> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
La Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) du Maroc a publié une liste de dix règles impératives à respecter en matière de protection des données durant les opérations et consultations électorales.Ces impératifs, fondés sur la loi 09-08, incluent la...
L'Autorité polonaise de protection des données (UODO) a communiqué sa position concernant l'initiative de créer un système public et gratuit de documentation scolaire numérique.Le président de l'UODO soutient ce projet, mais conditionne sa mise en œuvre à une analyse approfondie, rappelant qu'une lo...
Learn how to organize shared password vaults by department, enforce least privilege, and keep credential management secure.
L'autorité autrichienne de protection des données (DSB) a publié un document complémentaire à son guide sur la loi sur la liberté d'information (IFG), entrée en vigueur le 1er septembre 2025.Ce nouvel outil de travail, intitulé "Mise à jour IFG - Aspects de protection des données pour les organismes...
L'autorité polonaise de protection des données a publié son rapport d'activité pour l'année 2025, qui met en évidence une forte augmentation de ses actions et des sollicitations des personnes concernées.En 2025, l'Office de protection des données personnelles (UODO) a reçu 12 827 plaintes, soit une...
This is interesting:
The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.
[…]
The reporting also linked...
Meta a conclu un accord avec la quasi-totalité des États américains pour mettre fin aux poursuites concernant les effets de ses plateformes sur les mineurs.La société s'est engagée à verser jusqu'à 18 000 000 000 de dollars sur une période de dix ans pour régler des litiges initiés par les États. Ce...
Un cabinet notarial a été sanctionné pour avoir communiqué à sa cliente une certification cadastrale contenant les données personnelles d'un tiers, l'autorité ayant jugé que cette divulgation était dépourvue de base légale.Faits et contexteL'autorité espagnole de protection des données (AEPD) a aujo...
It was discovered that pyasn1 did not properly bound the size of long-form
tag identifiers when parsing BER, CER, or DER encoded data. An attacker
could possibly use this issue to cause applications decoding untrusted
ASN.1 data to consume excessive CPU resources, resulting in a denial of
service. (...
Le Garant italien pour la protection des données personnelles (GPDP) a sanctionné une commune pour avoir diffusé par erreur sur son site internet les données de plus de 31 000 contribuables. La décision met en lumière les manquements liés à la configuration par défaut d'un logiciel de publication et...
La Commission européenne a publié un appel à propositions dans le cadre du programme Europe Numérique, visant à financer le déploiement d'outils et de technologies de cybersécurité s'appuyant sur l'intelligence artificielle.L'objectif est de fournir aux autorités nationales et aux entités relevant d...
It was discovered that Libgcrypt had a timing-based side-channel flaw in
its RSA implementation. A remote attacker could possibly use this issue to
obtain sensitive information.
A fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.
AIR's platform can discover agents running at a company, continuously vets any skills and add-ons they use, and blocks any unwanted behaviour.
USN-8688-1 fixed a vulnerability in PAM. This update provides the
corresponding fix for PAM on Ubuntu 26.04 LTS.
Original advisory details:
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first...
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu
14.04 LTS only, it was discovered that some machines were unable to
enable esm-infra-legacy due to a preemptive apt-helper check. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Bi...
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
Alexis Challande discovered that libevent incorrectly handled certain
empty output buffers. An attacker could possibly use this issue to
trigger a use-after-free, resulting in a denial of service or arbitrary
code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 L...
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations.
The post 5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-i...
It was discovered that ncurses incorrectly handled specially crafted
terminfo database entries. A local attacker could possibly use this issue
to cause applications using ncurses to crash, resulting in a denial of
service.