[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (8 articles)

|

// AI-powered summary generated at 12:01

> ZDI-25-847: NVIDIA Isaac-GR00T TorchSerializer Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Isaac-GR00T. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-23296.
> Numerama – Cyberguerre
Workday s’est fait piéger par la méthode redoutable des hackers, les cyberattaques par CRM Dans un communiqué publié le 15 août 2025, le géant des logiciels RH Workday annonce avoir été victime d’une cyberattaque ayant compromis certaines données professionnelles de ses clients. L’offensive s’inscr...
> Amazon Q Developer: Remote Code Execution with Prompt Injection
The Amazon Q Developer VS Code Extension (Amazon Q) is a popular coding agent, with over 1 million downloads. The extension is vulnerable to indirect prompt injection, and in this post we discuss a vulnerability that allowed an adversary (or also the AI for that matter) to run arbitrary commands on...
> Slackware 15.0: mozilla-firefox Important Security Patch 2025-231-01
New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.
> Public Exploit Released for Critical SAP NetWeaver Flaw
A critical flaw in SAP NetWeaver AS Java is being widely exploited, allowing unauthenticated remote code execution
> Allianz Life Data Breach Exposes Personal Data of 1.1 Million Customers
A cyber-attack on Allianz Life, linked to the ShinyHunters group, has exposed the personal information of 1.1 million customers
> Marshal madness: A brief history of Ruby deserialization exploits
This post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
> Canadian Financial Regulator Hacked, Exposing Personal Data from Member Organizations
The Canadian Investment Regulatory Organization (CIRO) said it will work to identify the personal information breached and notify those affected
> Attacker “Patches” Vulnerability Post Exploitation to Lock Out Competition
Red Canary observed the novel tactic in a cluster of activity targeting a legacy vulnerability to access cloud-based Linux systems
> The need for speed: Why organizations are turning to rapid, trustworthy MDR
How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries
> Legitimate Chrome VPN Extension Turns to Browser Spyware
Researchers detected that FreeVPN.One, a longstanding Chrome Web Store VPN extension, recently turned into spyware
> South Yorkshire Police Deletes 96,000 Pieces of Digital Evidence
South Yorkshire Police have been reprimanded by the ICO after deleting 96,000 pieces of evidence from officers’ bodycams
> Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
> Australian ISP iiNet Suffers Breach of 280,000+ Records
Over 280,000 customers of Australian ISP iiNet have been impacted by a data breach
> Salesian Pontifical University (UPS)
La Salesian Pontifical University a été victime d'une attaque cybernétique grave le 19 août, rendant son site web et ses services numériques temporairement inaccessibles. Les autorités compétentes et les techniciens de l'université travaillent pour comprendre l'ampleur de l'attaque et assurer la séc...
> Motility Software Solutions
Motility Software Solutions suffered a data security incident where an unauthorized actor deployed malware that encrypted a portion of their systems, potentially exposing customers' personal data.
> Allianz Life - 1,115,061 breached accounts
In July 2025, Allianz Life was the victim of a cyber attack which resulted in millions of records later being leaked online. Allianz attributed the attack to "a social engineering technique" which targeted data on Salesforce and resulted in the exposure of 1.1M unique email addresses, names, genders...
> Volume Transportation, Inc.
Volume Transportation, Inc. experienced a network disruption on August 19, 2025, which led to unauthorized access to certain files. A cyberattack against Volume Transportation was claimed by Qilin on September 15.
> Fieldtex Products, Inc.
Fieldtex Products, Inc. a signalé une faille de sécurité dans ses systèmes informatiques, ce qui a pu compromettre des informations de santé protégées, notamment des noms de patients, des adresses et des numéros d'identification d'assurance. L'entreprise a pris des mesures pour sécuriser son réseau...
> Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
The next three posts will cover high severity vulnerabilities in the Amazon Q Developer VS Code Extension (Amazon Q Developer), which is a very popular coding agent, with over 1 million downloads. It is vulnerable to prompt injection from untrusted data and its security depends heavily on model beha...