> TODAY'S SUMMARY (8 articles)
Today's cybersecurity news highlights several significant threats and trends. Notably, a former engineer was sentenced for an insider cyber extortion plot, demanding 20 Bitcoin after compromising a company's infrastructure. Additionally, the rise of typosquatting exploits using rare Cyrillic and Latin characters poses new risks for users of Chromium browsers. Anthropic has halted live internet access for its AI tests following injection flaw exploits, underscoring ongoing vulnerabilities in AI systems. Furthermore, the co-creator of the Empire Market dark web platform received a 40-year prison sentence for facilitating over $430 million in illegal trades. Lastly, the FBI arrested the founder of a ransomware negotiation firm linked to the ShinyHunters group, marking a significant move against cybercriminal operations.
|
// AI-powered summary generated at 12:01
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
La compagnie des guides de Chamonix a été victime d'une cyberattaque le 15 août, entraînant la consultation et le potentiel vol de données confidentielles. Les défenses en place ont permis de contenir une partie de l'attaque, mais la direction appelle à la vigilance face à de possibles e-mails suspe...
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
An unauthorized actor accessed Moore & Van Allen PLLC's systems for approximately twenty minutes on August 15, 2025, and acquired copies of certain files containing the name and Social Security number of four Maine residents. The attack was claimed by Silentransomgroup on September 3.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes de Bio3g.
A flaw in KernelSU 0.5.7 allows attackers to impersonate its manager app and gain root access to Android devices
An ongoing malware campaign has been observed using malvertising to deliver PS1Bot, a PowerShell-based framework
In the previous post, we explored two data exfiltration vectors that Jules is vulnerable to and that can be exploited via prompt injection. This post takes it further by demonstrating how Jules can be convinced to download malware and join a remote command & control server.
This research was per...
The Bureau’s Internet Crime Complaint Center has provided a list of indicators for potential cryptocurrency scam victims to avoid a double whammy
Abnormal AI said gaining access to such accounts provides opportunities for sophisticated fraud schemes that impersonate officials
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 3.3. Th...
Fortinet reveals details of a new critical-rated vulnerability in FortiSIEM circulating in the wild
The UK government has announced 10 new live facial recognition police vans to be deployed around the country
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The follow...
This vulnerability allows local attackers to read arbitrary files on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The follo...
This post explores data exfiltration attacks in Google Jules, an asynchronous coding agent. This is the first of three posts that will highlight my research on Google Jules in May 2025. All information provided was also shared with Google at that time.
This first post will focus on data exfiltration...
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The follow...