> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights significant threats, including the discovery of preinstalled Android malware named Midnight Mimosa on MediaTek devices, affecting users in 150 countries by creating proxy botnets. Additionally, a malware incident at Nippon Columbia has compromised over 8.7 million records, underscoring the ongoing risks associated with data breaches. The U.S. CISA has updated its Known Exploited Vulnerabilities catalog, adding critical flaws in several widely used software applications, prompting urgent patching efforts. Meanwhile, concerns grow over AI's potential to execute sophisticated attacks on infrastructure, with experts warning that current defenses may be inadequate. The persistent threat of DDoS attacks also raises alarms about their impact on democratic processes. Overall, these developments reflect an evolving threat landscape that demands heightened vigilance and proactive security measures.
|
// AI-powered summary generated at 20:01
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
Oxford County a été victime d'une cyberattaque, l'administration du comté a publié une déclaration à ce sujet. La cyberattaque a eu lieu le 16 septembre 2025. Les détails de l'attaque ne sont pas encore connus.
Concrete CMS 9.4.3 - Stored XSS
Mbed TLS 3.6.4 - Use-After-Free
Le système de bibliothèque du comté de Chester en Pennsylvanie a subi une panne de plusieurs jours en raison d'une attaque de ransomware, affectant les 18 succursales et perturbant les services publics. Les services de téléphone et d'internet ont été rétablis le 25 septembre, mais des problèmes d'e-...
HTTP/2 2.0 - Denial Of Service (DOS)
HTMLDOC 1.9.13 - Stack Buffer Overflow
Form Energy a subi une faille de sécurité qui a exposé des informations personnelles sensibles de ses employés actuels et anciens, y compris des noms, adresses, dates de naissance et numéros de sécurité sociale. L'entreprise a détecté l'attaque le 16 septembre 2025 et a commencé à notifier les perso...
Cette victime n'a pas été revendiquée par Akira, mais un affidé de l'enseigne divulgue des données qu'il lui attribue.
We examine security weaknesses in LLM code assistants. Issues like indirect prompt injection and model misuse are prevalent across platforms.
The post The Risks of Code Assistant LLMs: Harmful Content, Misuse and Deception appeared first on Unit 42.
This is the first installment in a blog series documenting EFF's findings from the Stop Censoring Abortion campaign. You can read additional posts here.Â
We’ve been hearing that social media platforms are censoring abortion-related content, even when no law requires them to do so. Now, we’ve got the...
Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized acc...
HybridPetya ransomware mimics Petya/NotPetya, with an added UEFI bootkit and Secure Boot bypass
SEO poisoning attack has been observed targeting Chinese Windows users via lookalike domains, installing Hiddengh0st and Winos
For the latest discoveries in cyber research for the week of 15th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Panama’s Ministry of Economy and Finance (MEF) was hit by a ransomware attack that resulted in the theft of more than 1.5TB of data, including email...
Genians observed the Kimsuky group impersonate a defense institution in a spear-phishing attack, leveraging ChatGPT to create fake military ID cards
US Department of Homeland Security OIG claims CISA mismanaged a key cyber retention incentive program
Recently, we’ve shared a lot about post-quantum cryptography, the great work we’re doing to make it available to you through our products, and the importance of preparing for a future with quantum computers powerful enough to break classic RSA-based cryptography. You may have heard about “Q-day,” th...
Threat actors are using multiple lures to trick users into installing RMM tools