Nimbus Manticore Deploys New Malware Targeting Europe Key Findings Introduction Since early 2025, Check Point Research (CPR) has tracked waves of Nimbus Manticore activity. Known as UNC1549 or Smoke Sandstorm, Nimbus Manticore is a mature Iran-nexus APT group that primarily targets aerospace and def...
Police are using their drones as flying automated license plate readers (ALPRs), airborne police cameras that make it easier than ever for law enforcement to follow you.Â
"The Flock Safety drone, specifically, are flying LPR cameras as well,” Rahul Sidhu, Vice President of Aviation at Flock Safety,...
REMPAR25 : un exercice de crise cyber d’une ampleur inédite
anssiadm
lun 22/09/2025 - 11:47
Jeudi 18 septembre 2025, l’ANSSI a organisé REMPAR25, un exercice national de gestion de crise cyber de grande ampleur, en partenariat avec le Campus Cyber national, les campu...
What you see is not always what you get as cybercriminals increasingly weaponize SVG files as delivery vectors for stealthy malware
The FBI has warned that adversaries have published fake versions of its cybercrime reporting portal IC3
Heathrow, Brussels, Dublin and Berlin airports are among those disrupted by a cyber-attack on Collins Aerospace
Quand les gens nous posent la question suivante : "Les solutions Endpoint ne sont-elles pas toutes identiques de nos jours ? » notre réponse est simple : Non, elles ne le sont pas !
For the latest discoveries in cyber research for the week of 22nd September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Several major European airports including Heathrow, Berlin, Brussels, Dublin, and Cork have experienced a cyber-attack, resulting in disruptions to...
As the Cyber Resilience Act (CRA) is getting closer and companies wanting to sell digital services in goods within the EU need to step up, tighten their procedures, improve their documentation and get control over their dependencies I feel it could be timely to remind everyone: We of course offer fu...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS ratin...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS ratin...
Le fabricant de outils de coupe TENRYU AMERICA, INC. a été victime d'une attaque de ransomware, ce qui a entraîné la cryptage de données sur son serveur. L'entreprise a isolé le serveur et travaille avec des experts en sécurité pour résoudre le problème. Aucune fuite de données de clients ou de part...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS ratin...
Healthy Living suffered a ransomware attack on 9/22/2025, potentially accessing files containing personally identifiable information. The organization has seen no evidence of misuse, but is notifying staff in an abundance of caution. Staff are advised to monitor their credit reports and account stat...
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
Abusing IAM Roles Anywhere to obtain persistent AWS access from outside the cloud.
Abusing the CodeBuild managed GitHub Actions runner integration to obtain long‑term access to an AWS environment.
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.Imagine jumping on board a class action after your precious datas have been breached, then sticking through it all the way until a settlement is reached. Then, finally, after a long and a...
In October 2021, the now defunct Arabic language Anime website Animeify suffered a data breach that was later redistributed as part of a larger corpus of data. The data included 808k unique email addresses along with names, usernames, genders and plain text passwords.