> TODAY'S SUMMARY (8 articles)
Today's cybersecurity news highlights several significant threats and trends. Notably, a former engineer was sentenced for an insider cyber extortion plot, demanding 20 Bitcoin after compromising a company's infrastructure. Additionally, the rise of typosquatting exploits using rare Cyrillic and Latin characters poses new risks for users of Chromium browsers. Anthropic has halted live internet access for its AI tests following injection flaw exploits, underscoring ongoing vulnerabilities in AI systems. Furthermore, the co-creator of the Empire Market dark web platform received a 40-year prison sentence for facilitating over $430 million in illegal trades. Lastly, the FBI arrested the founder of a ransomware negotiation firm linked to the ShinyHunters group, marking a significant move against cybercriminal operations.
|
// AI-powered summary generated at 12:01
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes d'Apex Bulk.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
IGI Global Scientific Publishing suffered a ransomware attack on August 18, 2025, which may have exposed personal identifiable information. The impacted information may include name, date of birth, home address, phone number, and account number. IGI has not received any notice or indication of any o...
The North Atlantic States Carpenters Benefit Funds experienced a data breach on August 18, 2025, where an unauthorized actor accessed and/or acquired certain files on the systems of the CT office. The breach involved name, Social Security number, and financial account information. No funds were take...
In this post we discuss a vulnerability that was present in Amp Code from Sourcegraph by which an attacker could exploit markdown driven image rendering to exfiltrate sensitive information.
This vulnerability is common in AI applications and agents, and it’s actually similar to one we discussed last...
Le groupe d'assurance allemand Büchner Barella a été victime d'une attaque ciblée et criminelle de pirates informatiques, mais les systèmes de sécurité de l'entreprise ont permis de limiter les dégâts. Les pirates ont réussi à compromettre les systèmes, mais l'entreprise travaille avec des experts p...
La ville de Middletown est victime d'une faille de sécurité informatique qui a perturbé de nombreuses fonctions de la ville. Les services en personne sont suspendus au bâtiment de la ville de Middletown, mais les autres départements continuent de fonctionner normalement. La ville fournira des mises...
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.How much tech stuff do I have sitting there in progress, literally just within arm's reach? I kick off this week's video going through it, and it's kinda nuts. Doing runeos and house buil...
Melwood, Inc. suffered a data breach between August 9 and 17, 2025, where an unknown cyber actor accessed a portion of their computer network and copied files without permission. The breach involved the copying of files containing names and other personal information. A cyberattack was claimed by Si...
In this post we will look at Amp, a coding agent from Sourcegraph. The other day we discussed how invisible instructions impact Google Jules.
Turns out that many client applications are vulnerable to these kinds of attacks when they use models that support invisible instructions, like Claude.
Invisi...
Bragg a subi une faille de sécurité limitée à son environnement informatique interne, sans impact sur les informations personnelles ni sur ses opérations. L'entreprise prend la situation très au sérieux et demande à ses clients et partenaires de patienter pendant qu'elle tente de remédier à la situa...
Data I/O Corporation a subi une attaque de ransomware le 16 août 2025, ce qui a temporairement impacté ses opérations, notamment les communications internes et externes, l'expédition et la production manufacturière. L'entreprise travaille à la restauration des systèmes affectés et a engagé des exper...
Germany, the Netherlands and four of the Five Eyes countries share a common asset inventory for industrial cybersecurity
Nissan a subi une faille de sécurité suite à un accès non autorisé à un serveur de sa filiale Creative Box Inc., entraînant la fuite de données sensibles. Les pirates de Qilin ont revendiqué la responsabilité de cette attaque et menacent de rendre publiques les données volées. Une enquête est actuel...
Gym Management Services, Inc. suffered a data breach, resulting in unauthorized access to sensitive information. The company is offering free credit monitoring and identity protection services to affected individuals. The breach has been remediated, and the company is taking steps to prevent future...
Cisco has issued a software update to address the vulnerability, which can allow an unauthenticated, remote attacker to inject arbitrary shell commands
C.N. Wood Co, Inc. suffered a data breach, offering complimentary credit monitoring services to affected individuals. The breach may have exposed personal information, prompting recommendations for fraud alerts and security freezes. The company is providing identity restoration support and insurance...
A new Checkmarx study reveals that AI-generated code now accounts for over 60% of codebases in some companies, much of which contains known vulnerabilities
The latest Gemini models quite reliably interpret hidden Unicode Tag characters as instructions. This vulnerability, first reported to Google over a year ago, has not been mitigated at the model or API level, hence now affects all applications built on top of Gemini.
This includes Google’s own produ...
A RUSI report warned that money mules are exploiting inadequate security controls in smaller payment service providers to move fraudulent transactions about