> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
L'autorité finlandaise de protection des données a rappelé les obligations à respecter en matière de protection des données lors de l'utilisation de lunettes intelligentes.L'autorité souligne que l'utilisation de lunettes intelligentes constitue un traitement de données personnelles, collectant des...
La Commission nationale de l'informatique et des libertés (CNIL) a publié une nouvelle version de son outil expérimental, Genmod, destiné à la traçabilité des modèles d'intelligence artificielle publiés en source ouverte.Développé par le service IA de la CNIL en collaboration avec son Laboratoire d’...
Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool...
Cette décision, bien que ne donnant pas lieu à une sanction, détaille l'analyse par l'autorité danoise des pratiques de vidéosurveillance d'une société de logement, en insistant particulièrement sur le caractère incomplet et passif de l'information fournie aux personnes concernées.Faits et contexteL...
L'autorité danoise de protection des données a publié une décision de clôture d'inspection concernant l'utilisation de la vidéosurveillance par une société de logement social. Bien qu'aucune sanction n'ait été prononcée, la décision formule une série de rappels et de points d'attention essentiels po...
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a...
Meta has agreed to pay a $18 billion settlement and implement child-safety measures on Instagram and Facebook, ending a landmark trial.
FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The o...
The FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments.
Feng Ning discovered that libheif incorrectly handled certain image
transforms. A remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-62289)
Ali Firas discovered that libheif incorre...
Vitaly Simonovich discovered that Bind could exhaust memory during
GSS-API TKEY negotiation. A remote attacker could possibly use this
issue to cause Bind to use excessive resources, leading to a denial of
service. (CVE-2026-3039)
Shuhan Zhang discovered that Bind incorrectly handled self-pointed g...
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security...
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
The activity has been attributed to a Chinese state-sponsored...
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]
Under this settlement, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collecti...
The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.
Several security issues were fixed in OpenSSL and OpenSSL 1.0.
Summary On-chain potentially taxable crypto activity around the world reached more than $457 billion in 2025, with the United States…
The post What Blockchain Data Tell Us About $457+ Billion in Potentially Taxable Crypto Activity appeared first on Chainalysis.
A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"&#;x26;#;x3f;&#;x26;#;xc2;&#;x26;#;xa0; Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose).&#;x26;#;xc2;&a...
Researchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group.