[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 08:00

> 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign
Cybersecurity researchers have flagged a new set of 175 malicious packages on the npm registry that have been used to facilitate credential harvesting attacks as part of an unusual campaign. The packages have been collectively downloaded 26,000 times, acting as an infrastructure for a widespread phi...
> Forensic Focus Digest, October 10 2025
Discover what’s new on Forensic Focus – from impression evidence analysis and faster encrypted data access to enterprise DFIR insights and wellness lessons from Debbie Garner.
> Cops nuke BreachForums (again) amid cybercrime supergroup extortion blitz
US and French fuzz pull the plug on Scattered Lapsus$ Hunters' latest leak shop targeting Salesforce US authorities have seized the latest incarnation of BreachForums, the cybercriminal bazaar recently reborn under the stewardship of the so-called Scattered Lapsus$ Hunters, with help from French cyb...
> Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit
GTIG highlighted indicators that Clop is behind the extortion campaign targeting Oracle EBS instances, with its activity likely beginning as early as August 9
> UK techies' union warns members after breach exposes sensitive personal details
Prospect apologizes for cyber gaffe affecting up to 160K members UK trade union Prospect is notifying members of a breach that involved data such as sexual orientation and disabilities.…
> From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability
Cybersecurity company Huntress said it has observed active in-the-wild exploitation of an unpatched security flaw impacting Gladinet CentreStack and TrioFox products. The zero-day vulnerability, tracked as CVE-2025-11371 (CVSS score: 6.1), is an unauthenticated local file inclusion bug that allows u...
> Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits
With the mercenary spyware industry booming, Apple VP Ivan Krstić tells WIRED that the company is also offering bonuses that could bring the max total reward for iPhone exploits to $5 million.
> North Korean Scammers Are Doing Architectural Design Now
New research shows that North Koreans appear to be trying to trick US companies into hiring them to develop architectural designs using fake profiles, résumés, and Social Security numbers.
> La France décroche la 5e place de l’European Cybersecurity Challenge 2025
La France décroche la 5e place de l’European Cybersecurity Challenge 2025 anssiadm ven 10/10/2025 - 08:29 La Team France encadrée par des coachs de l’ANSSI a obtenu la 5e place lors de l’édition 2025 de l’European Cybersecurity Challenge (ECSC) qui s’est tenue à Vars...
> Pro-Russia Hacktivists “Claim” Attack on Water Utility Honeypot
Forescout said that the TwoNet actor was lured into attacking a honeypot disguised as a water treatment utility, providing insights into the group’s tactics
> CVE-2025-59220 Windows Bluetooth Service Elevation of Privilege Vulnerability
Added acknowledgements. This is an informational change only.
> CrowdStrike Named a Visionary in 2025 Gartner® Magic Quadrant™ for Security Information and Event Management
> CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw
Dozens of organizations may have been impacted following the zero-day exploitation of a security flaw in Oracle's E-Business Suite (EBS) software since August 9, 2025, Google Threat Intelligence Group (GTIG) and Mandiant said in a new report released Thursday. "We're still assessing the scope of thi...
> Oracle Linux 8: Important Advisory ELSA-2025-17675 for compat-libtiff3
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> ZDI-25-952: Ivanti Endpoint Manager UniqueFilename Unrestricted File Upload Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is require...
> Multiples vulnérabilités dans Microsoft Edge (10 octobre 2025)
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans le noyau Linux de Red Hat (10 octobre 2025)
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
> Lycées de la région des Hauts-de-France
Une attaque de rançongiciel impliquant l'enseigne Qilin a touché près de 80% des lycées publics de la région des Hauts-de-France, mais les cours continuent malgré la suspension temporaire de l'accès à Internet. Les équipes techniques travaillent à contenir l'attaque et à sécuriser les infrastructure...
> Multiples vulnérabilités dans le noyau Linux d'Ubuntu (10 octobre 2025)
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Elles permettent à un attaquant de provoquer un déni de service et un problème de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans le noyau Linux de SUSE (10 octobre 2025)
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.