> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain, SharePoint, OneDrive, Teams channel files, Slack messages, and Jira and Confl...
Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a question their examiners care about more than benchmark scores. Scott DePa...
You have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a circular chunk of a photo that has been spun around, and you drag it until the inside matches the ring around it. Simple enough. Annoying enough. Two re...
New pcre2 packages are available for Slackware 15.0 and -current to fix security issues.
Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices.
The company has established controls that flag when a model attempts to break out of a sandbox or successfully...
A federal judge has sided with Anthropic on its claims that the Department of Defense illegally retaliated against Anthropic’s protected speech by labeling the AI company a “supply chain risk.” The judge found that designation, intended to penalize Anthropic for telling the U.S. military it would no...
SSSD could be made to crash if it interacted with a smartcard or Yubikey
Le SPZOZ Warszawa-Ursynów, qui gère six cabinets médicaux et un centre de traitement à Varsovie, a été victime d'une cyberattaque par ransomware qui a affecté son serveur de messagerie. Le logiciel malveillant a chiffré la correspondance stockée, et il existe un risque potentiel de fuite de données...
SNEXI, entreprise de diagnostics immobiliers, a confirmé avoir été victime d'une cyberattaque le 2 septembre 2026, entraînant une violation de données personnelles. Les données potentiellement compromises incluent des noms, prénoms, adresses e-mail, adresses postales et numéros de téléphone, ainsi q...
Marimo 0.20.4 - RCE
Luminis Health a fait appel à des conseillers juridiques en raison d'un incident de cybersécurité en cours qui affecte les plateformes web du système hospitalier.
La Liga Nacional contra el Cáncer a communiqué que son victime d'un incident de cybersécurité qui a affecté temporairement les services de son Département de Radiothérapie. L'institution a confirmé que l'incident fait l'objet d'une enquête par les autorités compétentes et a assuré aux patients que s...
Fullhan FH8626V100 - Multiple Vulnerabilities
Plusieurs sites internet gouvernementaux liés au ministère de la Transition écologique sont inaccessibles suite à une cyberattaque revendiquée par un utilisateur anonyme sur un forum criminel. L'Agence nationale de la sécurité des systèmes d'information (Anssi) mène des investigations suite à des su...
Langflow 1.10.0 - RCE
Ghost_CMS 6.19.0 - Remote Code Execution