> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-83548 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié. La vulnérabilité...
Le fabricant de composants optoélectroniques Hangte a publié une alerte de cybersécurité indiquant que ses systèmes d'information ont été attaqués. L'entreprise a mis en place des mécanismes de défense et évalue que l'impact sur ses opérations n'est pas majeur.
23-year-old botnet down
LLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months. But it’s one thing to find vulnerabilities in well documented open-source projects and an entirely different skillset to decrypt file systems and reverse-...
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help...
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning i...
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteIt does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec tal...
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts.
The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.
Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.
In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:
The Settlement emb...
X is investigating a wave of unsolicited password reset emails that it believes may be tied to the rollout of its new payments service.
The model provider gave METR the credits for free. An actual customer would not have been so lucky
A hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."
The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR.
The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek.
Peters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued.
The post Tina Peters, through attorney, backs off formal role in Shasta County elections appeared first on CyberScoop.
Multiple vulnerabilities were discovered in Keystone, the OpenStack identity service, which may result in authorisation bypass or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 2:27.0.0-3+deb13u5.
Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default