<?xml 
version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="http://www.globalsecuritymag.com/spip.php?page=backend.xslt" ?>
<rss version="2.0" 
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:atom="http://www.w3.org/2005/Atom"
>

<channel xml:lang="fr">
	<title>Global Security Mag Online</title>
	<link>https://www.globalsecuritymag.com/</link>
	<description></description>
	<language>fr</language>
	<generator>SPIP - www.spip.net</generator>
	<atom:link href="http://www.globalsecuritymag.com/spip.php?page=backend" rel="self" type="application/rss+xml" />




<item xml:lang="en">
		<title>Vigilance.fr - Exim: buffer overflow via SQlite Database Field, analyzed on 15/12/2025</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-exim-buffer-overflow-via-sqlite-database-field-analyzed-on-15-12.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-exim-buffer-overflow-via-sqlite-database-field-analyzed-on-15-12.html</guid>
		<dc:date>2026-09-15T05:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger a buffer overflow of Exim, via SQlite Database Field, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger a buffer overflow of Exim, via SQlite Database Field, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Exim-buffer-overflow-via-SQlite-Database-Field-49099" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Exim : buffer overflow via SQlite Database Field, analys&#233; le 15/12/2025</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-exim-buffer-overflow-via-sqlite-database-field-analyse-le-15-12.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-exim-buffer-overflow-via-sqlite-database-field-analyse-le-15-12.html</guid>
		<dc:date>2026-09-15T05:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer un buffer overflow de Exim, via SQlite Database Field, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer un buffer overflow de Exim, via SQlite Database Field, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Exim-buffer-overflow-via-SQlite-Database-Field-49099" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Pacing AI innovation? What gov'ts can/can't do, what orgs. Must</title>
		<link>http://www.globalsecuritymag.com/pacing-ai-innovation-what-gov-ts-can-can-t-do-what-orgs-must.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/pacing-ai-innovation-what-gov-ts-can-can-t-do-what-orgs-must.html</guid>
		<dc:date>2026-09-14T21:42:17Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Approov, Black Hills Information Security, Liquibase, Secure.com, Suzu Labs, Xcape Inc.</dc:creator>


		<dc:subject>primetime</dc:subject>

		<description>
&lt;p&gt;Following this weekend's essay from Anthropic CEO Dario Amodei (linked at bottom) recommending pacing AI development, here are expert perspectives on the pace of AI frontier models, what governments can and can't do, and how (and whether) businesses can keep their AI agents in check and within the organization's boundaries. Ted Miracco, CEO, Approov &#034;Government regulations will never move fast enough to keep pace with AI development, but the industry doesn't need to wait for (&#8230;)&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Opinions-.html" rel="directory"&gt;Opinion&lt;/a&gt;

/ 
&lt;a href="http://www.globalsecuritymag.com/+-primetime-+.html" rel="tag"&gt;primetime&lt;/a&gt;

