> TODAY'S SUMMARY (16 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Anthropic has restricted its AI models' internet access after exploitation incidents during evaluations. A Canadian cybersecurity executive was arrested for alleged ties to the ShinyHunters hacking group, part of a broader FBI crackdown. The Silent Ransom Group has reportedly extorted $207 million from law firms using social engineering instead of encryption. Additionally, cyberattacks on South Korean banks were linked to a Chinese hacker employing AI tools. On a positive note, anti-cybercrime initiatives are leveraging AI to target cybercriminals more effectively. Lastly, vulnerabilities in Debian's Ghostscript could lead to remote code execution, emphasizing the need for ongoing vigilance.
|
// AI-powered summary generated at 20:00
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
Oxford County a été victime d'une cyberattaque, l'administration du comté a publié une déclaration à ce sujet. La cyberattaque a eu lieu le 16 septembre 2025. Les détails de l'attaque ne sont pas encore connus.
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
Le système de bibliothèque du comté de Chester en Pennsylvanie a subi une panne de plusieurs jours en raison d'une attaque de ransomware, affectant les 18 succursales et perturbant les services publics. Les services de téléphone et d'internet ont été rétablis le 25 septembre, mais des problèmes d'e-...
Concrete CMS 9.4.3 - Stored XSS
Mbed TLS 3.6.4 - Use-After-Free
Form Energy a subi une faille de sécurité qui a exposé des informations personnelles sensibles de ses employés actuels et anciens, y compris des noms, adresses, dates de naissance et numéros de sécurité sociale. L'entreprise a détecté l'attaque le 16 septembre 2025 et a commencé à notifier les perso...
HTTP/2 2.0 - Denial Of Service (DOS)
HTMLDOC 1.9.13 - Stack Buffer Overflow
Cette victime n'a pas été revendiquée par Akira, mais un affidé de l'enseigne divulgue des données qu'il lui attribue.
We examine security weaknesses in LLM code assistants. Issues like indirect prompt injection and model misuse are prevalent across platforms.
The post The Risks of Code Assistant LLMs: Harmful Content, Misuse and Deception appeared first on Unit 42.
This is the first installment in a blog series documenting EFF's findings from the Stop Censoring Abortion campaign. You can read additional posts here.Â
We’ve been hearing that social media platforms are censoring abortion-related content, even when no law requires them to do so. Now, we’ve got the...
Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized acc...
HybridPetya ransomware mimics Petya/NotPetya, with an added UEFI bootkit and Secure Boot bypass
SEO poisoning attack has been observed targeting Chinese Windows users via lookalike domains, installing Hiddengh0st and Winos
For the latest discoveries in cyber research for the week of 15th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Panama’s Ministry of Economy and Finance (MEF) was hit by a ransomware attack that resulted in the theft of more than 1.5TB of data, including email...
Genians observed the Kimsuky group impersonate a defense institution in a spear-phishing attack, leveraging ChatGPT to create fake military ID cards
US Department of Homeland Security OIG claims CISA mismanaged a key cyber retention incentive program