> TODAY'S SUMMARY (8 articles)
Today's cybersecurity news highlights several significant threats and trends. Notably, a former engineer was sentenced for an insider cyber extortion plot, demanding 20 Bitcoin after compromising a company's infrastructure. Additionally, the rise of typosquatting exploits using rare Cyrillic and Latin characters poses new risks for users of Chromium browsers. Anthropic has halted live internet access for its AI tests following injection flaw exploits, underscoring ongoing vulnerabilities in AI systems. Furthermore, the co-creator of the Empire Market dark web platform received a 40-year prison sentence for facilitating over $430 million in illegal trades. Lastly, the FBI arrested the founder of a ransomware negotiation firm linked to the ShinyHunters group, marking a significant move against cybercriminal operations.
|
// AI-powered summary generated at 12:01
AI workflows need storage that supports repeated movement across the model lifecycle. Large datasets are ingested, transformed, exported for training, pulled back for evaluation, and refreshed as models evolve. Backblaze’s Q1 2026 Network Stats report says this creates a shift from diffuse internet-...
Here’s a look at the most interesting products from the past month, featuring releases from Advenica, Aptori, Axonius, Broadcom, GlobalSign, Intruder, IP Fabric, Mallory, Secureframe, Siemens, Sitehop, and Virtue AI. Mallory brings contextual threat intelligence to security operations Mallory is lau...
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.
To help educate website owners about potential threats to their environments,...
In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign, with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on...
CSOs must ensure their Linux-based systems block unauthorized privilege escalation until distros release patches to plug a serious kernel vulnerability affecting all Linux distributions shipped since 2017.
Until fixes are available for what’s been dubbed the Copy Fail logic...
TL;DR
Two malicious versions of the popular PyTorch Lightning package have been uploaded to PyPI following the publisher account’s compromise.
Lightning versions 2.6.2 and 2.6.3 (tracked as sonatype-2026-002817) were published on April 30, 2026, containing embedded malicious code that gat...
Categories: Threat ResearchTags: advisory, Linux, Copy Fail
La Hochschule Emden/Leer a été victime d'une nouvelle cyberattaque le 1er mai 2026, qui a entraîné l'arrêt préventif des services informatiques centraux et la perturbation du site web. Bien que les systèmes aient été rapidement contenus sans perte de données rapportée, le fonctionnement des cours se...
Instructure, développeur de la plateforme Canvas, a annoncé avoir subi un incident de cybersécurité et mène actuellement une enquête avec l'aide d'experts externes. L'entreprise s'engage à maintenir la transparence tout en travaillant rapidement pour minimiser l'impact de cette attaque perpétrée par...
Frontier AI models inspired by Anthropic’s Claude Mythos could arm attackers with advanced capabilities that the banking sector is ill equipped to cope with, Australia’s financial regulator, the Australian Prudential Regulation Authority (APRA), has warned.
In a letter addr...
Des problèmes techniques affectant ses systèmes informatiques, Foxconn a dû fermer temporairement son site de Mount Pleasant au Wisconsin après une panne réseau prolongée. Les employés ont été renvoyés et les opérations de production ont été perturbées, soulevant des questions potentielles sur un in...
La société JR Tokai Takashimaya a annoncé le 1er mai 2026 qu'elle soupçonnait un accès non autorisé à son serveur de candidature pour les emplois à temps partiel ainsi qu'une infection par un rançongiciel. À la suite de cette attaque, les noms, coordonnées et coordonnées bancaires de 1 338 employés...
For the last couple of years, we’ve watched the same predictable cycle play out across the globe: a state (or country) passes a clunky age-verification mandate, and, without fail, Virtual Private Network (VPN) usage surges as residents scramble to maintain their privacy and anonymity. We've seen thi...
La société japonaise de logiciels éducatifs a annoncé qu'un accès non autorisé avait été détecté sur un serveur inactif. Cet accès a entraîné une cryptage par rançongiciel et des traces d'accès non autorisé par des tiers. L'incident, découvert grâce à l'entreprise de location de serveurs, concerne d...
Deux lieux de divertissement à Regina, The Artesian et The Exchange, ont vu leurs sites web affectés par une cyberattaque. L'incident a été signalé par Squareflo, l'entreprise locale responsable de la plateforme hébergeant ces sites. Bien que les deux venues aient subi des perturbations, elles ont i...
Ryan Goldberg and Kevin Martin attacked five companies in 2023 and extorted nearly $1.3 million from one of their victims.
The post Former incident responders sentenced to 4 years in prison for committing ransomware attacks appeared first on CyberScoop.
Mini Shai-Hulud caught spreading credential-stealing malware
Mini Shai-Hulud caught spreading credential-stealing malware The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom npm packages, plus the lightning PyPI package.…
Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser.
The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42.