		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Following this weekend's essay from Anthropic CEO Dario Amodei (linked at bottom) recommending pacing AI development, here are expert perspectives on the pace of AI frontier models, what governments can and can't do, and how (and whether) businesses can keep their AI agents in check and within the organization's boundaries.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ted Miracco, CEO, Approov&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#034;Government regulations will never move fast enough to keep pace with AI development, but the industry doesn't need to wait for governments to add guardrails. The most effective safeguard is simple product liability. If AI companies are held legally and financially responsible for the misuse of their products, safety could become a foundational feature rather than an afterthought. Today, we need to be less concerned about AI gaining sentience and spinning up its own attacks on humanity. The real, immediate dangers involve bad actors weaponizing AI as a force multiplier to cripple critical infrastructure or potentially paralyze the banking system.&#034;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; Jeremiah Fowler, Cybersecurity Researcher, Black Hills Information Security&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#034;The uncomfortable truth is that AI companies have an incentive to develop advanced models that are better than their competition. In my opinion, voluntary restraint will likely not be a real solution because nobody wants to fall behind in the AI arms race. I don't mean that in terms of cyberwarfare or conflict (yet), but it is good that we are starting the conversation around the worst-case scenarios and how to prevent them.&lt;/p&gt;
&lt;p&gt;History has shown us that the approach of letting the market or industry regulate itself doesn't always work and in reality, technology and innovation are moving light speed and far faster than oversight or regulation can keep up with. I think we do need real guardrails on AI. In many cases it seems like functionality was launched first and now we are at the stage where security needs to be added after realizing there have been incidents and the risks are real. Any serious AI guardrails should have enforceable minimum safety standards, independent testing and auditing, limits on autonomous permissions, and the most important part, don't fully remove the humans.&#034;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Eric Capuano, Director of SOC Operations, Black Hills Information Security&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#034;The OpenAI incident in July is a useful example. A model given a testing goal went outside its lane, got into another company's systems, and the operators found out after the fact. That is not a swarm taking over the internet. That is an agent with too much access, too little scoping, and nobody watching the logs in real time. Every SOC has seen that exact failure with a human contractor or a misconfigured service account. The difference is speed and volume.&lt;/p&gt;
&lt;p&gt;Companies do not need to wait on Washington for the fixes, because the fixes aren't new. Every agent gets its own identity with the narrowest permissions that still let it do the job. Agents run on segmented infrastructure with default-deny egress, so an agent cannot reach a target that it was never supposed to touch. Every action the agent takes is logged as an action, not buried in a chat transcript, and those logs land in the same place the SOC already monitors. Anything that writes, deletes, moves money, or touches production requires a human approval step until you have enough history to justify removing it. Someone owns the kill switch and has tested it.&lt;/p&gt;
&lt;p&gt;Where government can help is on the after side. The frontier labs are proposing embedded outside evaluators, which is fine, but evaluation before deployment tells you what a model does in a lab. What defenders need is mandatory reporting when an agent causes a security incident in the field, with enough technical detail that the rest of us can build detections from it. We did not learn to defend against ransomware from pre-release testing. We learned from incident writeups. Agents will be the same.&#034;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ryan McCurdy, VP, Liquibase:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#034;No one should expect AI agents to be perfectly predictable, instead, we should build around the assumption that they won't be. As agents gain access to more tools, credentials, and production systems, enterprises need to define what they can access, what they can change, what they can decide on their own, and what policies have to be met before an action reaches a critical system.&lt;/p&gt;
&lt;p&gt;The answer also can't be putting a human in front of every decision. AI is moving too quickly and that defeats much of the reason companies are adopting agents in the first place. Governance has to operate at the same speed as the systems it's governing.&lt;/p&gt;
&lt;p&gt;Government policy and the AI industry have a role in establishing standards for how these systems are developed and tested. But every enterprise still has to decide where AI is allowed to act inside its own environment. You don't need to predict every decision an agent might make if you control what it's allowed to turn into action.&#034;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Waseem Ahmed, Head of Engineering, Secure.com&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#034;The essay lands at the right time because AI agents are already acting on their own inside real company systems, and the OpenClaw ban wave earlier this year showed how fast that goes wrong when an agent has broad access and no leash.&lt;/p&gt;
&lt;p&gt;Slowing the pace matters, but enterprises cannot wait for that. The controls that protect us most are least privilege, network isolation, and sandboxing, so an agent can only touch what its job needs and nothing else.&lt;/p&gt;
&lt;p&gt;Give every agent its own identity, log every action it takes, and never let it run high-impact steps like disabling accounts or changing settings without a real person approving first. Traditional testing alone will not keep up, so we watch these agents continuously in production.&lt;/p&gt;
&lt;p&gt;Independent oversight should mean outside reviewers who can inspect the logs and confirm the agent stayed inside the boundaries we set.&#034;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Denis Calderone, CTO, Suzu Labs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#034;Enterprises must secure AI agents that can act autonomously across corporate systems - the agent is the new contractor or the new internal threat vector. The agent has a specific job, specific access requirements, and a bounded set of actions it should be performing. Enterprises need to treat every AI agent the same way they'd treat any other agent on the network, human or otherwise. Every agent must have its own machine identity, task-scoped credentials that expire when the job is done, and observability into everything it does. Not a shared service account or API token, but instead a distinct, auditable identity per agent per task.&lt;/p&gt;
&lt;p&gt;Because agents are purpose-built, modeling normal behavior is easier than it is for humans. A human user's workday is unpredictable. An agent doing invoice processing should only be touching invoices. Any deviation from that pattern is an immediate signal, cleaner than those you typically get from human behavioral analytics.&lt;/p&gt;
&lt;p&gt;Enterprises need to be disciplined about keeping the security and observability stack architecturally separated from the agent's operational environment. For example, say you deploy an agent to handle IT operations such as patching, config changes, routine maintenance, etc. If that agent has visibility into the monitoring and alerting system that flags anomalous behavior, it will learn which actions trigger alerts and potentially choose to route around them. Not because it's adversarial, but because it might just be trying to remove friction between itself and some obstacle in the way of achieving its goal. This is basically what happened in the OpenAI-Hugging Face incident where 700 agents organized a collective R&amp;D effort to reverse-engineer and defeat the evaluation system scoring them; it was easier to cheat to achieve the task. The agents worked hard to figure out how to generate its own flags, and then how to defeat a presumed causal check in the scoring workflow.&lt;/p&gt;
&lt;p&gt;This the same architectural principle and precautions we take when implementing a SIEM. We deploy out of band, on a separate management network and we try to make it invisible to the workloads it monitors.&#034;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Donald McFarlane, Board Member, Xcape Inc.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#034;AI does not develop an agenda; its operators do. When we give an autonomous system powerful access and ability to act at machine speed, they will continue to prove highly capable.&lt;/p&gt;
&lt;p&gt;Rules enacted in the name of safety must not become a moat against competition or progress. Enormous compliance costs may be manageable for the handful of companies already spending billions building frontier models, while becoming a substantial barrier to everyone behind them.&lt;/p&gt;
&lt;p&gt;Government can help clarify accountability and duties of care, and facilitate strong information sharing and collective defense, which is an area where we sorely need more effective public-private partnerships.&lt;/p&gt;
&lt;p&gt;But safeguards should focus on how these systems are used and deployed, rather than deciding who is allowed to build powerful AI in the first place.&lt;/p&gt;
&lt;p&gt;The goal should be safer deployment without pulling up the drawbridge on innovation.&#034;&lt;/p&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Revolut tricked into handing over passports, financial data through fake gov't requests - Expert Comments </title>
		<link>http://www.globalsecuritymag.com/revolut-tricked-into-handing-over-passports-financial-data-through-fake-gov-t.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/revolut-tricked-into-handing-over-passports-financial-data-through-fake-gov-t.html</guid>
		<dc:date>2026-09-14T21:06:58Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Suzu Labs, Black Hills Information Security and Xcape Inc.</dc:creator>


		<dc:subject>primetime</dc:subject>

		<description>&lt;p&gt;&lt;strong&gt;Digital banking and financial services platform Revolut has confirmed a data breach after an unauthorized party used an email account on a legitimate government agency domain to submit fraudulent requests for customer information, according to crypto investigator ZachXBT, who shared a customer notification sent out by the company. Revolut said its own systems were not compromised and customer funds were not affected.&lt;/strong&gt;&lt;/p&gt;

-
&lt;a href="http://www.globalsecuritymag.com/-Opinions-.html" rel="directory"&gt;Opinion&lt;/a&gt;

/ 
&lt;a href="http://www.globalsecuritymag.com/+-primetime-+.html" rel="tag"&gt;primetime&lt;/a&gt;

