> TODAY'S SUMMARY (4 articles)
Today's cybersecurity landscape highlights significant threats from AI, which can now autonomously execute complex attacks on critical infrastructure, raising concerns about preparedness. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities catalog, adding several high-risk software flaws, including those in ProFTPD and ONLYOFFICE Docs, emphasizing the need for immediate patching. Additionally, the ongoing FortiBleed vulnerability remains active, threatening organizations that have not yet implemented fixes. The broader implications of AI in cybersecurity are also being examined, particularly in relation to governance and compliance issues. Overall, organizations must remain vigilant and proactive in addressing these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:01
Malware campaigns distributing the RondoDox botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30 vendors.
The activity, described as akin to an "exploit shotgun" approach, has singled out a wide range of internet-exposed infrastructure, including routers,...
Microsoft said it has revamped the Internet Explorer (IE) mode in its Edge browser after receiving "credible reports" in August 2025 that unknown threat actors were abusing the backward compatibility feature to gain unauthorized access to users' devices.
"Threat actors were leveraging basic social e...
Oxygen Forensics releases Oxygen Remote Explorer v1.9.1, delivering enhanced remote collection, expanded app support, and powerful new forensic features.
Apple has doubled its top bug bounty reward to $2m but with bonuses it could reach $5m
Cybercriminals have tricked X’s AI chatbot into promoting phishing scams in a technique that has been nicknamed “Grokking”. Here’s what to know about it.
For the latest discoveries in cyber research for the week of 13th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Qilin ransomware group has claimed responsibility for targeting Asahi, Japan’s largest brewing company, that had been hacked on September 29th. The at...
The infamous BreachForums site has been taken offline again to disrupt Scattered Lapsus$ Hunters
A list of topics we covered in the week of October 6 to October 12 of 2025
Cybersecurity researchers are calling attention to a new campaign that delivers the Astaroth banking trojan that employs GitHub as a backbone for its operations to stay resilient in the face of infrastructure takedowns.
"Instead of relying solely on traditional command-and-control (C2) servers that...
Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts.
"Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an over-privileged...
Une vulnérabilité a été découverte dans Belden HiOS Switch Platform. Elle permet à un attaquant de provoquer un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
Une vulnérabilité a été découverte dans Oracle E-Business Suite. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
On Oct. 13, 2025, Jetobra discovered a data breach compromising sensitive data belonging to an unknown number of individuals. An investigation determined that a cybercriminal gained access to the company's internal network between Sept. 16, 2025 and Sept. 17, 2025.
Designs For Vision, Inc. experienced a data breach between October 11, 2025, and October 13, 2025, resulting in unauthorized access to certain computer systems and the theft of files. The breach involved the theft of personal data, including names and other data elements. A cyberattack was claimed b...
Blue Teal Holdings, LLC experienced unauthorized access to certain systems, resulting in the potential exposure of protected personal information. The incident occurred through current or previous relationships with Blue Teal Holdings' affiliates, subsidiaries, and other entities. The company is off...
Euronics XXL à Brackenheim a été victime d'une cyberattaque en octobre 2025, lui faisant rater les ventes de fin d'année. Le magasin, propriété de Schüle Handels GmbH a engagé une procédure de redressement en avril 2026.
BreachForums saisi. Scattered Spider maintient la pression. ZATAZ éclaire l’angle intégrations SaaS et les opérations françaises liées au forum....