> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical developments. Canadian cybersecurity executive Edward Dubrovsky was arrested for alleged ties to extortion linked to the ShinyHunters hacking group. Meanwhile, the Silent Ransom Group reportedly extorted $207 million from law firms through social engineering tactics without encrypting files. Cyberattacks on South Korean banks were traced to a Chinese hacker utilizing ARTEX AI tools. Additionally, an insider extortion case involved a former engineer demanding ransom from an industrial firm after compromising server access. As AI continues to evolve, initiatives are leveraging it to counter cybercriminals, indicating a shift in anti-cybercrime strategies. Lastly, the sentencing of the Empire Market co-creator underscores ongoing efforts to dismantle dark web operations.
|
// AI-powered summary generated at 16:00
On the day AWS Kiro was released, I couldn’t resist putting it through some of my Month of AI Bugs security tests for coding agents.
AWS Kiro was vulnerable to arbitrary command execution via indirect prompt injection. This means that a remote attacker, who controls data that Kiro processes, could h...
Key findings: Introduction Check Point Research (CPR) has been closely monitoring the activity of a highly persistent and sophisticated threat actor who leverages social engineering tactics to gain the trust of targeted U.S.-based organizations. While analyzing the phishing lures used by the actors,...
All previously scheduled mobility trips across Maryland for this week will be honored, said the state’s transportation administration
A new CIISec poll finds the majority of industry professionals would prefer more rigorous cybersecurity laws
Corrected Download and Article links in the Security Updates table. This is an informational change only.
Data I/O has revealed operational disruption following a ransomware breach that forced it to take some systems offline
Corrected Download and Article links in the Security Updates table. This is an informational change only.
Corrected Download and Article links in the Security Updates table. This is an informational change only.
In a previous blog post, we explored the technical side of passkeys (also known as discoverable credentials or resident keys), what they are, how they work, and why they’re a strong alternative to passwords. Today, we’ll show how passkeys are used in the real world - by everyday users and security p...
Les derniers articles scientifiques co-écrits par des agents issus des labos de l’ANSSI
anssiadm
mar 26/08/2025 - 07:00
Découvrez les parutions scientifiques les plus récentes auxquelles ont pris part différents agents de l’ANSSI issus des laboratoires de la division...
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of TeamViewer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1....
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of QNAP QHora-322 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.1. The...
Le 26 août 2025, Citrix a publié un bulletin de sécurité (cf. section Documentation) concernant, entre autres, la vulnérabilité CVE-2025-7775. Celle-ci permet une exécution de code arbitraire à distance et affecte toutes les versions de Citrix NetScaler ADC et NetScaler Gateway, dans certaines...
GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
A critical vulnerability in older versions of the Claude Code for Visual Studio Code (VS Code) and other IDE extensions allowed malicious websites to connect to unauthenticated local WebSocket servers, potentially enabling remote command execution
StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
Lotte Card a signalé une cyberattaque après avoir détecté des signes de violation dans ses serveurs internes à la fin du mois dernier. L'entreprise a découvert du code malveillant sur l'un de ses serveurs et a ensuite effectué un examen approfondi de ses systèmes. Aucune fuite de données sensibles d...
Lingdang CRM 8.6.4.7 - SQL Injection