		</description>


 <content:encoded>&lt;div class='rss_chapo'&gt;&lt;p&gt;&lt;strong&gt;Digital banking and financial services platform Revolut has confirmed a data breach after an unauthorized party used an email account on a legitimate government agency domain to submit fraudulent requests for customer information, according to crypto investigator ZachXBT, who shared a customer notification sent out by the company. Revolut said its own systems were not compromised and customer funds were not affected.&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
		&lt;div class='rss_texte'&gt;&lt;p&gt;The information disclosed may include names, dates of birth, addresses, phone numbers, email addresses and copies of passports and driver's licenses, as well as verification selfies. Some affected customers were also told that account statements, IBANs, withdrawal records and full transaction histories, including Bitcoin transactions, may have been exposed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Revolut&lt;/strong&gt; has not disclosed how many customers were affected or identified the government agency whose email domain was used. The company blocked the email address after discovering the scheme.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ZachXBT&lt;/strong&gt; reported that the incident appeared to target high-net-worth customers, although Revolut has not confirmed that claim. Revolut currently serves more than 80 million customers worldwide.&lt;/p&gt;
&lt;p&gt;Experts with Suzu Labs, Black Hills Information Security and Xcape Inc. offer perspectives on the matter.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Denis Calderone, CTO, Suzu Labs:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#8220;This attacker wasn't spoofing a government email address. They were logged into a legitimate government agency's email infrastructure and sent the request from inside it. SPF passed. DKIM passed. And Revolut's compliance team treated that as sufficient verification to release passports, driver's licenses, verification selfies, full transaction histories including Bitcoin activity, IBANs, and withdrawal records for what appears to be a targeted set of high-net-worth customers.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;Think about how most financial institutions handle a wire transfer request. You get the request, you verify it through an independent channel, you call back on a known number, you confirm authorization. Nobody releases six figures based solely on the fact that the email came from a real domain. But that appears to be essentially what happened here with data that, for affected customers, is more damaging than a wire fraud loss. You can reverse a wire. You can't un-leak a passport.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;The FBI's November 2024 Private Industry Notification on fraudulent data requests laid out a model that applies here. That advisory focused on emergency requests, but the core prescriptions are just as relevant for routine government data requests, especially when the data being released is this sensitive. The FBI told companies to &#034;apply critical thinking to any emergency data requests received&#034; and recommended &#034;contacting the sender and originating authority to discuss the request further.&#034; Whether a request comes in as an emergency or through standard legal compliance channels, the data being handed over is the same. Passports, KYC selfies, and full financial transaction histories don't become less valuable to an attacker because the request wasn't urgent. Out-of-band verification, callback procedures to independently verified agency contacts, and specialized legal request intake portals should be standard for any government data request involving sensitive customer records, not just the ones that come in marked urgent.&#8221;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;John Strand, Owner, Black Hills Information Security, Inc.:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#8220;This story just highlights that no matter how advanced defensive technology gets, and no matter how sophisticated attacks become with all the new exploits we're seeing, the human element is still one of the easiest ways to get access to data.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;What makes this one particularly interesting is how targeted the attackers were. To be honest, that makes the attack look even more realistic. They clearly had some understanding of the normal processes, how those processes worked, and the channels these requests would normally come through.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;That's critical for an attacker trying to pull something like this off. And once again, it proves that technology alone is not going to save us.&#8221;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Eric Capuano, Director of SOC Operations, Black Hills Information Security:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#8220;Revolut called this a sophisticated external impersonation scam. It was not. Someone sent email from a mailbox on a real government agency domain, and every technical check Revolut ran came back clean because the mail genuinely came from that domain. SPF and DKIM confirm a message came from where it claims. They say nothing about who is sitting at the keyboard. Revolut's own notification says the quiet part out loud: the request carried valid domain authentication, so it was fulfilled. That is authentication being treated as authorization, and it is the entire incident.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;The company says its systems were not compromised, and that is accurate and beside the point. The data walked out through a process working as designed. In most companies the government and law enforcement request queue is a shared mailbox, a person with a legal obligation, and a deadline. There is usually no callback to a number the company looked up itself, no second approver, and no logging that the SOC ever sees. Nobody gets an alert when the compliance team emails passport scans, verification selfies, and a full transaction history to an outside address, because that is a Tuesday for that team. Security spends its budget on the front door and this stuff goes out the loading dock.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;The customers are the ones stuck with it. A password gets rotated in a minute. A passport number, a date of birth, and the selfie you took to open the account do not. Those are the exact artifacts other institutions accept to verify identity and to recover an account, so the people in this set are now easier to impersonate everywhere else they bank. Pair that with full transaction history and Bitcoin records, and whoever received it has a list of who is worth working on and how much they are worth. ZachXBT says it looks like high net worth customers were the target and Revolut has not confirmed that, but targeting would fit what was asked for.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;Three things worth doing this week if you handle customer data. Find out who at your company can fulfill a government or law enforcement request and have them walk you through it while you watch. If the verification step is that the email passed authentication, add an out-of-band callback to a number you pull from the agency's own published directory, plus a second approver for anything involving identity documents or full account history. Then get that queue logged somewhere the SOC reads, because right now most of us cannot even reconstruct what left. And if you have ever received requests from that agency, go pull your mail logs for the same window. A mailbox that gets used once usually gets used more than once.&#8221;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Donald McFarlane, Board Member, Xcape Inc.:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&#8220;Financial institutions may be required to retain sensitive identity information, but that makes strict controls and data minimization more important, not less.&#034;&lt;/p&gt;
&lt;p&gt;&#8220;We should not be yeeting passports, transaction histories and other sensitive customer data to someone simply because a request arrives from a government email address. A government domain is not a substitute for authenticating a valid warrant and its legal authority, and using a secure process to return the information.&#8221;&lt;/p&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Siemens SIMATIC S7-PLCSIM Advanced: overload via Multicast Network Traffic, analyzed on 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-siemens-simatic-s7-plcsim-advanced-overload-via-multicast-network.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-siemens-simatic-s7-plcsim-advanced-overload-via-multicast-network.html</guid>
		<dc:date>2026-09-14T14:51:16Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger an overload of Siemens SIMATIC S7-PLCSIM Advanced, via Multicast Network Traffic, in order to trigger a denial of service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger an overload of Siemens SIMATIC S7-PLCSIM Advanced, via Multicast Network Traffic, in order to trigger a denial of service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Siemens-SIMATIC-S7-PLCSIM-Advanced-overload-via-Multicast-Network-Traffic-52022" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Siemens SIMATIC S7-PLCSIM Advanced : surcharge via Multicast Network Traffic, analys&#233; le 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-siemens-simatic-s7-plcsim-advanced-surcharge-via-multicast-network.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-siemens-simatic-s7-plcsim-advanced-surcharge-via-multicast-network.html</guid>
		<dc:date>2026-09-14T14:51:16Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer une surcharge de Siemens SIMATIC S7-PLCSIM Advanced, via Multicast Network Traffic, afin de mener un d&#233;ni de service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer une surcharge de Siemens SIMATIC S7-PLCSIM Advanced, via Multicast Network Traffic, afin de mener un d&#233;ni de service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Siemens-SIMATIC-S7-PLCSIM-Advanced-surcharge-via-Multicast-Network-Traffic-52022" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Xen: Man-in-the-Middle via XAPI SDKs, analyzed on 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-xen-man-in-the-middle-via-xapi-sdks-analyzed-on-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-xen-man-in-the-middle-via-xapi-sdks-analyzed-on-14-07-2026.html</guid>
		<dc:date>2026-09-14T14:41:10Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can act as a Man-in-the-Middle on Xen, via XAPI SDKs, in order to read or write data in the session.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can act as a Man-in-the-Middle on Xen, via XAPI SDKs, in order to read or write data in the session.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Xen-Man-in-the-Middle-via-XAPI-SDKs-52021" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Xen : Man-in-the-Middle via XAPI SDKs, analys&#233; le 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-xen-man-in-the-middle-via-xapi-sdks-analyse-le-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-xen-man-in-the-middle-via-xapi-sdks-analyse-le-14-07-2026.html</guid>
		<dc:date>2026-09-14T14:41:10Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut se positionner en Man-in-the-Middle sur Xen, via XAPI SDKs, afin de lire ou modifier des donn&#233;es de la session.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut se positionner en Man-in-the-Middle sur Xen, via XAPI SDKs, afin de lire ou modifier des donn&#233;es de la session.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Xen-Man-in-the-Middle-via-XAPI-SDKs-52021" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Notepad++: five vulnerabilities dated 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-notepad-five-vulnerabilities-dated-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-notepad-five-vulnerabilities-dated-14-07-2026.html</guid>
		<dc:date>2026-09-14T14:39:53Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can use several vulnerabilities of Notepad++, dated 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can use several vulnerabilities of Notepad++, dated 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Notepad-five-vulnerabilities-dated-14-07-2026-52020" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Notepad++ : cinq vuln&#233;rabilit&#233;s du 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-notepad-cinq-vulnerabilites-du-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-notepad-cinq-vulnerabilites-du-14-07-2026.html</guid>
		<dc:date>2026-09-14T14:39:53Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Notepad++, du 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Notepad++, du 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Notepad-cinq-vulnerabilites-du-14-07-2026-52020" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>


