> TODAY'S SUMMARY (151 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. is offering a $10 million reward for Zhang Yu, a key figure in the Hafnium hacking campaign, which compromised thousands of systems. In a concerning incident, attackers hijacked top-level domains to issue fake security certificates for major organizations, including Google, posing a severe risk of trusted brand impersonation. Additionally, vulnerabilities in Microsoft, Adobe, and Atlassian products have been disclosed, prompting urgent updates as exploitation attempts have already begun. The FBI and Secret Service are warning about the ongoing FortiBleed credential-stealing campaign, which has impacted over 86,000 devices. Finally, a data breach in Arizona's court system exposed information on over 1.3 million individuals, underscoring the persistent threat of cyberattacks on sensitive data.
|
// AI-powered summary generated at 20:00
De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoquer un problÚme de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans GLPI. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
Les classes ont été annulées à Delano, Minnesota, mercredi suite à un incident cyber. Le district scolaire a indiqué que l'incident s'était produit lundi soir et que l'internet a été coupé immédiatement aprÚs la compromission du réseau. Le district n'a pas confirmé s'il s'agissait d'une attaque, mai...
Le 20 mai, GitHub a publiĂ© les rĂ©sultats de son enquĂȘte sur une intrusion dans ses rĂ©fĂ©rentiels internes, rĂ©sultant d'une attaque menĂ©e Ă l'aide d'une extension malveillante de Visual Studio Code (VS Code). Cette attaque a visĂ© les appareils d'un employĂ© la veille, et GitHub a pris des mesures pour...
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un problÚme de sécurité non spécifié par l'éditeur.
La police de Scottsboro a stoppé rapidement une tentative d'attaque de cybersécurité contre ses serveurs avant que des données ne soient accédées ou prises. Aucune perturbation des services publics n'a été signalée. La police n'a trouvé aucune preuve que des informations identifiantes, photos, vidéo...
Des parties de la groupe Rhomberg-Bau ont Ă©tĂ© victimes d'une cyberattaque oĂč des inconnus ont pĂ©nĂ©trĂ© le rĂ©seau de l'entreprise et ont exfiltrĂ© des donnĂ©es. L'entreprise a coupĂ© complĂštement certaines de ses systĂšmes (finances, calculs de projet) pour prĂ©venir de nouveaux attaques. Les travaux sur l...
While also spoofing all the trusted domains - Apple, Microsoft, and Google - in the same attack
Des informations de contact et des adresses e-mail ont potentiellement été compromises lors d'un incident de cybersécurité chez Kinsmen Foundation. Bien que l'accÚs non autorisé ait été obtenu à certaines applications, les opérations et services réguliers n'ont pas été affectés. Les autorités polici...
Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected.
The post How Storm-2949 turned a compromised identity into a cloud-...
More than 200 individuals were arrested for cybercrime activities during INTERPOL's Operation Ramz, which focused on the Middle East and North Africa. [...]
Plus three other stealers in three other packages, all from the same scumbag
A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. [...]
In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a...
Investigators found hundreds of compromised devices that were used as part of the cybercriminal operation and notified device owners as part of the raids.
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public arch...
Anthropic and OpenAI promise their latest tools will find more vulnerabilities. Cybersecurity employees say theyâre already flooded with AI-generated reports.
The post AI might cut false positives, but it wonât stop the slop appeared first on CyberScoop.
âSomething didnât go as planned. Undoing changes.â Thatâs all the clue some Windows 11 users will get when Microsoftâs May Security Update fails to install because of insufficient free space on the EFI System Partition (ESP), leaving their systems unprotected by the dozens of...
Since the last update, the TeamPCP supply chain campaign produced its loudest stretch since the March Trivy disclosure: an officially confirmed Checkmarx Jenkins plugin compromise and a new self-spreading Mini Shai-Hulud worm across npm and PyPI.
Data breach notification letters have become a familiar routine. They usually start with âWe value your privacyâ and offer a year of free credit monitoring. But the most important part is often hidden in the middle:
A list of what actually got out.
A leaked email address is not a leaked admin passwo...