[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (8 articles)

|

// AI-powered summary generated at 12:01

> Sneaking Invisible Instructions by Developers in Windsurf
Imagine a malicious instruction hidden in plain sight, invisible to you but not to the AI. This is a vulnerability discovered in Windsurf Cascade, it follows invisible instructions. This means there can be instructions in a file or result of a tool call that the developer cannot see, but the LLM doe...
> Extant Aerospace
Extant Aerospace suffered a data breach due to ransomware activity affecting its network environment, potentially exposing personal information of current and former employees and other individuals. The breach occurred on or around August 23, 2025, and was discovered on April 13, 2026. The affected...
> Windsurf: Memory-Persistent Data Exfiltration (SpAIware Exploit)
In this second post about Windsurf Cascade we are exploring the SpAIware attack, which allows memory persistent data exfiltration. SpAIware is an attack we first successfully demonstrated with ChatGPT last year and OpenAI mitigated. While inspecting the system prompt of Windsurf Cascade I noticed th...
> Interpol-Led African Cybercrime Crackdown Leads to 1209 Arrests
Operation Serengeti 2.0 operators helped recover $97.4m stolen by cybercriminals
> Attackers Abuse Virtual Private Servers to Compromise SaaS Accounts
Darktrace observed a coordinated campaign on customer SaaS accounts, all of which involved logins from IP addresses linked to VPS providers
> Appel à manifestation d‘intérêt [clos]
Appel à manifestation d‘intérêt [clos] anssiadm ven 22/08/2025 - 07:13 L'ANSSI ouvre un appel à manifestation d‘intérêt (AMI) pour le renforcement de l’accompagnement local aux enjeux de cybersécurité, du 22 août au 15 septembre 2025....
> Apple Releases Patch for Likely Exploited Zero-Day Vulnerability
All Apple users are encouraged to update their iPhones, iPads and macOS devices
> Microsoft to Make All Products Quantum Safe by 2033
Microsoft has set out a roadmap to complete transition to PQC in all its products and services by 2033, with roll out beginning by 2029
> Cajeme
La ville de Cajeme a suspendu ses services numériques après une attaque informatique contre son système municipal. Les services en ligne ont été interrompus pour protéger les données sensibles. L'attaque a eu lieu le 22 août 2025 et les autorités travaillent pour rétablir les services.
> Blackpool Credit Union
La Blackpool Credit Union a été victime d'une attaque informatique, les informations personnelles de ses membres ont été compromises et partagées sur le dark web. Les experts techniques ont été appelés pour mener une enquête forensique et les systèmes ont été rétablis pour éviter toute perte de serv...
> Chromium: CVE-2025-9132 Out of bounds write in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
> Georgetown Brewing Company
A data security event resulted in unauthorized access to personal identifying information, including names and driver's license numbers. The incident occurred on August 22, 2025, and was discovered on the same day. There is no evidence of misuse of the information.
> KCI Telecommunications
KCI Telecommunications suffered a data breach on August 22, 2025, where an unknown actor accessed certain files containing names and Social Security numbers. The breach was discovered on August 22, 2025, and KCI took steps to secure its systems and launched an investigation. A cyberattack was claime...
> Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw
Russian state-backed hackers are exploiting a seven-year-old Cisco Smart Install vulnerability (CVE-2018-0171) in end-of-life devices, prompting warnings from the FBI and Cisco Talos
> Colt Admits Customer Data Likely Stolen in Cyber-Attack
Colt customers can request a list of filenames posted on the dark web via a dedicated call center
> Weaponizing image scaling against production AI systems
In this blog post, we’ll detail how attackers can exploit image scaling on Gemini CLI, Vertex AI Studio, Gemini’s web and API interfaces, Google Assistant, Genspark, and other production AI systems. We’ll also explain how to mitigate and defend against these attacks, and we’ll introduce Anamorpher,...
> Oregon Man Charged in Rapper Bot DDoS-for-Hire Case
A 22-year-old Oregon man has been charged with administering the Rapper Bot DDoS-for-hire Botnet
> Cybercriminal Linked to Notorious Scattered Spider Gang Gets 10-Year Sentence
Noah Urban, linked with the Scattered Spider cybercriminal gang, will also pay $13m in restitution to victims
> Hijacking Windsurf: How Prompt Injection Leaks Developer Secrets
This is the first post in a series exploring security vulnerabilities in Windsurf. If you are unfamiliar with Windsurf, it is a fork of VS Code and the coding agent is called Windsurf Cascade. The attack vectors we will explore today allow an adversary during an indirect prompt injection to exfiltra...
> Orange Data Breach Raises SIM-Swapping Attack Fears
Orange Belgium revealed that a threat actor has compromised 850,000 customer accounts, with SIM card numbers among the data accessed