> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. The company’s threat intelligence unit, Fortra Intelligence and Research Experts (FIRE), spent...
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 13,336 incidents with known revenue and defined mid-market companies as...
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteI genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house an...
AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability covers stateful rules in both custo...
La Commission de la construction du Québec (CCQ) est paralysée depuis lundi en raison d'une cyberattaque. L'organisme a confirmé l'incident et a fait appel à des experts externes pour évaluer l'étendue des dégâts. La CCQ n'a pas encore confirmé si des données ont été compromises, mais elle assure qu...
TeamSystem, un fournisseur de logiciels de gestion, a confirmé avoir subi une intrusion majeure dans ses systèmes de comptabilité en ligne. L'attaque, détectée le 24 août 2026, a entraîné l'exfiltration de données personnelles des clients, incluant les coordonnées bancaires (IBAN), les données d'ide...
De multiples vulnérabilités ont été découvertes dans Metabase. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection SQL (SQLi) et un problème de sécurité non spécifié par l'éditeur.
Nutex, un fournisseur de services de santé, enquête sur une violation de données où un tiers non autorisé a exfiltré des informations des serveurs de l'entreprise. L'incident a été divulgué à la SEC, et la société a engagé des spécialistes externes pour gérer la crise. Nutex n'a pas encore déterminé...
Franklin Mint Federal Credit Union (FMFCU) a connu une perturbation de son site web et de son accès bancaire numérique en raison d'un problème de domaine. L'incident a commencé lundi et s'est poursuivi mardi. Bien que les transactions aient continué à être traitées, les membres n'ont pas pu accéder...
De multiples vulnérabilités ont été découvertes dans LibreNMS. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
Sotheby's International, une société immobilière de luxe, enquête sur un incident de cybersécurité impliquant un accès non autorisé à des données stockées sur une plateforme logicielle tierce. Les données potentiellement compromises incluent des noms, adresses, adresses e-mail et numéros de téléphon...
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type an...
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot”    StubMaker RubyGems Campaign Delivers a Window...
Debian has issued an advisory for Thunderbird addressing multiple security vulnerabilities that could lead to arbitrary code execution or information disclosure, urging users to upgrade packages.
Debian released Security Advisory DSA-6460-1 addressing several vulnerabilities in OpenJDK Java runtime that could lead to denial of service or information disclosure, urging users to upgrade.
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
Aix-Marseille alerte 84 000 étudiants après une fraude réclamant 450 € sous couvert de frais scolaires. Explication de l'attaque !
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberatta...