> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
Premium Deception campaign uses 250 Android apps to silently sign victims up to paid services
Trump Mobile is leaking customers’ email and home addresses, but has not responded to people alerting the company of the data exposure, according to two YouTubers who said they verified that their leaked data is authentic.
Read the latest DFIR news – on-scene digital forensics with ADF, YellowKey BitLocker bypass, IPsec traffic decryption from memory, Tesla dashcam telemetry decoding, and more.
Microsoft acknowledged the YellowKey BitLocker bypass flaw and released mitigations, urging admins to disable autofstx.exe and enable TPM+PIN. A week after Chaotic Eclipse publicly dropped the YellowKey vulnerability, Microsoft acknowledged it and published a mitigation. Not a patch, a mitigation. T...
When it comes to keeping our texts, chats, and other digital messages safe from prying eyes, we have a powerful tool: end-to-end encryption. Used correctly, end-to-end encryption turns our conversations online into secret messages that can only be decoded by their intended recipients. In our latest...
Mini Shai-Hulud worm hits Alibaba AntV ecosystem in largest npm supply chain wave to date
The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering questions and into accessing your email, retrieving records from your CRM, writing and executing code, and taking actions on you...
GitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension, an incident that underscores the growing risks facing software development platforms and the ecosystems built around third-party developer to...
Un code d'exploitation a été publié pour PinTheft, une faille dans le noyau Linux permettant d'effectuer une élévation de privilèges en local. Qui est affecté ?
Le post PinTheft : ce nouvel exploit offre les droits root sur Arch Linux a été publié sur IT-Connect.
Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within hours of release across every industry.
The post AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop appeared first...
Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world.
The tech giant attribut...
ESET has released an analysis of the 2025 activity of Webworm, a China-aligned APT group tracked as Space Pirates and UAT-8302. Active since at least 2022, the group initially focused on targets in Asia, but has recently expanded its operations into Europe. ESET observed Webworm targeting government...
Good report:
Executive Summary: Let’s say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope, because benchmarks don’t actually work for measuring AI capabilities (even when they are NOT emergent systemic properties like s...
Learn about passkeys for business, where adoption makes sense, and how to manage passkeys and passwords together during the transition.
Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. This is the first time credential theft has been knocked off the top spot in the report’s 19-year hist...
Identity checks alone can't stop attackers using stolen session tokens and compromised devices. Specops Software outlines why Zero Trust strategies increasingly depend on continuous device verification. [...]
NanoCo announced a $12 million seed round, alongside the commercial launch of a professional assistant built on its open-source agent framework NanoClaw. Valley Capital Partners led the round. Docker, Vercel, monday.com, Slow Ventures, Clutch Capital, Factorial Capital, and Hugging Face CEO Clem Del...
Several security issues were fixed in GnuTLS.
Several security issues were fixed in Unbound.
GitHub Investigates Internal Repositories Breach Claimed by TeamPCP GitHub confirmed that roughly 3,800 internal repositories were accessed after an employee installed a malicious VS Code extension, in what appears to be a follow-on from the broader developer tooling supply chain attack activity see...