> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
L'autorité de protection des données estonienne (AKI) a publié une décision de sanction à l'encontre de deux personnes, comprenant le prononcé d'une amende de 2 000 € pour chacune, pour des manquements en lien avec la diffusion de photographies intimes sans le consentement des personnes concernées s...
L'autorité croate de protection des données (AZOP) a publié une foire aux questions détaillant les modalités de création, d'approbation et de suivi des codes de conduite prévus par le RGPD.L'autorité invite les associations et organismes représentant des catégories de responsables de traitement ou d...
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents.
RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and securi...
L'autorité croate de protection des données (AZOP) a publié une décision détaillant les exigences pour l'accréditation des organismes chargés de surveiller les codes de conduite.Fondée sur l'article 41 du RGPD et les lignes directrices du Comité européen de la protection des données (CEPD), cette dé...
L'autorité britannique de protection des données (ICO) a infligé une amende de 160 000 £ (soit 185 067 € environ) à une société du secteur de l'énergie pour avoir effectué plus de 700 000 appels de démarchage commercial non sollicités.La société Energy Prices Direct Limited (EPDL) a réalisé ces appe...
AI conversations are becoming critical evidence in digital investigations — GMDSOFT’s latest Tech Letter explores how MD-NEXT and MD-RED recover and interpret ChatGPT artifacts on Android devices.
L'autorité tchèque de protection des données (Úřad pro ochranu osobních údajů - UOOU) a communiqué sa position sur le traitement de données biométriques par des systèmes de vidéosurveillance visant à interdire l'accès aux stades de football à des personnes indésirables.L'autorité distingue la vidéos...
The investigation began after U.S. authorities informed their Ukrainian counterparts that hackers operating from Ukraine could be involved in attacks targeting users of American e-commerce platforms, Ukraine's Prosecutor General said.
The move comes as other major social media platforms are killing end-to-end encryption for messaging. In recent months, Instagram and TikTok both announced they will no longer offer the feature.
Attorney John Scola is representing a police officer who is suing over injuries allegedly sustained while working security at an MSG property in 2025.
The breach notification letters say 7-Eleven discovered the breach on April 8 and, after an investigation, determined that the cybercriminals gained access to “certain 7-Eleven systems used to store franchisee documents.”
Read about the unique challenges and rewards of securing gaming platforms and how to better protect gaming communities.
The post Securing the gaming culture of cultures appeared first on Microsoft Security Blog.
Microsoft’s GitHub has suffered what appears to be its biggest ever security breach after confirming that attackers exfiltrated code from around 3,800 of the company’s internal repositories.
News of the incident first emerged on May 19, when GitHub said it was investigating...
The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. [...]
The new Series A funding round brings the total raised by Quantum Bridge to $16 million.
The post Quantum Bridge Raises $8 Million for Quantum-Safe Key Distribution Solution appeared first on SecurityWeek.
The exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches.
The post Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass appeared first on SecurityWeek.
A cheap Android TV box promising free subscriptions can easily become the backbone for cybercriminal botnets and proxy servers. We break down how these streaming boxes lease out your IP address, and how to choose a device that’s secure.
The service let malware authors sign malicious files with fraudulent Microsoft-issued certificates to bypass security checks.
Premium Deception campaign uses 250 Android apps to silently sign victims up to paid services
Trump Mobile is leaking customers’ email and home addresses, but has not responded to people alerting the company of the data exposure, according to two YouTubers who said they verified that their leaked data is authentic.