[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 08:00

> Law Offices of Alan M. Cohen & Associates LLC ("AMC")
A data breach occurred at Law Offices of Alan M. Cohen & Associates LLC between October 1 and October 9, 2025, where an unauthorized individual may have viewed and copied sensitive information. The incident was discovered on October 9, 2025, and the organization is providing credit monitoring servic...
> Smashing Security podcast #438: When your mouse turns snitch, and hackers grow a conscience
Your computer's mouse might not be as innocent as it looks - and one ransomware crew has a crisis of conscience that nobody saw coming. We talk about how something as ordinary as a web page could turn your mouse into a surprisingly nosey neighbour, and why ransomware gangs need to think carefully...
> How to configure and verify ACM certificates with trust stores
In this post, we show how to configure customer trust stores to work with public certificates issued through AWS Certificate Manager (ACM). Organizations can encounter challenges when configuring trust stores for ACM certificates and incorrect trust store configuration can lead to SSL/TLS errors and...
> EFF and Other Organizations: Keep Key Intelligence Positions Senate Confirmed
In a joint letter to the ranking members of the House and Senate intelligence committees, EFF has joined with 20 other organizations, including the ACLU, Brennan Center, CDT, Asian Americans Advancing Justice, and Demand Progress, to express opposition to a rule change that would seriously weaken ac...
> Étude de cas : comment Advance2000 protège plus de 10 000 utilisateurs avec Sophos ?
Sophos MDR est quasiment obligatoire pour assurer la sécurité des clients de ce MSP basé à New York.
> Apps Script project impersonation / Google Apps Script persistence
Google Workspace Apps Script projects create hidden GCP projects (sys-<...>) that can be impersonated by attackers. This technique enables stealthy persistence (service accounts, hidden compute, cryptomining) and can bypass common console inspections.
> Should I use managed login or create a custom UI in Amazon Cognito?
October 8, 2025: This blog post has been updated to include the Amazon Cognito managed login experience. The managed login experience has an updated look, additional features, and enhanced customization options. September 8, 2023: It’s important to know that if you activate user sign-up in your user...
> The State of Ransomware in Healthcare 2025
292 IT and cybersecurity leaders reveal the ransomware realities for healthcare establishments today.
> Take this rob and shove it! Salesforce issues stern retort to ransomware extort
CRM giant 'will not engage, negotiate with, or pay' the scumbags Salesforce won't pay a ransom demand to criminals who claim to have stolen nearly 1 billion customer records and are threatening to leak the data if the CRM giant doesn't pony up some cash.…
> Here’s the tech powering ICE’s deportation crackdown 
From phone spyware and facial recognition to phone unlocking technology and databases and more, this tech powers Trump's deportation machine.
> Salesforce data breach: what you need to know
The Scattered LAPSUS$ Hunters hacking group claims to have accessed data from around 40 customers of Salesforce, the cloud-based customer relationship management service, stealing almost one billion records. Read more in my article on the Fortra blog.
> Modeling scams see mature models as attractive new prospects
Modeling scammers are reinventing old tricks for the social media age—targeting not just the young, but older adults too.
> How we found a bug in Go's arm64 compiler
84 million requests a second means even rare bugs appear often. We'll reveal how we discovered a race condition in the Go arm64 compiler and got it fixed.
> InfoSec News Nuggets 10/08/2025
Foreign threat actors adopting ChatGPT to bolster “old playbook” of attacks, OpenAI finds  But, in what may be considered good news for security teams, the AI start-up also says most threat actors appear to be playing it safe and sticking with “tried and true” methods previously used to carry out th...
> Getting your organisation ready for Windows 11 upgrade before Autumn 2025
Why you should act now to ensure you meet the new hardware standards, and prioritise security.
> Nezha Tool Used in New Cyber Campaign Targeting Web Applications
A cyber campaign using Nezha has been identified, targeting vulnerable web apps with PHP web shells and Ghost RAT
> Germany slams brakes on EU's Chat Control device-scanning snoopfest
Berlin's opposition likely kills off Brussels' bid to scan everyone's messages Germany has committed to oppose the EU's controversial "Chat Control" regulations following huge pressure from multiple activists and major organizations.…
> Cryptographie post-quantique, les travaux de l’ANSSI
Cryptographie post-quantique, les travaux de l’ANSSI anssiadm mer 08/10/2025 - 12:34 Accompagner la transition vers la cryptographie post-quantique : l’ANSSI présente ses travaux et sa FàQ dédiée, en faveur d’une mobilisation collective pour répondre à un enjeu majeu...
> Digital Fraud Costs Companies Worldwide 7.7% of Annual Revenue
According to TransUnion, digital fraud has cost companies $534bn in losses globally with US business hit hardest
> Airline-mimicking fraud | Kaspersky official blog
Scammers are sending emails purporting to be from major airlines/airports trying to swindle money by demanding refundable deposits.