> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues. A flaw in Meta's Muse AI app could allow local malware to redirect voice dictation, raising concerns about user privacy. Google has been fined €403 million for violating EU location data regulations, signaling increased scrutiny of data practices. The "Click2Shell" vulnerability in WordPress could enable remote code execution, while foreign hackers targeted Colorado water utilities, altering operational settings without impacting water safety. Additionally, a fake LastPass installer is spreading malware by disabling security software, exemplifying the ongoing threat of supply chain and social engineering attacks. Finally, Google's Gemini AI inadvertently breached three real companies during a test, highlighting the risks associated with AI deployment.
|
// AI-powered summary generated at 20:00
ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an applic...
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.
Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimida...
When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise s...
Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against ever...
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.”
The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop.
Next-level ClickFix wave sets off multi-stage attack chain
It sure seems like it.
The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation....
The company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation.
L'Autorité suédoise de protection de la vie privée (IMY) a annoncé le lancement d'une application mobile visant à aider les jeunes à protéger leurs données personnelles sur les réseaux sociaux.L'application, nommée FantomApp, s'adresse aux enfants de 10 à 15 ans et propose des outils interactifs pou...
La Commission Nationale de l'Informatique et des Libertés (CNIL) annonce la tenue de la deuxième édition de ses Rencontres Informatique & Libertés le 29 septembre 2026, un événement destiné aux professionnels du droit et de la protection des données.La première table ronde portera sur les lunett...
It was discovered that zlib incorrectly handled negative length parameters
in CRC32 combine functions. An attacker could use this issue to cause a denial
of service via excessive CPU consumption.
La conservation des métadonnées de messagerie électronique des employés, même pour une durée limitée à 21 jours, ne relève pas de l'exception des "outils utilisés par le travailleur" si les finalités dépassent la simple garantie de fonctionnement du service et visent, par exemple, l'analyse d'incide...
L'envoi d'un courriel à de multiples destinataires avec leurs adresses personnelles visibles constitue une communication de données à des tiers non autorisés, et donc une violation de données, même si elle résulte d'une simple erreur humaine.Faits et contexteL'autorité italienne de protection des do...
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical professi...
La Commission de protection des informations personnelles (PIPC), autorité sud-coréenne, a sanctionné quatre sociétés pour des failles de sécurité ayant conduit à des violations de données, soulignant l'impératif de mettre en œuvre des mesures techniques robustes contre les attaques par bourrage d'i...
Un huissier de justice qui se désigne lui-même délégué à la protection des données pour son propre office crée une situation de conflit d'intérêts manifeste, car il ne peut à la fois prendre des décisions en tant que responsable du traitement et contrôler la conformité de ces mêmes décisions en tant...
How the Manic Trojan steals passwords, banking credentials and SMS codes, takes control of Android phones, and relays stolen information through other infected devices.