[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (132 articles)

|

// AI-powered summary generated at 20:00

> ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an applic...
> Fraudsters steal $6 million from Tectonic crypto platform after inflating token price
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.
> OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
> Doxxing Safety Part II: Incident Response
Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimida...
> We invited a direct competitor into Security Hub Extended. Here’s why.
When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise s...
> Doxxing Safety Pt I: Prevention and Footprint Management
Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against ever...
> Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
> ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.” The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop.
> Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Next-level ClickFix wave sets off multi-stage attack chain
> Is Someone Hacking DoD Refrigerators?
It sure seems like it. The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation....
> Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
The company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation.
> IMY - autorité suédoise
L'Autorité suédoise de protection de la vie privée (IMY) a annoncé le lancement d'une application mobile visant à aider les jeunes à protéger leurs données personnelles sur les réseaux sociaux.L'application, nommée FantomApp, s'adresse aux enfants de 10 à 15 ans et propose des outils interactifs pou...
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) annonce la tenue de la deuxième édition de ses Rencontres Informatique & Libertés le 29 septembre 2026, un événement destiné aux professionnels du droit et de la protection des données.La première table ronde portera sur les lunett...
> USN-8706-1: zlib vulnerability
It was discovered that zlib incorrectly handled negative length parameters in CRC32 combine functions. An attacker could use this issue to cause a denial of service via excessive CPU consumption.
> GPDP - autorité italienne
La conservation des métadonnées de messagerie électronique des employés, même pour une durée limitée à 21 jours, ne relève pas de l'exception des "outils utilisés par le travailleur" si les finalités dépassent la simple garantie de fonctionnement du service et visent, par exemple, l'analyse d'incide...
> GPDP - autorité italienne
L'envoi d'un courriel à de multiples destinataires avec leurs adresses personnelles visibles constitue une communication de données à des tiers non autorisés, et donc une violation de données, même si elle résulte d'une simple erreur humaine.Faits et contexteL'autorité italienne de protection des do...
> North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical professi...
> PIPC - autorité sud-coréenne
La Commission de protection des informations personnelles (PIPC), autorité sud-coréenne, a sanctionné quatre sociétés pour des failles de sécurité ayant conduit à des violations de données, soulignant l'impératif de mettre en œuvre des mesures techniques robustes contre les attaques par bourrage d'i...
> UODO - autorité polonaise
Un huissier de justice qui se désigne lui-même délégué à la protection des données pour son propre office crée une situation de conflit d'intérêts manifeste, car il ne peut à la fois prendre des décisions en tant que responsable du traitement et contrôler la conformité de ces mêmes décisions en tant...
> This Android malware steals banking credentials even without an internet connection | Kaspersky official blog
How the Manic Trojan steals passwords, banking credentials and SMS codes, takes control of Android phones, and relays stolen information through other infected devices.