> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape reveals significant threats and trends. Bitdefender has identified preinstalled Android malware, "Midnight Mimosa," affecting cheap MediaTek devices in 150 countries, which engages in click fraud and botnet activities. Additionally, a malware incident at Nippon Columbia has compromised 8.7 million records of karaoke enthusiasts, showcasing the ongoing risks of data breaches. In infrastructure security, AI systems are increasingly being recognized for their potential to execute sophisticated attacks, raising alarms about preparedness. U.S. CISA has updated its Known Exploited Vulnerabilities catalog with critical flaws in several applications, emphasizing the need for timely patching. Meanwhile, new insights into facial recognition vulnerabilities reveal risks even when individuals are partially obscured.
|
// AI-powered summary generated at 16:01
Read how Microsoft is partnering with Anthropic and broader industry to use leading models, paired with our platforms and expertise, to turn AI-driven discovery into protection at scale.
The post AI-powered defense for an AI-accelerated threat landscape appeared first on Microsoft Security Blog.
Learn how SentinelOne has stopped three recent zero-day supply chain attacks with AI-driven defense built for machine-speed threats.
France Titres, a French government agency, has disclosed a data breach that may have exposed user data from its online portal. France Titres, also known as the Agence nationale des titres sécurisés (ANTS), operates under the French Ministry of the Interior and manages systems for official identity a...
Building on our recent announcement of AWS Security Hub Extended —our full-stack enterprise security offering — we want to show you how we’re simplifying security procurement and operations for your multicloud environments. Whether you’re a security architect evaluating solutions or a CISO looking t...
macOS LOTL techniques bypass detection using native tools and metadata abuse
L'autorité polonaise de protection des données (UODO) et l'Office des marchés publics ont organisé une conférence sur les défis de la protection des données dans le cadre des marchés publics face aux nouvelles technologies.Le président de l'UODO a souligné que les marchés publics impliquent un trait...
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de A.A.A., comprenant le prononcé d'une amende de 1 000 €, pour des manquements liés à l'utilisation de témoins de connexion et au défaut d'information sur son site internet. Cette affaire débute par u...
Developer-focused attacks: from malicious npm packages and GitHub phishing, to fake interviews and take-home assignments.
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre de Moyens de Prévention Externes Sud, S.L. (comprenant le prononcé d'une amende de 36 000 €) pour des manquements en lien avec la sécurité des données personnelles. Cette affaire débute par la notifica...
Series Note: This article is Part Five of our ongoing series on AI‑driven side‑channel attacks and the architectural shifts required to defend against them. If you missed Part Four, you can read it here.Â
Organizations are racing to deploy AI across their operations — accelerating decisions, a...
Chatrie v. United States asks whether a single warrant can justify a location-data dragnet — and what “probable cause” means when the search starts with basically everyone nearby.
The post The Supreme Court is about to decide how far geofence warrants can go appeared first on CyberScoop.
Introduction Building on recent research identifying DNS-based exfiltration risks in Sandbox mode AgentCore Code Interpreters, I identified global S3 access as another Command & Control channel for sandboxed code interpreters. Unlike DNS-based exfiltration, which has since been fully mitigated,...
One group of hackers used AI for everything from vibe coding their malware to creating fake company websites—and stole as much as $12 million in three months.
Agencies Ignored EFF’s Public-Records Requests Regarding Unlawful Efforts to Locate People Who Criticized the Government or Attended Protests.SAN FRANCISCO – The Electronic Frontier Foundation (EFF) sued the Department of Homeland Security (DHS) and Immigration and Customs Enforcement (ICE) today de...
The cosmetics retailer, which counts 41 million customers in its membership data, declined to provide an accurate total number of customers affected.
What's New in CyberStrong
We're excited to share everything that's new in the latest CyberStrong releases. From expanded questionnaire capabilities to smarter risk reporting and a more intuitive personal work view, this cycle is packed with updates designed to help you work faster and manage r...
Age verification is expanding from laws to platforms and operating systems, reshaping the internet. Here’s what it means for privacy and access.
French authorities have arrested a suspected hacker believed to be behind dozens of data breaches targeting public institutions, sports federations and private organizations across the country.
The threat actor known as Harvester has been attributed to a new Linux version of its GoGra backdoor deployed as part of attacks likely targeting entities in South Asia.
"The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control (C2) channel, allowing...
Read the latest DFIR news – Cyincore’s Emil Opachevsky calls for auditable AI in DFIR, ALEAPP 3.4.1 adds new mobile parsers, Tailscale research highlights Windows 11 artifacts, and more.