<item xml:lang="fr">
		<title>Vigilance.fr - Apache Tomcat : deux vuln&#233;rabilit&#233;s du 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apache-tomcat-deux-vulnerabilites-du-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apache-tomcat-deux-vulnerabilites-du-14-07-2026.html</guid>
		<dc:date>2026-09-14T13:30:06Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Apache Tomcat, du 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Apache Tomcat, du 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Apache-Tomcat-deux-vulnerabilites-du-14-07-2026-52017" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Apache Tomcat: two vulnerabilities dated 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apache-tomcat-two-vulnerabilities-dated-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apache-tomcat-two-vulnerabilities-dated-14-07-2026.html</guid>
		<dc:date>2026-09-14T13:30:06Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can use several vulnerabilities of Apache Tomcat, dated 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can use several vulnerabilities of Apache Tomcat, dated 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Apache-Tomcat-two-vulnerabilities-dated-14-07-2026-52017" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Noyau Linux : deux vuln&#233;rabilit&#233;s du 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-noyau-linux-deux-vulnerabilites-du-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-noyau-linux-deux-vulnerabilites-du-14-07-2026.html</guid>
		<dc:date>2026-09-14T13:27:58Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s du noyau Linux, du 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s du noyau Linux, du 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Noyau-Linux-deux-vulnerabilites-du-14-07-2026-52016" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Linux kernel: two vulnerabilities dated 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-linux-kernel-two-vulnerabilities-dated-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-linux-kernel-two-vulnerabilities-dated-14-07-2026.html</guid>
		<dc:date>2026-09-14T13:27:58Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can use several vulnerabilities of the Linux kernel, dated 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can use several vulnerabilities of the Linux kernel, dated 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Linux-kernel-two-vulnerabilities-dated-14-07-2026-52016" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Perl Core : d&#233;bordement d'entier via S_measure_struct(), analys&#233; le 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-perl-core-debordement-d-entier-via-s_measure_struct-analyse-le-14.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-perl-core-debordement-d-entier-via-s_measure_struct-analyse-le-14.html</guid>
		<dc:date>2026-09-14T13:20:09Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer un d&#233;bordement d'entier de Perl Core, via S_measure_struct(), afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer un d&#233;bordement d'entier de Perl Core, via S_measure_struct(), afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Perl-Core-debordement-d-entier-via-S-measure-struct-52015" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Perl Core: integer overflow via S_measure_struct(), analyzed on 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-perl-core-integer-overflow-via-s_measure_struct-analyzed-on-14-07.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-perl-core-integer-overflow-via-s_measure_struct-analyzed-on-14-07.html</guid>
		<dc:date>2026-09-14T13:20:09Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger an integer overflow of Perl Core, via S_measure_struct(), in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger an integer overflow of Perl Core, via S_measure_struct(), in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Perl-Core-integer-overflow-via-S-measure-struct-52015" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Perl Core : corruption de m&#233;moire via Regular Expression Matches, analys&#233; le 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-perl-core-corruption-de-memoire-via-regular-expression-matches.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-perl-core-corruption-de-memoire-via-regular-expression-matches.html</guid>
		<dc:date>2026-09-14T13:18:37Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer une corruption de m&#233;moire de Perl Core, via Regular Expression Matches, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer une corruption de m&#233;moire de Perl Core, via Regular Expression Matches, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Perl-Core-corruption-de-memoire-via-Regular-Expression-Matches-52014" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Perl Core: memory corruption via Regular Expression Matches, analyzed on 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-perl-core-memory-corruption-via-regular-expression-matches.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-perl-core-memory-corruption-via-regular-expression-matches.html</guid>
		<dc:date>2026-09-14T13:18:37Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger a memory corruption of Perl Core, via Regular Expression Matches, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger a memory corruption of Perl Core, via Regular Expression Matches, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Perl-Core-memory-corruption-via-Regular-Expression-Matches-52014" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Eclipse Jetty : deux vuln&#233;rabilit&#233;s du 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-deux-vulnerabilites-du-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-deux-vulnerabilites-du-14-07-2026.html</guid>
		<dc:date>2026-09-14T13:09:26Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Eclipse Jetty, du 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Eclipse Jetty, du 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Eclipse-Jetty-deux-vulnerabilites-du-14-07-2026-52013" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Eclipse Jetty: two vulnerabilities dated 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-two-vulnerabilities-dated-14-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-two-vulnerabilities-dated-14-07-2026.html</guid>
		<dc:date>2026-09-14T13:09:26Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can use several vulnerabilities of Eclipse Jetty, dated 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can use several vulnerabilities of Eclipse Jetty, dated 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Eclipse-Jetty-two-vulnerabilities-dated-14-07-2026-52013" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Eclipse Jetty : deux vuln&#233;rabilit&#233;s du 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-deux-vulnerabilites-du-14-07-2026-178445.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-deux-vulnerabilites-du-14-07-2026-178445.html</guid>
		<dc:date>2026-09-14T13:08:24Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Eclipse Jetty, du 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Eclipse Jetty, du 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Eclipse-Jetty-deux-vulnerabilites-du-14-07-2026-52012" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Eclipse Jetty: two vulnerabilities dated 14/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-two-vulnerabilities-dated-14-07-2026-178451.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-eclipse-jetty-two-vulnerabilities-dated-14-07-2026-178451.html</guid>
		<dc:date>2026-09-14T13:08:24Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can use several vulnerabilities of Eclipse Jetty, dated 14/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can use several vulnerabilities of Eclipse Jetty, dated 14/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Eclipse-Jetty-two-vulnerabilities-dated-14-07-2026-52012" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vuln&#233;rabilit&#233; dans CPython (14 septembre 2026)</title>
		<link>http://www.globalsecuritymag.com/vulnerabilite-dans-cpython-14-septembre-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vulnerabilite-dans-cpython-14-septembre-2026.html</guid>
		<dc:date>2026-09-14T02:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		



