> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
Aix-Marseille alerte 84 000 étudiants après une fraude réclamant 450 € sous couvert de frais scolaires. Explication de l'attaque !
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberatta...
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attack...
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest pro...
New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI researcher Rony Utevsky devised a new attack technique, called Cryptographic Context Injection, that bypasses AI safety filters by sending instructi...
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan...
La ville de Libercourt a été victime d'une cyberattaque par rançongiciel (ransomware) à la fin du mois d'août. Bien que les services municipaux ne soient pas impactés, il est confirmé que des données personnelles ont été exfiltrées. La municipalité a renforcé la sécurité de ses serveurs et a signalé...
Le groupe financier Partners a été victime d'une cyberattaque qui a entraîné la fuite de certaines données personnelles de ses clients. L'attaque, survenue le dimanche précédent la publication, a affecté plusieurs entités du groupe, notamment Partners Financial Services, Simplea, Rentea et Simplea F...
Debian has addressed two vulnerabilities in libnet-dns-perl that pose risks of denial of service and remote code execution, advising users to upgrade to version 1.56-0+deb13u1.
La plateforme scolaire nationale IServ a été victime d'une cyberattaque affectant un module cloud de l'opérateur. La municipalité de Hattingen a confirmé que les écoles locales utilisent ce module et pourraient être indirectement touchées, bien qu'aucune fuite de données personnelles d'élèves ou de...
Le gouvernement municipal de San Luis Potosà a été victime d'une cyberattaque par rançongiciel (ransomware). Les attaquants ont exigé une rançon en échange de la libération des informations volées. L'attaque a principalement ciblé les déclarations patrimoniales des employés municipaux. La municipali...
The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. Â
The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.
ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2....
A new study finds leading AI labs have few publicly documented plans for containing rogue models, raising questions about preparedness as AI systems increasingly demonstrate unexpected and potentially dangerous behavior.
Agents are also the new attack surface - cue defenders' existential angst
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.
As part of the settlement, the social media platform will pay $300 million immediately, and an add...
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
Cyber actualités ZATAZ de la semaine du 17 au 23 août 2026. Un mois d'août trés... hot !
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe comm...
ShinyHunters revendique un piratage de Logitech et Streamlabs. Les streameurs en danger ?