[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> How to Use a Password Manager to Share Your Logins After You Die (2025)
Your logins will live on after you pass on. Make sure they end up in the right hands.
> Capture JavaScript Integrity Metadata using CSP!
Today we're announcing the open beta of a brand new and incredibly powerful feature on the Report URI platform, CSP Integrity! Having the ability to collect integrity metadata for scripts running on your site opens up a whole new realm of possibilities, and it couldn't be
> Two-Thirds of Organizations Have Unfilled Cybersecurity Positions
Recruitment and retention remain a significant challenge for security teams, amid growing pressures on cyber professionals
> This month in security with Tony Anscombe – September 2025 edition
The past 30 days have seen no shortage of new threats and incidents that brought into sharp relief the need for well-thought-out cyber-resilience plans
> Tile Tracking Tags Can Be Exploited by Tech-Savvy Stalkers, Researchers Say
A team of researchers found that, by not encrypting the data broadcast by Tile tags, users could be vulnerable to having their location information exposed to malicious actors.
> SonicWall SSL VPN Attacks Escalate, Bypassing MFA
Akira ransomware attacks on SonicWall SSL VPN appliances are bypassing its MFA for rapid deployment
> Harrods Reveals Supply Chain Breach Impacting Online Customers
Department store Harrods has notified e-commerce customers of a major data breach
> Understanding your OT environment: the first step to stronger cyber security
If you can’t see your entire operational technology environment, you can’t defend it. New guidance from the NCSC will help you gain that visibility.
> Welcoming CERN to Have I Been Pwned
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.It's hard to explain the significance of CERN. It's the birthplace of the World Wide Web and the home of the largest machine ever built, the Large Hadron Collider. The bit that's hard to...
> LG Balakrishnan & Bros Ltd
LG Balakrishnan & Bros Ltd a subi une attaque de malware, mais a assuré que ses systèmes sont sécurisés. L'entreprise a pris des mesures immédiates pour contenir l'impact et a notifié les autorités compétentes. Les opérations commerciales se poursuivent normalement.
> DeKalb county government
Un incident de cybersécurité a touché le système informatique du gouvernement du comté de DeKalb. Les détails de l'incident ne sont pas précisés, mais il est actuellement en cours d'investigation. Le comté de DeKalb est situé dans l'Indiana, aux États-Unis.
> Bulletin d'actualité CERTFR-2025-ACT-041 (29 septembre 2025)
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
> Engel & Völkers
Le groupe immobilier Engel & Völkers a été victime d'une attaque informatique à la fin septembre 2025, entraînant la fuite de données personnelles de clients. Les données compromises incluent des noms, des adresses, des coordonnées et des informations liées à des transactions immobilières. L'entrepr...
> Charles P. Elliott, P.C.
The breach notification does not explicitly state that a breach occurred, but rather provides information on security freezes and credit monitoring services. However, it is implied that a breach may have occurred, prompting the notification. A cyberattack was claimed by Akira on November 4, 2025.
> AWS Network Firewall Egress Filtering Bypass
Bypass AWS Network Firewall Egress Filtering using SNI spoofing and Host Header manipulation.
> Debian Security Advisory: GIMP Denial of Service Vulnerabilities DSA-6014-1
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed Farbfeld, Wireless Bitmap, DICOM or Apple Icon images are opened.
> How a Travel YouTuber Captured Nepal’s Revolution for the World
Harry Jackson went into Kathmandu as a tourist. He ended up being one of the main international sources of news on Nepal’s Gen Z protests.
> Debian: Critical Symlink Bypass Vulnerability in node-tar-fs DSA-6013-1
It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.
> Debian: firefox-esr Important Connection Errors Fix DSA-6003-2
Firefox 140.3.1 has been released, which fixes connection errors with some sites; if HTTP/3 connections failed, the fallback is now handled more gracefully.
> Asahi Group Holdings, Ltd.
Asahi Group Holdings, Ltd. a subi une attaque informatique qui a provoqué une panne de système, affectant ses opérations au Japon. Les opérations de commande et d'expédition ainsi que les centres d'appel ont été suspendus. L'entreprise enquête actuellement sur la cause et travaille à rétablir les op...