		<description>
&lt;p&gt;Une vuln&#233;rabilit&#233; a &#233;t&#233; d&#233;couverte dans CPython. Elle permet &#224; un attaquant de provoquer un probl&#232;me de s&#233;curit&#233; non sp&#233;cifi&#233; par l'&#233;diteur.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Une vuln&#233;rabilit&#233; a &#233;t&#233; d&#233;couverte dans CPython. Elle permet &#224; un attaquant de provoquer un probl&#232;me de s&#233;curit&#233; non sp&#233;cifi&#233; par l'&#233;diteur.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1167/" class="spip_out"&gt;https://www.cert.ssi.gouv.fr/avis/C...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Multiples vuln&#233;rabilit&#233;s dans Microsoft Edge (14 septembre 2026)</title>
		<link>http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-microsoft-edge-14-septembre-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-microsoft-edge-14-septembre-2026.html</guid>
		<dc:date>2026-09-14T02:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		



		<description>
&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans Microsoft Edge. Elles permettent &#224; un attaquant de provoquer un contournement de la politique de s&#233;curit&#233; et un probl&#232;me de s&#233;curit&#233; non sp&#233;cifi&#233; par l'&#233;diteur. Microsoft indique que la vuln&#233;rabilit&#233; CVE-2026-87491 est activement exploit&#233;e.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans Microsoft Edge. Elles permettent &#224; un attaquant de provoquer un contournement de la politique de s&#233;curit&#233; et un probl&#232;me de s&#233;curit&#233; non sp&#233;cifi&#233; par l'&#233;diteur. Microsoft indique que la vuln&#233;rabilit&#233; CVE-2026-87491 est activement exploit&#233;e.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1171/" class="spip_out"&gt;https://www.cert.ssi.gouv.fr/avis/C...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Bulletin d'actualit&#233; CERTFR-2026-ACT-039 (14 septembre 2026)</title>
		<link>http://www.globalsecuritymag.com/bulletin-d-actualite-certfr-2026-act-039-14-septembre-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/bulletin-d-actualite-certfr-2026-act-039-14-septembre-2026.html</guid>
		<dc:date>2026-09-14T02:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		



		<description>
&lt;p&gt;Ce bulletin d'actualit&#233; du CERT-FR revient sur les vuln&#233;rabilit&#233;s significatives de la semaine pass&#233;e pour souligner leurs criticit&#233;s. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publi&#233;s par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Ce bulletin d'actualit&#233; du CERT-FR revient sur les vuln&#233;rabilit&#233;s significatives de la semaine pass&#233;e pour souligner leurs criticit&#233;s. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publi&#233;s par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-039/" class="spip_out"&gt;https://www.cert.ssi.gouv.fr/actual...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Multiples vuln&#233;rabilit&#233;s dans MISP (14 septembre 2026)</title>
		<link>http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-misp-14-septembre-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-misp-14-septembre-2026.html</guid>
		<dc:date>2026-09-14T02:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		



		<description>
&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans MISP. Certaines d'entre elles permettent &#224; un attaquant de provoquer un d&#233;ni de service &#224; distance, une atteinte &#224; la confidentialit&#233; des donn&#233;es et une atteinte &#224; l'int&#233;grit&#233; des donn&#233;es.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans MISP. Certaines d'entre elles permettent &#224; un attaquant de provoquer un d&#233;ni de service &#224; distance, une atteinte &#224; la confidentialit&#233; des donn&#233;es et une atteinte &#224; l'int&#233;grit&#233; des donn&#233;es.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1170/" class="spip_out"&gt;https://www.cert.ssi.gouv.fr/avis/C...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Multiples vuln&#233;rabilit&#233;s dans Squid (14 septembre 2026)</title>
		<link>http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-squid-14-septembre-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-squid-14-septembre-2026.html</guid>
		<dc:date>2026-09-14T02:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		



		<description>
&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans Squid. Certaines d'entre elles permettent &#224; un attaquant de provoquer un d&#233;ni de service &#224; distance, une atteinte &#224; l'int&#233;grit&#233; des donn&#233;es et un contournement de la politique de s&#233;curit&#233;.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans Squid. Certaines d'entre elles permettent &#224; un attaquant de provoquer un d&#233;ni de service &#224; distance, une atteinte &#224; l'int&#233;grit&#233; des donn&#233;es et un contournement de la politique de s&#233;curit&#233;.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1168/" class="spip_out"&gt;https://www.cert.ssi.gouv.fr/avis/C...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Multiples vuln&#233;rabilit&#233;s dans MongoDB (14 septembre 2026)</title>
		<link>http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-mongodb-14-septembre-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/multiples-vulnerabilites-dans-mongodb-14-septembre-2026.html</guid>
		<dc:date>2026-09-14T02:00:00Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		



		<description>
&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans MongoDB. Certaines d'entre elles permettent &#224; un attaquant de provoquer un d&#233;ni de service &#224; distance, une atteinte &#224; la confidentialit&#233; des donn&#233;es et une atteinte &#224; l'int&#233;grit&#233; des donn&#233;es.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;De multiples vuln&#233;rabilit&#233;s ont &#233;t&#233; d&#233;couvertes dans MongoDB. Certaines d'entre elles permettent &#224; un attaquant de provoquer un d&#233;ni de service &#224; distance, une atteinte &#224; la confidentialit&#233; des donn&#233;es et une atteinte &#224; l'int&#233;grit&#233; des donn&#233;es.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1169/" class="spip_out"&gt;https://www.cert.ssi.gouv.fr/avis/C...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>CYBERBREW : Le Nord de la France va bient&#244;t accueillir un nouvel &#233;v&#232;nement Cyber !</title>
		<link>http://www.globalsecuritymag.com/cyberbrew-le-nord-de-la-france-va-bientot-accueillir-un-nouvel-evenement-cyber.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/cyberbrew-le-nord-de-la-france-va-bientot-accueillir-un-nouvel-evenement-cyber.html</guid>
		<dc:date>2026-09-13T17:18:45Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Valentin Jangwa, Global Security Mag</dc:creator>


		<dc:subject>affiche</dc:subject>
		<dc:subject>evenement_milieu</dc:subject>

		<description>&lt;p&gt;&lt;strong&gt;En effet, le Mardi 15 septembre 2026, &#224; Lille, la premi&#232;re &#233;dition de &lt;br class='autobr' /&gt;
CYBERBREW sera lanc&#233;e ! &lt;/strong&gt;&lt;/p&gt;

-
&lt;a href="http://www.globalsecuritymag.com/-Evenements-.html" rel="directory"&gt;&#201;v&#232;nements&lt;/a&gt;

/ 
&lt;a href="http://www.globalsecuritymag.com/+-affiche-+.html" rel="tag"&gt;affiche&lt;/a&gt;, 
&lt;a href="http://www.globalsecuritymag.com/+-evenement_milieu-+.html" rel="tag"&gt;evenement_milieu&lt;/a&gt;

