> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
We're introducing a pilot program for MSPs to offer Proton Pass to their clients. Find out how to apply and what to expect.
En l'absence de la protection MTE sur le Pixel 11, GrapheneOS ne peut pas finir son portage, et surtout l'achat d'un Google Pixel 11 est déconseillé.
Le post Google Pixel 11 : pas de MTE, pas de GrapheneOS a été publié sur IT-Connect.
The most common way into a company last year was to ask.
A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, a...
Join the DFIR community in San Diego, October 20–22, 2026, for the Techno Security & Digital Forensics Conference – three days of expert-led education, emerging technologies, hands-on insights, and valuable industry networking.
The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.
The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek.
Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an orga...
Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s inv...
The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.
The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
Une série de 19 patchs apporte l'USB4 et le Thunderbolt aux Mac M1, M2 et M3 sous Linux. Mais les écrans externes et les boîtiers PCIe devront encore patienter.
Le post Le Thunderbolt arrive sur les Mac sous Linux, mais pas pour tous les modèles a été publié sur IT-Connect.
Anthropic has warned that infostealers are stealing Claude session cookies to access users’ accounts and consume usage at their expense.
More than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work.
The post The Collective Cyber Defense letter wrote your n...
Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links.
Part 1 is about the Japanese digital democracy party, Team Mirai.
Part 2 is abo...
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.
The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.
Pillow could be made to crash or expose sensitive information if it processed a specially crafted image file.
A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia.
The thre...
Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting K...
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]