> TODAY'S SUMMARY (4 articles)
Today's cybersecurity landscape highlights significant threats from AI, which can now autonomously execute complex attacks on critical infrastructure, raising concerns about preparedness. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities catalog, adding several high-risk software flaws, including those in ProFTPD and ONLYOFFICE Docs, emphasizing the need for immediate patching. Additionally, the ongoing FortiBleed vulnerability remains active, threatening organizations that have not yet implemented fixes. The broader implications of AI in cybersecurity are also being examined, particularly in relation to governance and compliance issues. Overall, organizations must remain vigilant and proactive in addressing these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:01
292 responsables IT/Cybersécurité révèlent les expériences vécues actuellement face aux ransomwares par les établissements de santé.
Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data.
The vulnerability, tracked as CVE-2025-61884, carries a CVSS score of 7.5, indicating high severity. It affects versions from 12....
When a website fails, your browser returns an HTTP status code that’s short, technical, and often cryptic. You’ve probably seen 404 Not Found or 500 Internal Server Error. Less common, but just as disruptive, is 501 Not Implemented. This guide explains what a 501 error actually means, how it present...
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.This week's video was recorded on Friday morning Aussie time, and as promised, hackers dumped data the following day. Listening back to parts of the video as I write this on a Sunday morn...
Omrin said to be experiencing a technical malfunction due to a ransomware attack, and working hard to find a solution. It cannot be reached by telephone, but can be contacted by email. Omrin will honor existing appointments (bulky waste) as much as possible.
Le groupe DLSI a subi une cyberattaque sur deux de ses filiales, PRESTIM et ML Intérim, mais a pu récupérer toutes ses données sans altération. Les autres sociétés du groupe n'ont pas été impactées. Un dépôt de plainte et une notification à la CNIL ont été effectués.
Cybersecurity company Huntress on Friday warned of "widespread compromise" of SonicWall SSL VPN devices to access multiple customer environments.
"Threat actors are authenticating into multiple accounts rapidly across compromised devices," it said. "The speed and scale of these attacks imply that th...
MedImpact a récemment identifié un logiciel de rançon sur certains de ses systèmes, ce qui a entraîné une interruption de service. L'entreprise a pris des mesures pour contenir et atténuer l'incident, et elle travaille actuellement à la restauration des systèmes touchés. Les réclamations de pharmaci...
Threat actors are abusing Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in connection with ransomware attacks likely orchestrated by Storm-2603 (aka CL-CRI-1040 or Gold Salem), which is known for deploying the Warlock and LockBit ransomware.
The threat actor's use...
Les hackers nord-coréens ont volé plus de 2 milliards en cryptoactifs en 2025....
Plus: US government cybersecurity staffers get reassigned to do immigration work, a hack exposes sensitive age-verification data of Discord users, and more.
Microsoft, Zataz et le FBI alertent : les services RH deviennent la cible privilégiée des cybercriminels détournant les salaires....
In October 2025, data stolen from the Salesforce instances of multiple companies by a hacking group calling itself "Scattered LAPSUS$ Hunters" was publicly released. Among the affected organisations was Vietnam Airlines, which had 7.3M unique customer email addresses exposed following a breach of it...
Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code if malformed document files are processed. For the oldstable distribution (bookworm), these problems have been fixed
Kearney Public Schools a été victime d'une attaque de cybersécurité qui a compromis son réseau technologique, les écoles resteront ouvertes mais les téléphones et les emails ne seront pas opérationnels jusqu'à la restauration du réseau. Les systèmes basés sur le cloud, y compris les informations sur...
I like testing publication strategies. I started self-publishing my own books in 2011 after having bad experiences with traditional publishers. This worked out amazingly well for about a decade. Over the last few years, book piracy eliminated many of the sales, and we have retreated from further new...
Online surveillance is everywhere—and understanding how you’re being tracked, and how to fight back, is more important than ever. That’s why EFF partnered with Women In Security and Privacy (WISP) for our annual Global Members’ Speakeasy, where we tackled online behavioral tracking and the massive d...
Video.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
Scattered Lapsus$ Hunters: Organizations, be aware of the effort of this cybercriminal alliance as they target retail and hospitality for extortion.
The post The Golden Scale: Bling Libra and the Evolving Extortion Economy appeared first on Unit 42.
Austin, Texas is a major tech hub with a population that’s engaged in advocacy and paying attention. Since 1991, EFF-Austin an independent nonprofit civil liberties organization, has been the proverbial beacon alerting those in central Texas to the possibilities and implications of modern technology...