Cybersécurité

Retrouvez toutes les actualités de cette catégorie dans une vue dédiée.

Cybersécurité

Retour aux actualités
Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack
CYBERSECURITY 28/03/2026 15:40

Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack

Threat actors with ties to Iran successfully broke into the personal email account of Kash Patel, the director of the U.S. Federal Bureau of Investigation (FBI), and leaked a cache of photos and other documents to the in

Source: The Hacker News

New Infinity Stealer malware grabs macOS data via ClickFix lures
CYBERSECURITY 28/03/2026 14:35

New Infinity Stealer malware grabs macOS data via ClickFix lures

A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka compiler. [...]

Source: BleepingComputer

Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
CYBERSECURITY 28/03/2026 09:11

Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug

A recently disclosed critical security flaw impacting Citrix NetScaler ADC and NetScaler Gateway is witnessing active reconnaissance activity, according to Defused Cyber and watchTowr. The vulnerability, CVE-2026-3055 (C

Source: The Hacker News

Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
CYBERSECURITY 27/03/2026 21:13

Backdoored Telnyx PyPI package pushes malware hidden in WAV audio

TeamPCP hackers compromised the Telnyx package on the Python Package Index today, uploading malicious versions that deliver credential-stealing malware hidden inside a WAV file. [...]

Source: BleepingComputer

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
CYBERSECURITY 28/03/2026 07:07

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices. The activity has been attributed

Source: The Hacker News

Fake VS Code alerts on GitHub spread malware to developers
CYBERSECURITY 27/03/2026 16:51

Fake VS Code alerts on GitHub spread malware to developers

A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code (VS Code) security alerts posted in the Discussions section of various projects, to trick users into downloading malware. [...]

Source: BleepingComputer

CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
CYBERSECURITY 28/03/2026 07:07

CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) catalog, citing evide

Source: The Hacker News

Agentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.
CYBERSECURITY 27/03/2026 14:02

Agentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.

Agentic GRC automates workflows, forcing teams to rethink their role beyond operations. Anecdotes explains why the biggest challenge is shifting from execution to risk leadership. [...]

Source: BleepingComputer

Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits
CYBERSECURITY 27/03/2026 17:22

Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits

Apple is now sending Lock Screen notifications to iPhones and iPads running older versions of iOS and iPadOS to alert users of web-based attacks and urge them to install the update. The development was first reported by

Source: The Hacker News

European Commission investigating breach after Amazon cloud account hack
CYBERSECURITY 27/03/2026 12:22

European Commission investigating breach after Amazon cloud account hack

The European Commission, the European Union's main executive body, is investigating a security breach after a threat actor gained access to the Commission's Amazon cloud environment. [...]

Source: BleepingComputer

TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
CYBERSECURITY 27/03/2026 16:53

TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files

TeamPCP, the threat actor behind the supply chain attack targeting Trivy, KICS, and litellm, has now compromised the telnyx Python package by pushing two malicious versions to steal sensitive data. The two versions, 4.87

Source: The Hacker News

Anti-piracy coalition takes down AnimePlay app with 5 million users
CYBERSECURITY 27/03/2026 10:40

Anti-piracy coalition takes down AnimePlay app with 5 million users

The Alliance for Creativity and Entertainment (ACE) announced the shutdown of AnimePlay, a major anime streaming platform with over 5 million users. [...]

Source: BleepingComputer

Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
CYBERSECURITY 27/03/2026 13:57

Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks

Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX's pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the

Source: The Hacker News

Windows 11 KB5079391 update rolls out Smart App Control improvements
CYBERSECURITY 27/03/2026 09:20

Windows 11 KB5079391 update rolls out Smart App Control improvements

​Microsoft has released the KB5079391 preview cumulative update for Windows 11 24H2 and 25H2, which includes 29 changes, such as Smart App Control and Display improvements. [...]

Source: BleepingComputer

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
CYBERSECURITY 27/03/2026 12:03

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion

Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social

Source: The Hacker News

Dutch Police discloses security breach after phishing attack
CYBERSECURITY 27/03/2026 08:20

Dutch Police discloses security breach after phishing attack

The Dutch National Police (Politie) says a security breach resulting from a successful phishing attack has had a limited impact and hasn't affected citizens' data. [...]

Source: BleepingComputer

We Are At War
CYBERSECURITY 27/03/2026 11:00

We Are At War

Rising geopolitical tensions are reflected (or in some cases preceded) by cyber operations, while technology itself has become politicized. Let’s admit it: we are in the middle of it.  Introduction: One tech power t

Source: The Hacker News

Ajax football club hack exposed fan data, enabled ticket hijack
CYBERSECURITY 26/03/2026 20:37

Ajax football club hack exposed fan data, enabled ticket hijack

Dutch professional football club Ajax Amsterdam (AFC Ajax) disclosed that a hacker exploited vulnerabilities in its IT systems and accessed data belonging to a few hundred people. [...]

Source: BleepingComputer

Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware
CYBERSECURITY 27/03/2026 10:04

Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware

A pro-Ukrainian group called Bearlyfy has been attributed to more than 70 cyber attacks targeting Russian companies since it first surfaced in the threat landscape in January 2025, with recent attacks leveraging a custom

Source: The Hacker News

CISA: New Langflow flaw actively exploited to hijack AI workflows
CYBERSECURITY 26/03/2026 19:17

CISA: New Langflow flaw actively exploited to hijack AI workflows

The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agen

Source: BleepingComputer

LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
CYBERSECURITY 27/03/2026 08:07

LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks

Cybersecurity researchers have disclosed three security vulnerabilities impacting LangChain and LangGraph that, if successfully exploited, could expose filesystem data, environment secrets, and conversation history. Both

Source: The Hacker News

UK sanctions Xinbi marketplace linked to Asian scam centers
CYBERSECURITY 26/03/2026 15:42

UK sanctions Xinbi marketplace linked to Asian scam centers

The United Kingdom's Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language cryptocurrency-based online marketplace that sells stolen data and satellite internet equipment to scam ne

Source: BleepingComputer

China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
CYBERSECURITY 26/03/2026 17:40

China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks

A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves impla

Source: The Hacker News

TikTok for Business accounts targeted in new phishing campaign
CYBERSECURITY 26/03/2026 14:09

TikTok for Business accounts targeted in new phishing campaign

Threat actors are targeting TikTok for Business accounts in a phishing campaign that prevents security bots from analyzing malicious pages. [...]

Source: BleepingComputer