> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Rust developers are being targeted through seemingly legitimate video calls, potentially linked to North Korean tactics. Microsoft has acknowledged issues with its September updates, which may disrupt the File History backup feature. A major breach at Gyazo has compromised over 23 million user records due to a server vulnerability. Meanwhile, attackers are exploiting three Linux kernel vulnerabilities that could lead to severe consequences like denial-of-service attacks. Additionally, a new wave of phishing attacks is targeting Revolut customers following a recent data breach. As AI continues to evolve, incidents like Google's Gemini AI breaching three firms raise alarms about the security of AI systems. Lastly, hackers have turned on each other, with ShinyHunters taking over a rival gang's dark web site amidst ongoing cybercrime feuds.
|
// AI-powered summary generated at 12:01
L'autorité polonaise de protection des données (UODO) a annoncé le lancement de la 17ème édition de son programme éducatif national intitulé "Tes données – Ton affaire".Ce programme, destiné aux écoles primaires, secondaires et aux centres de formation des enseignants, vise à développer les compéten...
L'autorité espagnole a clos une procédure initiée contre un sous-traitant pour la falsification de preuves d'envoi de mises en demeure, au motif que les faits avaient déjà fait l'objet d'une condamnation pénale définitive.Faits et contexteL'autorité espagnole de protection des données (AEPD) a aujou...
Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After years of successful grassroots battles to pull these cameras from local st...
L'autorité espagnole de protection des données a classé une procédure initiée contre une personne physique pour avoir utilisé les données d'un tiers sans base légale dans une démarche administrative, en raison de l'absence de culpabilité (intention ou négligence) de sa part.Faits et contexteL'autori...
La Commission de protection des données irlandaise (DPC) a sanctionné le Service de santé exécutif (HSE) d'une amende totale de 645 000 € pour de graves manquements à la sécurité et à la gestion de dossiers médicaux papier stockés dans des entrepôts externes.Faits et contexteL'autorité irlandaise de...
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.
Le tribunal de première instance estonien a confirmé la sanction de 3 000 000 € infligée à un responsable de traitement pour des mesures de sécurité jugées insuffisantes au regard du volume et de la sensibilité des données traitées, notamment des données de santé.Faits et contexteLe tribunal du comt...
Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.
The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop.
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affe...
Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'
Read the latest DFIR news – SANS AI frameworks for DFIR, AI hackathon tools, investigator well-being, macOS unlock artifacts, cross-platform log analysis, Apple Health forensics, and more.
Tech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.
The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executa...
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on CyberScoop.
HiddenLayer has raised a $100M Series B from Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, Booz Allen Hamilton, and others.
it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs.
The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.
If your forensic tool isn’t showing you every file in a case, how can you be sure you’re investigating the full picture? See how S21 VisionX keeps difficult, damaged and excluded material visible to investigators.