> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical developments. Canadian cybersecurity executive Edward Dubrovsky was arrested for alleged ties to extortion linked to the ShinyHunters hacking group. Meanwhile, the Silent Ransom Group reportedly extorted $207 million from law firms through social engineering tactics without encrypting files. Cyberattacks on South Korean banks were traced to a Chinese hacker utilizing ARTEX AI tools. Additionally, an insider extortion case involved a former engineer demanding ransom from an industrial firm after compromising server access. As AI continues to evolve, initiatives are leveraging it to counter cybercriminals, indicating a shift in anti-cybercrime strategies. Lastly, the sentencing of the Empire Market co-creator underscores ongoing efforts to dismantle dark web operations.
|
// AI-powered summary generated at 16:00
Cline is quite a popular AI coding agent, according to the product website it has 2+ million downloads and over 47k stars on GitHub.
Unfortunately, Cline is vulnerable to data exfiltration through the rendering of markdown images from untrusted domains in the chat box.
This allows an adversary to ex...
A series of cyber-attacks against government organizations in Central Asia and Asia- Pacific has been linked to the ShadowSilk threat cluster
EIP-7730 enables hardware wallets to decode transactions into human-readable formats, eliminating blind signing vulnerabilities with minimal implementation effort for dApp developers.
Citrix customers are urged to patch their vulnerable NetScaler appliances, but “patching alone won’t cut it,” experts said
EU security agency ENISA is being handed €36m to operate the EU Cybersecurity Reserve
In a brand-new collaboration between ethical hacking and AppSec expert John Hammond and world-renowned security researcher James Kettle, the pair explore how tens of millions of websites are compromis
Cyberbullying is a fact of life in our digital-centric society, but there are ways to push back
Google is warning of a new credential theft campaign targeting Salesforce customers via Salesloft Drift
Abnormal AI said the campaign, which lures victims into downloading legitimate RMM software, marks a major evolution in phishing tactics
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.It seems like every manufacturer of anything electrical that goes in the house wants to be part of the IoT story these days. Further, they all want their own app, which means you have to...
This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-9276.
In June 2025, 107k unique customer email addresses were allegedly obtained from TheSqua.re, the "easiest way to find your next serviced apartment". The data also included names, phone numbers and cities which were subsequently posted to a popular hacking forum. TheSqua.re did not respond to repeated...
Le Centre de services scolaire des Appalaches a été victime d'une attaque par rançongiciel, les pirates revendiquant avoir obtenu 180 Go de données de l'organisation, dont des informations personnelles sur les élèves et les employés. L'organisation a repris le contrôle de ses serveurs et travaille a...
Saint Mary’s Home of Erie experienced a data breach where files and folders stored on certain databases may have been accessible to others outside of their organization between August 26, 2025, and August 28, 2025. A cyberattack was claimed by Worldleaks on October 3.
The discovery of PromptLock shows how malicious use of AI models could supercharge ransomware and other threats
Kovack Financial, LLC experienced a data breach between August 8, 2025, and August 27, 2025, where an unknown actor gained access to files within their network. The breach was discovered on July 16, 2026. The incident may have impacted some of the company's information.
ESET Endpoint Antivirus and ESET Endpoint Security for Windows version 12.0.2062.0 have been released and are available for download.
A new version of the Hook Android banking Trojan features 107 remote commands, including ransomware overlays
A global phishing campaign has been identified using personalized emails and fake websites to deliver malware via UpCrypter
Written by: Austin Larsen, Matt Lin, Tyler McLellan, Omar ElAhdan
Update (August 28)
Based on new information identified by GTIG, the scope of this compromise is not exclusive to the Salesforce integration with Salesloft Drift and impacts other integrations. We now advise all Salesloft Drift custom...