Parce que… c’est l’épisode 0x639!
Shameless plug
12 au 17 octobre 2025 - Objective by the sea v814 et 15 octobre 2025 - ATT&CKcon 6.014 et 15 octobre 2025 - Forum inCyber CanadaCode rabais de 30% - CA25KDUX924 et 5 novembre 2025 - FAIRCON 20258 et 9 novembre 2025 - DEATHcon17 au 20 novembre 2025 - European Cyber Week25 et 26 février 2026 - SéQCure 2026CFPNotes
VulnérabilitésApple Font Parser Vulnerability Enables Malicious Fonts to Corrupt Process MemoryCritical Western Digital My Cloud NAS Vulnerability Allows Remote Code ExecutionVMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to RootChina Exploited New VMware Bug for Nearly a YearPoC exploit Released for VMware Workstation guest-to-host escape VulnerabilityTesla’s Telematics Control Unit Vulnerability Let Attackers Gain Code Execution as RootThreat Actors Allegedly Listed Veeam RCE Exploit for Sale on Dark WebCISA Warns of Linux Sudo Vulnerability Actively Exploited in AttacksWarnings about Cisco vulns under active exploit are falling on deaf earsOpenSSL Patches Three Flaws: Timing Side-Channel RCE Risk and Memory Corruption Affect All VersionsOneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate AppsMultiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript codeWindows 10 refuses to go gentle into that good nightUndead Operating Systems Haunt Enterprise Security NetworksPrivacyWestJet data breach exposes travel details of 1.2 million customersICE to Buy Tool that Tracks Locations of Hundreds of Millions of Phones Every DayAmazon’s Ring plans to scan everyone’s face at the doorPrivacy Harm Is HarmDonnées volées à Desjardins: les dossiers de 50 000 Québécois refont surface sur le «dark web»UK once again demands backdoor to Apple’s encrypted cloud storageFor a future with privacy, not mass surveillance, Germany must stand firmly against client-side canning in the Chat Control proposalMillions impacted by data breaches at insurance giant, auto dealership software firmSignal Protocol and Post-Quantum RatchetsMicrosoft’s Voice Clone Becomes Scary & UnsalvageableDiscord Data Breach – Customers Personal Data and Scanned Photo IDs leakedWinGuide cybersécurité des systèmes industrielsAnthropic touts safety, security improvements in Claude Sonnet 4.5New Google Drive Desktop Feature adds AI-powered Ransomware Detection to Prevent CyberattacksMISP 2.5.22 Released with improvements and bugs fixesMicrosoft to Launch New Secure Default Settings for Exchange and Teams APIsMicrosoft Outlook stops displaying inline SVG images used in attacksGmail business users can now send encrypted emails to anyoneDivers‘Trifecta’ of Google Gemini Flaws Turn AI Into Attack VehicleUn groupe de cybercriminels tente de corrompre un journaliste de la BBCNew China APT Strikes With Precision and PersistenceNorth Korea IT worker scheme expanding to more industries, countries outside of US tech sectorBeware! Threat Actors Distributing Malicious AI Tools as Chrome ExtensionsHackers Hijack Industrial Cellular Routers to Launch Widespread Smishing Campaigns Across EuropeUS gov shutdown leaves IT projects hanging, security defenders a skeleton crewTwo-thirds of CISA personnel could be sent home under shutdownEU consistently targeted by diverse yet convergent threat groupsAustria’s Armed Forces Gets Rid of Microsoft Office (Mostly) for LibreOfficeToken Trouble: How Leaked JWTs Let Me Become Everyone on the InternetInsolitesOne the craziest elements about cybersecurity is you have half the industry sat worrying about cyberwar!1! and going on about quantum and AI, then you have you have the operational reality of what is actually happening on the ground - it bares no resemblance, at all, to what people are focused on.Pentagon decrees warfighters don’t need ‘frequent’ cybersecurity trainingBeer Brewing Giant Asahi Halts Production Following CyberattackFreeIPA - CVE-2025-7493 - Privilege Escalation from host to domain adminCollaborateurs
Nicolas-Loïc FortinCrédits
Montage par Intrasecure incLocaux réels par Intrasecure inc