> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
One line tucked into a federal highway bill would strip funds from cities and states unless they kill their automated plate tracking programs—effectively banning the tech for all but toll collection.
The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation targeting users of an online store in California. [...]
Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. [...]
Agents have agency: they adapt and find multiple ways to solve problems. This autonomy creates a fundamental security challenge: the large language model (LLM) at the heart of the agent is non-deterministic, and its decisions can’t be predicted or guaranteed in advance. It can hallucinate harmful ac...
Another day, another AI bug silently fixed with no CVE and no public disclosure
PinTheft is a Linux LPE flaw in the RDS subsystem with public exploit code. Arch Linux users face the highest risk and should patch immediately. The wave of Linux local privilege escalation vulnerabilities showing up with working exploit code is not slowing down. The latest is PinTheft, discovered b...
Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 1:9.18.49-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in
Microsoft’s AI red team lead talked to CyberScoop about the goals behind open sourcing a pair of security tools meant for developers and incident responders.
The post Meet Rampart and Clarity, Microsoft’s new red team combo AI agents appeared first on CyberScoop.
Several security issues were fixed in the Linux kernel.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For the oldstable distribution (bookworm), these...
Multiple vulnerabiliites have been discovered in the PowerDNS DNS server, which could result in denial of service or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 4.9.15-0+deb13u1. We recommend that you upgrade your pdns packages.
It was discovered that Bubblewrap incorrectly handled the sandbox
setup phase when installed in setuid mode. A local attacker could
possibly use this issue to bypass sandbox restrictions.
It was discovered that XDG Desktop Portal incorrectly handled
trashing files. A local attacker could possibly use this issue to
delete arbitrary files on the host file system via a symlink attack.
Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms.
The post Mini Shai Hulud: Compromise...
Our largest security services customers started the same way every customer does – with a click. They enabled Amazon GuardDuty, Amazon Inspector, AWS WAF, and AWS Security Hub, experienced the benefits in real time, and evaluated with transparent pay-as-you-go pricing. No RFP. No six-month evaluatio...
The law mandates that platforms make it easy for people to ask that nonconsensual intimate images be removed and to delete them within 48 hours of a request.
L'autorité de protection des données estonienne (AKI) a publié une décision de sanction à l'encontre de deux personnes, comprenant le prononcé d'une amende de 2 000 € pour chacune, pour des manquements en lien avec la diffusion de photographies intimes sans le consentement des personnes concernées s...
L'autorité croate de protection des données (AZOP) a publié une foire aux questions détaillant les modalités de création, d'approbation et de suivi des codes de conduite prévus par le RGPD.L'autorité invite les associations et organismes représentant des catégories de responsables de traitement ou d...
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents.
RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and securi...
L'autorité britannique de protection des données (ICO) a infligé une amende de 160 000 £ (soit 185 067 € environ) à une société du secteur de l'énergie pour avoir effectué plus de 700 000 appels de démarchage commercial non sollicités.La société Energy Prices Direct Limited (EPDL) a réalisé ces appe...