> TODAY'S SUMMARY (8 articles)
Today's cybersecurity news highlights several significant threats and trends. Notably, a former engineer was sentenced for an insider cyber extortion plot, demanding 20 Bitcoin after compromising a company's infrastructure. Additionally, the rise of typosquatting exploits using rare Cyrillic and Latin characters poses new risks for users of Chromium browsers. Anthropic has halted live internet access for its AI tests following injection flaw exploits, underscoring ongoing vulnerabilities in AI systems. Furthermore, the co-creator of the Empire Market dark web platform received a 40-year prison sentence for facilitating over $430 million in illegal trades. Lastly, the FBI arrested the founder of a ransomware negotiation firm linked to the ShinyHunters group, marking a significant move against cybercriminal operations.
|
// AI-powered summary generated at 12:01
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Isaac-GR00T. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-23296.
Workday s’est fait piéger par la méthode redoutable des hackers, les cyberattaques par CRM
Dans un communiqué publié le 15 août 2025, le géant des logiciels RH Workday annonce avoir été victime d’une cyberattaque ayant compromis certaines données professionnelles de ses clients. L’offensive s’inscr...
The Amazon Q Developer VS Code Extension (Amazon Q) is a popular coding agent, with over 1 million downloads.
The extension is vulnerable to indirect prompt injection, and in this post we discuss a vulnerability that allowed an adversary (or also the AI for that matter) to run arbitrary commands on...
New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.
A critical flaw in SAP NetWeaver AS Java is being widely exploited, allowing unauthenticated remote code execution
A cyber-attack on Allianz Life, linked to the ShinyHunters group, has exposed the personal information of 1.1 million customers
This post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby ecosystem are needed rather than continued patch-and-hope approaches.
The Canadian Investment Regulatory Organization (CIRO) said it will work to identify the personal information breached and notify those affected
Red Canary observed the novel tactic in a cluster of activity targeting a legacy vulnerability to access cloud-based Linux systems
How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries
Researchers detected that FreeVPN.One, a longstanding Chrome Web Store VPN extension, recently turned into spyware
South Yorkshire Police have been reprimanded by the ICO after deleting 96,000 pieces of evidence from officers’ bodycams
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
Over 280,000 customers of Australian ISP iiNet have been impacted by a data breach
La Salesian Pontifical University a été victime d'une attaque cybernétique grave le 19 août, rendant son site web et ses services numériques temporairement inaccessibles. Les autorités compétentes et les techniciens de l'université travaillent pour comprendre l'ampleur de l'attaque et assurer la séc...
Motility Software Solutions suffered a data security incident where an unauthorized actor deployed malware that encrypted a portion of their systems, potentially exposing customers' personal data.
In July 2025, Allianz Life was the victim of a cyber attack which resulted in millions of records later being leaked online. Allianz attributed the attack to "a social engineering technique" which targeted data on Salesforce and resulted in the exposure of 1.1M unique email addresses, names, genders...
Volume Transportation, Inc. experienced a network disruption on August 19, 2025, which led to unauthorized access to certain files. A cyberattack against Volume Transportation was claimed by Qilin on September 15.
Fieldtex Products, Inc. a signalé une faille de sécurité dans ses systèmes informatiques, ce qui a pu compromettre des informations de santé protégées, notamment des noms de patients, des adresses et des numéros d'identification d'assurance. L'entreprise a pris des mesures pour sécuriser son réseau...
The next three posts will cover high severity vulnerabilities in the Amazon Q Developer VS Code Extension (Amazon Q Developer), which is a very popular coding agent, with over 1 million downloads.
It is vulnerable to prompt injection from untrusted data and its security depends heavily on model beha...