> TODAY'S SUMMARY (1 articles)
Today's cyber news highlights significant developments in cybersecurity threats and trends. The UK government has imposed new sanctions on Russian crypto payment processors Cryptomus, Heleket, and TokenSpot, aiming to disrupt financial support for Russia's wartime activities. This move underscores the increasing use of cryptocurrency in financing illicit operations and the need for enhanced monitoring of crypto infrastructure. Additionally, organizations are urged to bolster their defenses against potential retaliatory cyberattacks from state-sponsored actors in light of these sanctions. The evolving landscape emphasizes the importance of robust cybersecurity measures and vigilance against emerging threats.
|
// AI-powered summary generated at 04:00
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
NVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach. [...]
USN-8248-1 introduced a regression in NASM
Anonymized data can still be traced back to you. Here's how companies use it, and how you can protect your privacy.
On Thursday, dozens of students took to social media to say they saw a message from a cybercriminal group as they navigated through Canvas, an educational platform created by Instructure that hosts teaching materials, tests, readings and more.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.86-1.
The evolution of correlation rules in the Kaspersky Unified Monitoring and analysis SIEM system.
One in eight UK workers admits to selling their company login credentials - or knowing someone who has - in the past 12 months.
The really alarming bit? Their bosses are even more relaxed about it.
Read more in my article on the Fortra blog.
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
New kernel packages are available for Slackware 15.0 and -current to fix a security issue.
Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number, only to trick users into joining a subscription that provided fake data and incurred financial loss.
The 28 apps have c...
Most universities have a careers fair. At Bauman Moscow State Technical University, however, an elite group of students appear to have something rather more unusual: a direct pipeline into some of the world's most notorious state-sponsored hacking groups.
Read more in my article on the Hot for Se...
Other noteworthy stories that might have slipped under the radar: US gov targets 72-hour patch cycles, malware uses Windows Phone Link to steal OTPs, spy operation targets Eurasian drone industry.
The post In Other News: Train Hacker Arrested, PamDOORa Linux Backdoor, New CISA Director Frontrunner a...
USN-8248-1 fixed vulnerabilities in NASM. Unfortunately the update
introduced a regression which could cause NASM to crash. This update fixes
the problem by reverting the fix for CVE-2021-33450 and CVE-2021-33452 in
Ubuntu 24.04 LTS.
We apologize for the inconvenience.
Original advisory details:...
A week after Copy Fail, another Linux local privilege escalation vulnerability dubbed “Dirty Frag” has been revealed, along with a PoC exploit. What is Dirty Frag In effect, Dirty Frag refers to two flaws: A xfrm-ESP Page-Cache Write vulnerability (CVE-2026-43284, aka Copy Fail 2.0), now patched in...
Nearly 200,000 Zara customers were exposed in a third-party breach linked to ShinyHunters, revealing emails, purchase history, and support data. Personal data belonging to nearly 197,000 Zara customers has been compromised following a cyberattack on a former technology provider used by Inditex, the...
Attackers move faster than overwhelmed SOC teams can realistically investigate alerts. Prophet Security breaks down how AI can help analysts investigate alerts faster and focus on real threats. [...]
Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE
The group that stole data from Instructure users claims that it will release the data of students from nearly 9,000 education institutions around the country.
The post ShinyHunters claims nearly 9,000 schools affected by Canvas data breach appeared first on CyberScoop.
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion. [...]