and propaganda)
 
Theregister.com 24/07/2026
Hermes AI agent used to automate attack on Thai Finance Ministry
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
 
BleepingComputer 24/07/2026
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]
 
BleepingComputer 24/07/2026
Uncle Sam tells overseas cybercrooks their visas are canceled
Uncle Sam tells overseas cybercrooks their visas are canceled
Policy targets online scammers, sextortionists, and potentially their immediate families
 
Theregister.com 24/07/2026
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rar…
 
Securityaffairs.com 24/07/2026
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek.
 
Securityweek.com 24/07/2026
Man gets six years for hacking 750 women's Snapchat accounts
Man gets six years for hacking 750 women's Snapchat accounts
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]
 
BleepingComputer 24/07/2026
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a thr…
 
Internet 24/07/2026
Australian energy provider Origin says data breach exposes client data
Australian energy provider Origin says data breach exposes client data
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]
 
BleepingComputer 23/07/2026
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to …
 
Securityaffairs.com 23/07/2026
Year-long Russian attacks infect users as soon as they look at an email
Year-long Russian attacks infect users as soon as they look at an email
Phishing for dummies
 
Theregister.com 23/07/2026
Model Context Protocol prepares to break with its stateful past
Model Context Protocol prepares to break with its stateful past
Biggest overhaul since launch ditches sessions, guts little-used features, and leaves homebrew implementations facing a slog
 
Theregister.com 23/07/2026
Oracle drops 1,449 security patches like it's the new normal
Oracle drops 1,449 security patches like it's the new normal
Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
 
Theregister.com 23/07/2026
What Is Cryptocurrency and How Does It Actually Work?
What Is Cryptocurrency and How Does It Actually Work?
Learn how cryptocurrency works, from blockchains and wallets to private keys, custody, and secure transactions, with practical security tips. for confident use.
 
HackRead 23/07/2026
Iran-linked crews are probing more flavors of US industrial kit
Iran-linked crews are probing more flavors of US industrial kit
CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure
 
Theregister.com 23/07/2026
OpenAI's attack agent did exactly what it was told - just more relentlessly than expected
OpenAI's attack agent did exactly what it was told - just more relentlessly than expected
OpenAI's unintended attack on Hugging Face startled the world because its AI agent was acting on its own. But that's exactly what agentic AI is designed to do. We just didn't expect it to do it so well.
 
ZDNet 23/07/2026
Swiss train maker tells ransomware crooks to get off at the next stop
Swiss train maker tells ransomware crooks to get off at the next stop
Stadler refuses $12.3 demand after thieves swipe technical data through supplier platform
 
Theregister.com 23/07/2026
Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting
Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting
Google DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of…
 
Securityaffairs.com 23/07/2026
Google will let you upload a video selfie to recover your account - but should you?
Google will let you upload a video selfie to recover your account - but should you?
Google's new account recovery option prompts users to upload a selfie to prove their identity. Here's what to know.
 
ZDNet 23/07/2026
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. [...]
 
BleepingComputer 23/07/2026
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]
 
BleepingComputer 23/07/2026
OpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winning
OpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winning
Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused
 
Theregister.com 23/07/2026
OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning
OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning
Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused
 
Theregister.com 23/07/2026
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports file…
 
Internet 22/07/2026
OpenAI test model escaped on to internet & broke into a real company�s servers
OpenAI test model escaped on to internet & broke into a real company�s servers
OpenAI test model escaped on to internet & broke into a real company’s servers - posted in General Chat: https://www.cnn.com/2026/07/22/tech/openai-hugging-face-ai-cybersecurity   OpenAI says some of its experimental AI models left a test environment with no …
 
BleepingComputer 22/07/2026
OpenAI Models Escaped Test Environment and Breached Hugging Face
OpenAI Models Escaped Test Environment and Breached Hugging Face
OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers.
 
HackRead 22/07/2026
How enterprise GenAI can amplify ransomware risk — and how to contain it
How enterprise GenAI can amplify ransomware risk — and how to contain it
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while …
 
BleepingComputer 22/07/2026
Greedy ransomware crews return for seconds after victims cough up first extortion payments
Greedy ransomware crews return for seconds after victims cough up first extortion payments
Some never saw their files again either, infosec biz Proofpoint finds
 
Theregister.com 22/07/2026
CISA orders urgent action on actively exploited Langflow RCE flaw
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]
 
BleepingComputer 22/07/2026
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaw…
 
Securityaffairs.com 22/07/2026
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
OpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were…
 
Securityaffairs.com 22/07/2026
Anyone with a shed, an extension cord, a couple of GPUs and an overdraft is building datacenters. Fujitsu just offloaded five
Anyone with a shed, an extension cord, a couple of GPUs and an overdraft is building datacenters. Fujitsu just offloaded five
‘Digital transformation’ is a better bet, apparently, so private equity gets a turn
 
Theregister.com 22/07/2026
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]
 
BleepingComputer 22/07/2026
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI com…
 
Internet 22/07/2026
OpenAI admits it was the source of the agent swarm that attacked Hugging Face
OpenAI admits it was the source of the agent swarm that attacked Hugging Face
Sandboxed experiment found itself a zero day, escaped onto the open internet and stole data
 
Theregister.com 22/07/2026
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the …
 
Securityaffairs.com 21/07/2026
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Ch…
 
Securityweek.com 21/07/2026
Critical wp2shell WordPress flaws exploited to install webshells
Critical wp2shell WordPress flaws exploited to install webshells
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]
 
BleepingComputer 21/07/2026
Kratos phishing-as-a-service kit loses its battle with international law enforcement
Kratos phishing-as-a-service kit loses its battle with international law enforcement
Alleged developer arrested in Indonesia after more than 200 servers slain
 
Theregister.com 21/07/2026
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-025…
 
Securityaffairs.com 21/07/2026
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tec…
 
Internet 21/07/2026
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and C…
 
Internet 21/07/2026
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS…
 
Internet 21/07/2026
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE…
 
Securityaffairs.com 21/07/2026
Paramètres
from : recherche depuis .. jours (limité à 30)
max : nombre de réponses par requète
query : mot clé à rechercher. AND peut être utilisé
domains : liste des domaines internet à explorer
arrow_upward