[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (16 articles)

|

// AI-powered summary generated at 20:00

> Shai-Hulud Worm Prowls npm to Steal Hundreds of Secrets
A secret-stealing worm is spreading fast across the npm ecosystem, experts have warned
> Multiples vulnérabilités dans les produits Mattermost (17 septembre 2025)
De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
> Chroma ATE Inc.
Chroma ATE a été victime d'une attaque de hackers, mais grâce à son équipe de sécurité et à la collaboration avec des professionnels, aucune information personnelle ou confidentielle n'a été divulguée. L'entreprise a activé ses mécanismes de défense et a renforcé la sécurité de son infrastructure. L...
> Morrisroe Ltd
Morrisroe Ltd a subi une attaque informatique, les données personnelles de ses employés, y compris les informations financières et bancaires, pourraient avoir été compromises. L'entreprise a pris des mesures pour contenir l'attaque et avertit ses employés de rester vigilants. L'attaque a été découve...
> Myth Busting: Why "Innocent Clicks" Don't Exist in Cybersecurity
Unit 42 explores how innocent clicks can have serious repercussions. Learn how simply visiting a malicious site can expose users to significant digital dangers. The post Myth Busting: Why "Innocent Clicks" Don't Exist in Cybersecurity appeared first on Unit 42.
> California, Tell Governor Newsom: Regulate AI Police Reports and Sign S.B. 524
The California legislature has passed a necessary piece of legislation, S.B. 524, which starts to regulate police reports written by generative AI. Now, it’s up to us to make sure Governor Newsom will sign the bill.  We must make our voices heard. These technologies obscure certain records and draft...
> Debian Bookworm: node-sha.js Critical Incomplete Type Checks DSA-6002-1
It was discovered that Node sha.js, an implementation of the SHA family hash functions in pure JavaScript, performed incomplete type checks. For the oldstable distribution (bookworm), this problem has been fixed
> Fifteen Ransomware Gangs “Retire,” Future Unclear
Fifteen ransomware groups have claimed shutdown on BreachForums; experts warn of rebrands and copycats
> Gucci and Alexander McQueen Hit by Customer Data Breach
The attack, which is linked to ShinyHunters, has reportedly compromised data relating to 7.4 million unique email addresses
> Sentinels League: Live Rankings for the Threat Hunting World Championship
The Sentinels League brings global threat hunters together to battle across AI, Cloud, SIEM & Endpoint surfaces for $100K in prizes and more.
> Chinese AI Villager Pen Testing Tool Hits 11,000 PyPI Downloads
AI-native Villager, which automates Kali and DeepSeek penetration tests, has reached 11,000 PyPI downloads fueling dual-use threat
> Self-Replicating Worm Hits 180+ Software Packages
At least 187 code packages made available through the JavaScript repository NPM have been infected with a self-replicating worm that steals credentials from developers and publishes those secrets on GitHub, experts warn. The malware, which briefly infected multiple code packages from the security ve...
> LABScon 2025 | From LLM Malware to Hotel Room Bugs: A Look at This Year’s Talks
Discover the groundbreaking threat intelligence debuting at LABScon 2025! From AI-driven malware and cryptocrime to surveillance tech and cyber espionage.
> Under the Pure Curtain: From RAT to Builder to Coder
Research by: Antonis Terefos (@Tera0017) Key Points Introduction The Pure malware family is a suite of malicious tools developed and sold by the author known as PureCoder. This suite includes PureHVNC RAT (a remote administration tool and predecessor to PureRAT), PureCrypter (a malware obfuscator), ...
> HybridPetya: The Petya/NotPetya copycat comes with a twist
HybridPetya is the fourth publicly known real or proof-of-concept bootkit with UEFI Secure Boot bypass functionality
> UK: Tax Refund-Themed Phishing Slows in 2025
Reports of email phishing attempts impersonating the UK’s HM Revenue & Customs plummeted in the first half of 2025
> Fickling’s new AI/ML pickle file scanner
We’ve added a pickle file scanner to Fickling that uses an allowlist approach to protect AI/ML environments from malicious pickle files that could compromise models or infrastructure.
> JLR Extends Production Halt After Cyber-Attack
Jaguar Land Rover (JLR) has confirmed that its pause in production will last until at least Wednesday, September 24
> API Threats Surge to 40,000 Incidents in 1H 2025
Thales claims there were over 40,000 API incidents in the first half of 2025
> CVE-2025-54896 Microsoft Excel Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action...