> TODAY'S SUMMARY (8 articles)
Today's cybersecurity news highlights several significant threats and trends. Notably, a former engineer was sentenced for an insider cyber extortion plot, demanding 20 Bitcoin after compromising a company's infrastructure. Additionally, the rise of typosquatting exploits using rare Cyrillic and Latin characters poses new risks for users of Chromium browsers. Anthropic has halted live internet access for its AI tests following injection flaw exploits, underscoring ongoing vulnerabilities in AI systems. Furthermore, the co-creator of the Empire Market dark web platform received a 40-year prison sentence for facilitating over $430 million in illegal trades. Lastly, the FBI arrested the founder of a ransomware negotiation firm linked to the ShinyHunters group, marking a significant move against cybercriminal operations.
|
// AI-powered summary generated at 12:01
In July 2025, Allianz Life was the victim of a cyber attack which resulted in millions of records later being leaked online. Allianz attributed the attack to "a social engineering technique" which targeted data on Salesforce and resulted in the exposure of 1.1M unique email addresses, names, genders...
The next three posts will cover high severity vulnerabilities in the Amazon Q Developer VS Code Extension (Amazon Q Developer), which is a very popular coding agent, with over 1 million downloads.
It is vulnerable to prompt injection from untrusted data and its security depends heavily on model beha...
Why sharing lessons learned from cyber security incidents and ‘near misses’ will help everyone to improve
An incident involving the npm package eslint-config-prettier has been uncovered spreading Scavenger RAT
A multi-stage attack delivered via USB devices has been observed installing cryptomining malware using DLL hijacking and PowerShell
We've just deployed some mega updates to our infrastructure at Report URI that will give us much more resilience in the future, allow us to apply updates to our servers even faster, and will probably go totally unnoticed from the outside!Our previous Redis setupI've
Cisco Talos observed the newly identified group compromise a Taiwanese web hosting provider to conduct a range of malicious activities
The Warlock ransomware gang has taken credit for the cyber-attack after the UK telco giant publicly confirmed an incident on August 14
Can you tell the difference between legitimate marketing and deepfake scam ads? It’s not always as easy as you may think.
Al-Tahery Al-Mashriky has been sentenced to 20 months behind bars for hacktism-related offenses
Workday has revealed a breach of its third-party CRM systems in what could be the latest ShinyHunters attack
Updated first FAQ to state that CVE-2020-0674 has now been issued to address this vulnerability. This is an informational change only.
Tenda AC20 16.03.08.12 - Command Injection
Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
Le Département de l'Aude a été victime d'une cyberattaque, les données des usagers, partenaires et fournisseurs des services sociaux départementaux ont été volées. Les usagers sont invités à changer leur mot de passe et à rester vigilant face à toute requête suspecte. Une plainte a été déposée et de...
Soosyze CMS 2.0 - Brute Force Login
Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes d'Apex Bulk.
PHPMyAdmin 3.0 - Bruteforce Login Bypass
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)