[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Friday Squid Blogging: Giant Squid Live in the Waters of Western Australia
Evidence of them has been found by analyzing DNA in the seawater. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
> Five new holes, one exploited, found in Ivanti Endpoint Manager Mobile
The five new vulnerabilities discovered in Ivanti’s on-premises mobile endpoint management solution are a “classic example of the legacy trap” that CSOs must avoid, says an expert. “Patch today to survive the weekend,” said Robert Enderle of the Enderle Group, “but start pl...
> RansomHouse says it breached Trellix and exposes internal systems
RansomHouse claimed responsibility for the Trellix breach, adding the security firm to its Tor data leak site and sharing screenshots of internal systems. The RansomHouse ransomware group has claimed responsibility for the recent cyberattack on cybersecurity firm Trellix. To support its claims, the...
> GM to pay over $12 million in California privacy settlement involving driver data
The settlement, announced by California officials Friday, is the largest fine issued under the California Consumer Privacy Act (CCPA) in its more than five-year history.
> Kingdom Market administrator given 16-year sentence
Slovakian national Alan Bill, 33, pleaded guilty in January to a conspiracy to distribute controlled substances charge after admitting to his role in running Kingdom Market — a platform used by drug dealers and cybercriminals between March 2021 and December 2023.
> Debian Bookworm Postorius Important Cross-Site Scripting Fix DSA-6257-1
A cross-site scripting vulnerability was discovered in Postorius, the administrative web frontend for Mailman 3. For the oldstable distribution (bookworm), this problem has been fixed in version 1.3.8-3+deb12u1. For the stable distribution (trixie), this problem has been fixed in
> Debian DSA-6255-1 php8.2 Critical Security Issues Affecting Users
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, SQL injection, cross-site scripting or the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed
> APD - autorité belge
L'Autorité de protection des données (APD) a publié une décision de sanction à l'encontre d'un cabinet d’avocats, comprenant le prononcé d'une amende de 4 920 €, pour des manquements en lien avec l'obligation d'information et le respect du droit d'accès des personnes concernées. Cette affaire débute...
> Debian Trixie php8.4 Significant SQL Injection DOS DSA-6256-1
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, SQL injection, cross-site scripting, information disclosure or the execution of arbitrary code. For the stable distribution (trixie), these problems have...
> DPC - autorité irlandaise
L'autorité irlandaise de protection des données (DPC) a publié une décision de sanction à l'encontre de Permanent TSB (PTSB), comprenant le prononcé d'une amende de 277 500 €, pour des manquements liés à la sécurité des données et à la notification de violations. Cette affaire fait suite à une enquê...
> Debian firefox-esr Important Arbitrary Code Exec DSA-6254-1 CVE-2026-8090
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 140.10.2esr-1~deb12u1.
> IDPC - autorité maltaise
La Commission européenne a annoncé l'accord politique conclu le 7 mai 2026 entre le Parlement européen et le Conseil de l'UE concernant la simplification des règles sur l'intelligence artificielle (IA).Proposé par la Commission dans le cadre de l'"Omnibus numérique sur l'IA", cet accord vise à facil...
> DPA - autorité grecque
L'Autorité hellénique de protection des données a émis un avis défavorable sur un projet de loi du Ministère de l'Intérieur (ΥΠΕΣ) visant à instaurer un système de contrôle de présence et d'accès par données biométriques pour les agents du secteur public.Le projet de disposition prévoyait l'utilisat...
> Cyberattacks on Poland’s Water Plants: A Blueprint for Hybrid Warfare
Poland’s ABW confirmed hackers breached ICS at five water plants, gaining ability to alter equipment settings. Russia-linked APT groups suspected. Poland’s Internal Security Agency (ABW) has published a detailed account of a sustained campaign targeting the country’s water plants, documenting securi...
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de la Direction Régionale de la Santé de Castille-et-León (GRS) pour des manquements en lien avec un système de communication non sécurisé pour la gestion des prescriptions médicales. Cette affaire déb...
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de B.B.B., exploitante d'un bureau de transfert d'argent, comprenant le prononcé d'une amende de 2 000 € pour des manquements en lien avec la licéité du traitement de données personnelles. Cette affair...
> Virginia man found guilty of deleting 96 government databases
A Virginia man was convicted on federal charges Thursday after a jury found him guilty of deleting 96 government databases and stealing an individual’s password, leading their email account to be accessed without permission.
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de FRESHLY COSMETICS, S.L. (comprenant le prononcé d'une amende de 5 000 €) pour des manquements en lien avec l'utilisation de témoins de connexion. Cette affaire débute par une plainte d'un particulie...
> AEPD - autorité espagnole
L'Agence espagnole de protection des données (AEPD) a publié une décision de sanction à l'encontre de l'Institut national de la sécurité sociale (INSS) pour des manquements en lien avec la gestion des données personnelles du Revenu minimum vital (IMV). Cette affaire débute par une enquête d'office d...
> TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a majo...