		</description>


 <content:encoded>&lt;div class='rss_chapo'&gt;&lt;p&gt;&lt;strong&gt;En effet, le Mardi 15 septembre 2026, &#224; Lille, la premi&#232;re &#233;dition de &lt;br class='autobr' /&gt;
CYBERBREW sera lanc&#233;e ! &lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
		&lt;div class='rss_texte'&gt;&lt;div class='spip_document_18760 spip_document spip_documents spip_document_image spip_documents_center spip_document_center'&gt;
&lt;figure class=&#034;spip_doc_inner&#034;&gt; &lt;img src='http://www.globalsecuritymag.com/local/cache-vignettes/L136xH160/cyberbrew_logo_-_copie-ea95b.jpg?1789319932' width='136' height='160' alt='' /&gt;
&lt;/figure&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a href=&#034;https://cyberbrew.tech/&#034; class=&#034;spip_url spip_out auto&#034; rel=&#034;nofollow external&#034;&gt;https://cyberbrew.tech/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Une journ&#233;e qui sera rythm&#233;e par des Conf&#233;rences Cyber, des bi&#232;res artisanales et des rencontres. Des &#171; talks &#187; pointus et concrets par des expert.e.s cyber, des partages d'exp&#233;riences et de bonnes pratiques.&lt;br class='autobr' /&gt;
Bi&#232;res artisanales s&#233;lectionn&#233;es. Des brasseurs passionn&#233;s, des rencontres et des d&#233;gustations tout au long de la journ&#233;e.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ecosyst&#232;me &amp; networking.&lt;/strong&gt; &#201;changes, partages et connexions dans une ambiance &lt;br class='autobr' /&gt;
d&#233;tendue et conviviale.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Des sujets autour de : &lt;/strong&gt; &lt;br class='autobr' /&gt;
Keynotes, RETEX, Incident Response, Blue Team, ICS / SCADA, Pentest, VOC, OSINT Forensic.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;De bons moments en perspective, au sein d'un lieu embl&#233;matique :&lt;/strong&gt; &lt;br class='autobr' /&gt;
EURATECHNOLOGIES&lt;br class='autobr' /&gt;
165 Av. de Bretagne, 59000 Lille.&lt;/p&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - GIMP: buffer overflow via PSP File Parsing, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-gimp-buffer-overflow-via-psp-file-parsing-analyzed-on-13-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-gimp-buffer-overflow-via-psp-file-parsing-analyzed-on-13-07-2026.html</guid>
		<dc:date>2026-09-13T14:19:55Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger a buffer overflow of GIMP, via PSP File Parsing, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger a buffer overflow of GIMP, via PSP File Parsing, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/GIMP-buffer-overflow-via-PSP-File-Parsing-52010" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - GIMP : buffer overflow via PSP File Parsing, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-gimp-buffer-overflow-via-psp-file-parsing-analyse-le-13-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-gimp-buffer-overflow-via-psp-file-parsing-analyse-le-13-07-2026.html</guid>
		<dc:date>2026-09-13T14:19:55Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer un buffer overflow de GIMP, via PSP File Parsing, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer un buffer overflow de GIMP, via PSP File Parsing, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/GIMP-buffer-overflow-via-PSP-File-Parsing-52010" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Avahi: buffer overflow via Resource Records Names, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-avahi-buffer-overflow-via-resource-records-names-analyzed-on-13-07.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-avahi-buffer-overflow-via-resource-records-names-analyzed-on-13-07.html</guid>
		<dc:date>2026-09-13T11:49:59Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger a buffer overflow of Avahi, via Resource Records Names, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger a buffer overflow of Avahi, via Resource Records Names, in order to trigger a denial of service, and possibly to run code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Avahi-buffer-overflow-via-Resource-Records-Names-52009" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Avahi : buffer overflow via Resource Records Names, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-avahi-buffer-overflow-via-resource-records-names-analyse-le-13-07.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-avahi-buffer-overflow-via-resource-records-names-analyse-le-13-07.html</guid>
		<dc:date>2026-09-13T11:49:59Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer un buffer overflow de Avahi, via Resource Records Names, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer un buffer overflow de Avahi, via Resource Records Names, afin de mener un d&#233;ni de service, et &#233;ventuellement d'ex&#233;cuter du code.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Avahi-buffer-overflow-via-Resource-Records-Names-52009" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Contao: Server-Side Request Forgery via RSS Feed URLs, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-contao-server-side-request-forgery-via-rss-feed-urls-analyzed-on.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-contao-server-side-request-forgery-via-rss-feed-urls-analyzed-on.html</guid>
		<dc:date>2026-09-13T11:43:32Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger a Server-Side Request Forgery of Contao, via RSS Feed URLs, in order to force the server to send queries.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger a Server-Side Request Forgery of Contao, via RSS Feed URLs, in order to force the server to send queries.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Contao-Server-Side-Request-Forgery-via-RSS-Feed-URLs-52007" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Contao : Server-Side Request Forgery via RSS Feed URLs, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-contao-server-side-request-forgery-via-rss-feed-urls-analyse-le-13.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-contao-server-side-request-forgery-via-rss-feed-urls-analyse-le-13.html</guid>
		<dc:date>2026-09-13T11:43:32Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer un Server-Side Request Forgery de Contao, via RSS Feed URLs, afin de forcer le serveur &#224; envoyer des requ&#234;tes.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer un Server-Side Request Forgery de Contao, via RSS Feed URLs, afin de forcer le serveur &#224; envoyer des requ&#234;tes.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Contao-Server-Side-Request-Forgery-via-RSS-Feed-URLs-52007" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - CUPS: information disclosure via Root-side Banner File, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-cups-information-disclosure-via-root-side-banner-file-analyzed-on.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-cups-information-disclosure-via-root-side-banner-file-analyzed-on.html</guid>
		<dc:date>2026-09-13T11:39:29Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can bypass access restrictions to data of CUPS, via Root-side Banner File, in order to read sensitive information.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can bypass access restrictions to data of CUPS, via Root-side Banner File, in order to read sensitive information.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/CUPS-information-disclosure-via-Root-side-Banner-File-52006" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - CUPS : obtention d'information via Root-side Banner File, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-cups-obtention-d-information-via-root-side-banner-file-analyse-le.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-cups-obtention-d-information-via-root-side-banner-file-analyse-le.html</guid>
		<dc:date>2026-09-13T11:39:29Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s aux donn&#233;es de CUPS, via Root-side Banner File, afin d'obtenir des informations sensibles.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s aux donn&#233;es de CUPS, via Root-side Banner File, afin d'obtenir des informations sensibles.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/CUPS-obtention-d-information-via-Root-side-Banner-File-52006" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - FasterXML Jackson Core: overload via maxNumberLength bypass, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-core-overload-via-maxnumberlength-bypass.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-core-overload-via-maxnumberlength-bypass.html</guid>
