[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 16:00

> Inovie Labosud
Le groupe de biologie médicale Inovie Labosud a été victime d’une cyberattaque début août, entraînant l’exfiltration de données personnelles et médicales de plusieurs millions de patients. Les données concernées sont de nature administrative et médicale, mais aucun mot de passe ou coordonnée bancair...
> BARTEK
BARTEK experienced a cyber security incident where a third party compromised some of their data, potentially affecting personal information including names, social security numbers, and earning statements. A cyberattack against Bartek was claimed by INC Ransom on September 2.
> Slackware 15.0: udisks2 Critical Local Escalation Fix SSA:2025-242-01
New udisks2 packages are available for Slackware 15.0 and -current to fix a security issue.
> University of Hawaiʻi Cancer Center
Des numéros de sécurité sociale et d'autres informations personnelles de participants à une étude du Centre du cancer de l'Université de Hawaï ont été exposés à des hackers informatiques en août, mais quatre mois plus tard, l'UH n'avait pas encore informé les personnes touchées que leurs données ava...
> AgentHopper: An AI Virus
As part of the Month of AI Bugs, serious vulnerabilities that allow remote code execution via indirect prompt injection were discovered. There was a period of a few weeks where multiple arbitrary code execution vulnerabilities existed in popular agents, like GitHub Copilot, Amazon Q, AWS Kiro,… Duri...
> North Korean Hackers Weaponize Seoul Intelligence Files to Target South Koreans
Pyongyang-backed hacking group APT37 leveraged an internal South Korean intelligence briefing in a spear phishing campaign
> Npm Package Hijacked to Steal Data and Crypto via AI-Powered Malware
A software supply chain attack targeting Nx marks the first known case where attackers have leveraged developer AI assistants, according to StepSecurity
> Social Media: how to use it safely
Use privacy settings across social media platforms to manage your digital footprint.
> State-Sponsored Hackers Behind Majority of Vulnerability Exploits
Recorded Future highlighted the vast capabilities of state actors to rapidly weaponize newly disclosed vulnerabilities for geopolitical purposes
> TransUnion Data Breach Impacts 4.5 Million US Customers
The credit rating giant revealed that the breach, which occurred on July 28, was caused by unauthorized access to a third-party application
> Ordre des journalistes de Rome et du Lazio
L'Ordine dei Giornalisti di Roma e del Lazio a été victime d'une attaque informatique qui pourrait avoir compromis les données personnelles de milliers de professionnels, un collettif de pirates informatiques de l'Est de l'Europe a revendiqué l'attaque et a exigé un ransom, mais l'Ordine refuse de p...
> Ville de Poitiers et Grand-Poitiers
La ville de Poitiers et Grand-Poitiers ont été victimes d'une importante cyberattaque depuis le 29 août, touchant leurs services informatiques et rendant les services en ligne inaccessibles. La situation est désormais stabilisée, mais le retour à la normale prendra du temps. Les services concernés t...
> Windsurf MCP Integration: Missing Security Controls Put Users at Risk
Part of my default test cases for coding agents is to check how MCP integration looks like, especially if the agent can be configured to allow setting fine-grained controls for tools. Sometimes there are basic security controls missing. Especially when running an agent on your local computer. Stakes...
> Barnhart
Barnhart Group, Inc. experienced a network disruption that led to unauthorized access to certain information stored on their network between August 27, 2025, and August 29, 2025. A cyberattack was claimed by Akira on November 14.
> Chromium: CVE-2025-9478 Use after free in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
> Fake IT Support Attacks Hit Microsoft Teams
Fake IT support lures are being used to trick employees into installing remote‑access tools via Microsoft Teams
> Netherlands Confirms China's Salt Typhoon Targeted Small Dutch Telcos
Salt Typhoon’s primary Dutch targets were small internet service providers and hosting providers
> Chasing the Silver Fox: Cat & Mouse in Kernel Shadows
Highlights: Introduction While Microsoft Windows has steadily strengthened its security model—through features like Protected Processes (PP/PPL) and enhanced driver verification—threat actors have adapted by shifting their tactics to exploit lower-level weaknesses that bypass these protections witho...
> Malicious VS Code Extensions Exploit Name Reuse Loophole
Visual Studio Code extensions have been identified exploiting a loophole that allows reuse of names from removed packages
> The year so far: How Burp Suite DAST is leveling up enterprise security in 2025
Enterprise security teams are under more pressure than ever to secure sprawling application estates, without slowing down delivery. That's why, over the first half of 2025, we've delivered some of our