[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Sophos se classe en tête des Rapports G2 Fall 2025 : N°1 Overall dans la catégorie MDR et Firewall
Sophos classé N°1 dans 47 Rapports Globaux.
> Gamaredon X Turla collab
Notorious APT group Turla collaborates with Gamaredon, both FSB-associated groups, to compromise high‑profile targets in Ukraine
> Attackers Abuse AI Tools to Generate Fake CAPTCHAs in Phishing Attacks
Trend Micro said the use of AI platforms to create and host fake CAPTCHA pages helps attackers develop more sophisticated phishing campaigns at scale and speed
> Debian: DSA-6004-1 Chromium Critical Arbitrary Code Exec Threat
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-10585 exists in the wild.
> Vastaamo psychotherapy hack: US citizen charged in latest twist of notorious data breach
28-year-old Daniel Lee Newhard, an American citizen living in Estonia, has been charged in relation to the notorious hack of Vastaamo, the biggest data breach in Finnish history. Read more in my article on the Hot for Security blog.
> Chromium: CVE-2025-10501 Use after free in WebRTC
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
> Chromium: CVE-2025-10585 Type Confusion in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information. Google is aware that an exploit for CVE-2025-10585 exists in the wild.
> Bye bye Kerberos FTP
We are dropping support for this feature in curl 8.17.0. Kerberos5 FTP to be exact. The last Kerberos support we had for FTP. Badness On September 16, 2025 we received a security report that accurately identified a possible stack based buffer overflow in the Kerberos FTP code that could allow a mali...
> Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
> Chromium: CVE-2025-10500 Use after free in Dawn
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
> Have I Been Pwned Demos Are Now Live!
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.Well, one of them is, but what's important is that we now have a platform on which we can start pushing out a lot more. It's not that HIBP is a particularly complex system that needs expl...
> Collins Aerospace
Un attaque informatico contre Collins Aerospace, un fournisseur de services aeroportuels, cause des perturbations dans plusieurs aeroports europeens, notamment Heathrow, Berlino et Bruxelles. Les passagers sont invités à vérifier l'état de leur vol avec leur compagnie aérienne avant de se rendre à l...
> Circle K (OK便利店)
Le réseau de Circle K (OK便利店) a été touché par une panne de réseau, ce qui a affecté les systèmes de paiement, les e-mails et les plans de récompense pour les membres, les magasins fonctionnent normalement mais ne acceptent que les paiements en espèces et par Octopus. L'entreprise enquête sur l'i...
> Authorizing access to data with RAG implementations
Organizations are increasingly using large language models (LLMs) to provide new types of customer interactions through generative AI-powered chatbots, virtual assistants, and intelligent search capabilities. To enhance these interactions, organizations are using Retrieval-Augmented Generation (RAG)...
> Catawba County government
Le site web du gouvernement du comté de Catawba a été rétabli mardi après-midi après avoir été hors ligne pendant plusieurs jours. Le site web était soit hors ligne, soit en maintenance depuis vendredi. Une cyberattaque contre le gouvernement du comté a été revendiquée par Qilin le 14 octobre.
> Dermatology Associates of Concord
Dermatology Associates of Concord suffered a cyber-attack that resulted in unauthorized access to certain files within their network. The breach occurred between September 18, 2025, and September 19, 2025. An attack against Dermatology Associates was claimed by Anubis on November 6.
> Shining a Spotlight on Digital Rights Heroes: EFF Awards 2025
It's been a year full of challenges, but also important victories for digital freedoms. From EFF’s new lawsuit against OPM and DOGE, to launching Rayhunter (our new tool to detect cellular spying), to exposing the censorship of abortion-related content on social media, we’ve been busy! But we’re not...
> Johnson, Webbert, & Beard, LLP
Unauthorized access to Johnson, Webbert, & Beard, LLP's network occurred between September 15, 2025, and September 19, 2025, potentially exposing personal information. The incident was discovered on September 19, 2025, and an investigation was conducted. The organization is offering complimentary id...
> EFF, ACLU to SFPD: Stop Illegally Sharing Data With ICE and Anti-Abortion States
The San Francisco Police Department is the latest California law enforcement agency to get caught sharing automated license plate reader (ALPR) data with out-of-state and federal agencies. EFF and the ACLU of Northern California are calling them out for this direct violation of California law, which...
> Debian: Firefox ESR Critical Code Execution Risks DSA-6003-1
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or bypass of the same-origin policy.