		<dc:date>2026-09-13T11:30:45Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger an overload of FasterXML Jackson Core, via maxNumberLength bypass, in order to trigger a denial of service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger an overload of FasterXML Jackson Core, via maxNumberLength bypass, in order to trigger a denial of service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/FasterXML-Jackson-Core-overload-via-maxNumberLength-bypass-52005" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - FasterXML Jackson Core : surcharge via maxNumberLength bypass, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-core-surcharge-via-maxnumberlength-bypass.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-core-surcharge-via-maxnumberlength-bypass.html</guid>
		<dc:date>2026-09-13T11:30:45Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer une surcharge de FasterXML Jackson Core, via maxNumberLength bypass, afin de mener un d&#233;ni de service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer une surcharge de FasterXML Jackson Core, via maxNumberLength bypass, afin de mener un d&#233;ni de service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/FasterXML-Jackson-Core-surcharge-via-maxNumberLength-bypass-52005" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - FasterXML Jackson Databind : acc&#232;s en &#233;criture via JsonUnwrapped Container Properties, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-acces-en-ecriture-via-jsonunwrapped.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-acces-en-ecriture-via-jsonunwrapped.html</guid>
		<dc:date>2026-09-13T11:27:01Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de FasterXML Jackson Databind, via JsonUnwrapped Container Properties, afin de modifier des donn&#233;es.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de FasterXML Jackson Databind, via JsonUnwrapped Container Properties, afin de modifier des donn&#233;es.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/FasterXML-Jackson-Databind-acces-en-ecriture-via-JsonUnwrapped-Container-Properties-52004" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - FasterXML Jackson Databind: write access via JsonUnwrapped Container Properties, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-write-access-via-jsonunwrapped.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-write-access-via-jsonunwrapped.html</guid>
		<dc:date>2026-09-13T11:27:01Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can bypass access restrictions of FasterXML Jackson Databind, via JsonUnwrapped Container Properties, in order to alter data.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can bypass access restrictions of FasterXML Jackson Databind, via JsonUnwrapped Container Properties, in order to alter data.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/FasterXML-Jackson-Databind-write-access-via-JsonUnwrapped-Container-Properties-52004" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - FasterXML Jackson Databind : acc&#232;s en lecture et &#233;criture via PropertyNamingStrategy JsonIgnore Bypass, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-acces-en-lecture-et-ecriture-via.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-acces-en-lecture-et-ecriture-via.html</guid>
		<dc:date>2026-09-13T11:25:10Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de FasterXML Jackson Databind, via PropertyNamingStrategy JsonIgnore Bypass, afin de lire ou modifier des donn&#233;es.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de FasterXML Jackson Databind, via PropertyNamingStrategy JsonIgnore Bypass, afin de lire ou modifier des donn&#233;es.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/FasterXML-Jackson-Databind-acces-en-lecture-et-ecriture-via-PropertyNamingStrategy-JsonIgnore-Bypass-52003" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - FasterXML Jackson Databind: read-write access via PropertyNamingStrategy JsonIgnore Bypass, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-read-write-access-via.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-read-write-access-via.html</guid>
		<dc:date>2026-09-13T11:25:10Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can bypass access restrictions of FasterXML Jackson Databind, via PropertyNamingStrategy JsonIgnore Bypass, in order to read or alter data.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can bypass access restrictions of FasterXML Jackson Databind, via PropertyNamingStrategy JsonIgnore Bypass, in order to read or alter data.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/FasterXML-Jackson-Databind-read-write-access-via-PropertyNamingStrategy-JsonIgnore-Bypass-52003" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - FasterXML Jackson Databind : acc&#232;s en lecture et &#233;criture via Creator Properties Bypass, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-acces-en-lecture-et-ecriture-via-178434.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-acces-en-lecture-et-ecriture-via-178434.html</guid>
		<dc:date>2026-09-13T11:22:43Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de FasterXML Jackson Databind, via Creator Properties Bypass, afin de lire ou modifier des donn&#233;es.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de FasterXML Jackson Databind, via Creator Properties Bypass, afin de lire ou modifier des donn&#233;es.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/FasterXML-Jackson-Databind-acces-en-lecture-et-ecriture-via-Creator-Properties-Bypass-52002" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - FasterXML Jackson Databind: read-write access via Creator Properties Bypass, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-read-write-access-via-creator.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-fasterxml-jackson-databind-read-write-access-via-creator.html</guid>
		<dc:date>2026-09-13T11:22:43Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can bypass access restrictions of FasterXML Jackson Databind, via Creator Properties Bypass, in order to read or alter data.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can bypass access restrictions of FasterXML Jackson Databind, via Creator Properties Bypass, in order to read or alter data.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/FasterXML-Jackson-Databind-read-write-access-via-Creator-Properties-Bypass-52002" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - IBM Db2: multiple vulnerabilities dated 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-ibm-db2-multiple-vulnerabilities-dated-13-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-ibm-db2-multiple-vulnerabilities-dated-13-07-2026.html</guid>
		<dc:date>2026-09-13T08:52:21Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can use several vulnerabilities of IBM Db2, dated 13/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can use several vulnerabilities of IBM Db2, dated 13/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/IBM-Db2-multiple-vulnerabilities-dated-13-07-2026-52000" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - IBM Db2 : multiples vuln&#233;rabilit&#233;s du 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-ibm-db2-multiples-vulnerabilites-du-13-07-2026.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-ibm-db2-multiples-vulnerabilites-du-13-07-2026.html</guid>
		<dc:date>2026-09-13T08:52:21Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de IBM Db2, du 13/07/2026.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de IBM Db2, du 13/07/2026.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/IBM-Db2-multiples-vulnerabilites-du-13-07-2026-52000" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Apache Log4j API: write access via Non-finite Floating-point Values, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apache-log4j-api-write-access-via-non-finite-floating-point-values.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apache-log4j-api-write-access-via-non-finite-floating-point-values.html</guid>
		<dc:date>2026-09-13T08:45:16Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can bypass access restrictions of Apache Log4j API, via Non-finite Floating-point Values, in order to alter data.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can bypass access restrictions of Apache Log4j API, via Non-finite Floating-point Values, in order to alter data.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Apache-Log4j-API-write-access-via-Non-finite-Floating-point-Values-51999" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Apache Log4j API : acc&#232;s en &#233;criture via Non-finite Floating-point Values, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apache-log4j-api-acces-en-ecriture-via-non-finite-floating-point.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apache-log4j-api-acces-en-ecriture-via-non-finite-floating-point.html</guid>
