<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>InYourGeek — Security</title><description>Flaws, leaks, attacks and regulation. The one section where we do not joke.</description><link>https://inyourgeek.com</link><language>en-US</language><item><title>Record Patch Tuesday: 966 Microsoft flaws, two zero-days exploited</title><link>https://inyourgeek.com/en/articles/2026-09-09-patch-tuesday-record-966-failles-microsoft-deux-zero-days</link><guid isPermaLink="true">https://inyourgeek.com/en/articles/2026-09-09-patch-tuesday-record-966-failles-microsoft-deux-zero-days</guid><description>On 8 September 2026, Microsoft shipped the largest batch of security fixes in its history, including two vulnerabilities already under attack. The sheer volume changes how teams must prioritise deployment.</description><pubDate>Wed, 09 Sep 2026 05:00:22 GMT</pubDate><category>securite</category><category>microsoft</category><category>patch</category><category>zeroday</category><category>vulnerabilites</category></item><item><title>A researcher cracked a 1990s CA&apos;s 512-bit RSA keys in 61 hours</title><link>https://inyourgeek.com/en/articles/2026-09-08-un-chercheur-factorise-les-cles-rsa-512-bits-d</link><guid isPermaLink="true">https://inyourgeek.com/en/articles/2026-09-08-un-chercheur-factorise-les-cles-rsa-512-bits-d</guid><description>On 7 September 2026, a developer published the private keys of two 512-bit roots that shipped with Netscape 4.51 in 1999, factored in 61 hours on a desktop PC. Compute always catches up with a key size — the only question is when.</description><pubDate>Tue, 08 Sep 2026 05:00:18 GMT</pubDate><category>securite</category><category>securite</category><category>rsa</category><category>chiffrement</category><category>netscape</category></item><item><title>153 million driver&apos;s licenses for sale: IDScan faces lawsuits</title><link>https://inyourgeek.com/en/articles/2026-09-06-153-millions-de-permis-mis-en-vente-idscan-vise</link><guid isPermaLink="true">https://inyourgeek.com/en/articles/2026-09-06-153-millions-de-permis-mis-en-vente-idscan-vise</guid><description>A dark web service offered more than 153 million driver&apos;s license scans for sale, a database traced back to identity verification vendor IDScan. Several lawsuits have been filed, and the FBI is investigating.</description><pubDate>Sun, 06 Sep 2026 05:00:21 GMT</pubDate><category>securite</category><category>fuite</category><category>identite</category><category>donnees</category><category>justice</category></item><item><title>CVE-2026-85046: a Chromium sandbox escape already exploited</title><link>https://inyourgeek.com/en/articles/2026-09-05-cve-2026-85046-une-evasion-du-bac-a-sable</link><guid isPermaLink="true">https://inyourgeek.com/en/articles/2026-09-05-cve-2026-85046-une-evasion-du-bac-a-sable</guid><description>An NVD entry published on 4 September 2026 documents a sandbox escape in Chromium that is already being exploited. Because the engine is shared by nearly every browser and every Electron application, the scope reaches far past Chrome.</description><pubDate>Sat, 05 Sep 2026 05:00:20 GMT</pubDate><category>securite</category><category>chromium</category><category>faille</category><category>electron</category><category>navigateur</category></item><item><title>Elementor Pro flaw CVE-2026-32475 exploited since patch day</title><link>https://inyourgeek.com/en/articles/2026-09-04-elementor-pro-la-faille-cve-2026-32475-exploitee-depuis</link><guid isPermaLink="true">https://inyourgeek.com/en/articles/2026-09-04-elementor-pro-la-faille-cve-2026-32475-exploitee-depuis</guid><description>A critical Elementor Pro vulnerability, fixed on 19 August 2026, has been exploited since that same day to drop a webshell on WordPress sites. Wordfence says it blocked close to 200,000 attempts.</description><pubDate>Fri, 04 Sep 2026 12:06:18 GMT</pubDate><category>securite</category><category>wordpress</category><category>elementor</category><category>faille</category><category>webshell</category></item><item><title>Coder&apos;s registry hijacked to serve booby-trapped Terraform modules</title><link>https://inyourgeek.com/en/articles/2026-09-04-le-registre-de-coder-detourne-pour-diffuser-des-modules</link><guid isPermaLink="true">https://inyourgeek.com/en/articles/2026-09-04-le-registre-de-coder-detourne-pour-diffuser-des-modules</guid><description>On 31 August, part of the traffic to Coder&apos;s registry was diverted to attacker-controlled servers handing out booby-trapped Terraform modules. Those modules went straight for the keys and tokens held by infrastructure teams.</description><pubDate>Fri, 04 Sep 2026 11:48:58 GMT</pubDate><category>securite</category><category>securite</category><category>terraform</category><category>cloudflare</category><category>coder</category></item><item><title>524,867 patient records leaked: €500,000 fine for French hospital</title><link>https://inyourgeek.com/en/articles/2026-09-03-fuite-de-524-867-dossiers-patients-500-000-d</link><guid isPermaLink="true">https://inyourgeek.com/en/articles/2026-09-03-fuite-de-524-867-dossiers-patients-500-000-d</guid><description>France&apos;s CNIL has fined Hôpital privé de la Loire €500,000, a year after the data of 524,867 patients was exfiltrated. The ruling describes basic failures: no VPN, no two-factor authentication, no monitoring of access.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>securite</category><category>cnil</category><category>sante</category><category>rgpd</category><category>fuite</category></item></channel></rss>