		<dc:date>2026-09-13T08:45:16Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de Apache Log4j API, via Non-finite Floating-point Values, afin de modifier des donn&#233;es.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut contourner les restrictions d'acc&#232;s de Apache Log4j API, via Non-finite Floating-point Values, afin de modifier des donn&#233;es.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Apache-Log4j-API-acces-en-ecriture-via-Non-finite-Floating-point-Values-51999" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - OPAM: directory traversal via Install File Directives, analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-opam-directory-traversal-via-install-file-directives-analyzed-on.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-opam-directory-traversal-via-install-file-directives-analyzed-on.html</guid>
		<dc:date>2026-09-13T08:41:14Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can traverse directories of OPAM, via Install File Directives, in order to write a file outside the service root path.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can traverse directories of OPAM, via Install File Directives, in order to write a file outside the service root path.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/OPAM-directory-traversal-via-Install-File-Directives-51998" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - OPAM : travers&#233;e de r&#233;pertoire via Install File Directives, analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-opam-traversee-de-repertoire-via-install-file-directives-analyse.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-opam-traversee-de-repertoire-via-install-file-directives-analyse.html</guid>
		<dc:date>2026-09-13T08:41:14Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut traverser les r&#233;pertoires de OPAM, via Install File Directives, afin de modifier un fichier situ&#233; hors de la racine du service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut traverser les r&#233;pertoires de OPAM, via Install File Directives, afin de modifier un fichier situ&#233; hors de la racine du service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/OPAM-traversee-de-repertoire-via-Install-File-Directives-51998" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - p11-kit: overload via p11_rpc_message_get_attribute(), analyzed on 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-p11-kit-overload-via-p11_rpc_message_get_attribute-analyzed-on-13.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-p11-kit-overload-via-p11_rpc_message_get_attribute-analyzed-on-13.html</guid>
		<dc:date>2026-09-13T08:35:35Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can trigger an overload of p11-kit, via p11_rpc_message_get_attribute(), in order to trigger a denial of service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can trigger an overload of p11-kit, via p11_rpc_message_get_attribute(), in order to trigger a denial of service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/p11-kit-overload-via-p11-rpc-message-get-attribute-51997" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - p11-kit : surcharge via p11_rpc_message_get_attribute(), analys&#233; le 13/07/2026</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-p11-kit-surcharge-via-p11_rpc_message_get_attribute-analyse-le-13.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-p11-kit-surcharge-via-p11_rpc_message_get_attribute-analyse-le-13.html</guid>
		<dc:date>2026-09-13T08:35:35Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut provoquer une surcharge de p11-kit, via p11_rpc_message_get_attribute(), afin de mener un d&#233;ni de service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut provoquer une surcharge de p11-kit, via p11_rpc_message_get_attribute(), afin de mener un d&#233;ni de service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/p11-kit-surcharge-via-p11-rpc-message-get-attribute-51997" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Apple iOS | macOS: multiple vulnerabilities dated 12/12/2025</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apple-ios-macos-multiple-vulnerabilities-dated-12-12-2025.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apple-ios-macos-multiple-vulnerabilities-dated-12-12-2025.html</guid>
		<dc:date>2026-09-12T20:38:20Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can use several vulnerabilities of Apple iOS | macOS, dated 12/12/2025.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can use several vulnerabilities of Apple iOS | macOS, dated 12/12/2025.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Apple-iOS-macOS-multiple-vulnerabilities-dated-12-12-2025-49094" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Apple iOS | macOS : multiples vuln&#233;rabilit&#233;s du 12/12/2025</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apple-ios-macos-multiples-vulnerabilites-du-12-12-2025.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apple-ios-macos-multiples-vulnerabilites-du-12-12-2025.html</guid>
		<dc:date>2026-09-12T20:38:20Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Apple iOS | macOS, du 12/12/2025.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut employer plusieurs vuln&#233;rabilit&#233;s de Apple iOS | macOS, du 12/12/2025.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Apple-iOS-macOS-multiples-vulnerabilites-du-12-12-2025-49094" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="en">
		<title>Vigilance.fr - Apache Tika: external XML entity injection via PDF XFA File, analyzed on 12/12/2025</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apache-tika-external-xml-entity-injection-via-pdf-xfa-file-178409.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apache-tika-external-xml-entity-injection-via-pdf-xfa-file-178409.html</guid>
		<dc:date>2026-09-12T10:24:03Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>en</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;An attacker can transmit malicious XML data to Apache Tika, via PDF XFA File, in order to read a file, scan sites, or trigger a denial of service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-Security-Vulnerability-.html" rel="directory"&gt;Security Vulnerability&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;An attacker can transmit malicious XML data to Apache Tika, via PDF XFA File, in order to read a file, scan sites, or trigger a denial of service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;View online : &lt;a href="https://vigilance.fr/vulnerability/Apache-Tika-external-XML-entity-injection-via-PDF-XFA-File-49085" class="spip_out"&gt;https://vigilance.fr/vulnerability/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>
<item xml:lang="fr">
		<title>Vigilance.fr - Apache Tika : injection d'entit&#233; XML externe via PDF XFA File, analys&#233; le 12/12/2025</title>
		<link>http://www.globalsecuritymag.com/vigilance-fr-apache-tika-injection-d-entite-xml-externe-via-pdf-xfa-file-178410.html</link>
		<guid isPermaLink="true">http://www.globalsecuritymag.com/vigilance-fr-apache-tika-injection-d-entite-xml-externe-via-pdf-xfa-file-178410.html</guid>
		<dc:date>2026-09-12T10:24:03Z</dc:date>
		<dc:format>text/html</dc:format>
		<dc:language>fr</dc:language>
		<dc:creator>Vigilance.fr</dc:creator>



		<description>
&lt;p&gt;Un attaquant peut transmettre des donn&#233;es XML malveillantes vers Apache Tika, via PDF XFA File, afin de lire un fichier, de scanner des sites, ou de mener un d&#233;ni de service.&lt;/p&gt;


-
&lt;a href="http://www.globalsecuritymag.com/-vulnerabilites-.html" rel="directory"&gt;Vuln&#233;rabilit&#233;s&lt;/a&gt;


		</description>


 <content:encoded>&lt;div class='rss_texte'&gt;&lt;p&gt;Un attaquant peut transmettre des donn&#233;es XML malveillantes vers Apache Tika, via PDF XFA File, afin de lire un fichier, de scanner des sites, ou de mener un d&#233;ni de service.&lt;/p&gt;&lt;/div&gt;
		&lt;div class="hyperlien"&gt;Voir en ligne : &lt;a href="https://vigilance.fr/vulnerabilite/Apache-Tika-injection-d-entite-XML-externe-via-PDF-XFA-File-49085" class="spip_out"&gt;https://vigilance.fr/vulnerabilite/...&lt;/a&gt;&lt;/div&gt;
		
		</content:encoded>


		

	</item>

</channel>

</rss>
