> TODAY'S SUMMARY (3 articles)
Raheim Hamilton, co-creator of the Empire Market dark web marketplace, has been sentenced to 40 years in prison for facilitating over $430 million in illegal trades, highlighting ongoing law enforcement efforts against cybercrime. Hamilton's guilty plea included the forfeiture of $100 million in Bitcoin and assets. Additionally, the FBI has arrested the founder of a Canadian cybersecurity firm, linked to the ShinyHunters hacking group, signaling a crackdown on organizations involved in ransomware negotiations. These developments underscore the increasing focus on dismantling criminal enterprises in the dark web and addressing ransomware threats.
|
// AI-powered summary generated at 08:00
How to defend organisations against malware or ransomware attacks.
The US Department of Justice has announced the seizure of domains, servers and $1m in proceeds from the BlackSuit ransomware group
Microsoft announced updates for 107 vulnerabilities on Patch Tuesday, including one zero-day
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rati...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rati...
La commune de Hoppegarten est actuellement hors ligne en raison d'une attaque informatique, le Landeskriminalamt enquête sur une tentative de sabotage informatique, et la CDU-Landtagsfraktion réclame un plan d'urgence national pour les communes. La commune a été informée d'une attaque imminente sur...
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVE...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS ratin...
The Institute for Human Resources and Services Inc. suffered a data breach between August 13, 2025, and August 14, 2025, where an unknown actor gained access to certain systems and potentially accessed or took personal information. The information impacted includes name, Social Security number, and...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DIAView. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-53417.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Delta Electronics DIAView. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-53417.
Pyramid Global Hospitality suffered a data breach, prompting the company to offer identity protection services to affected individuals. The breach led to the potential misuse of consumers' personal information. A cyberattack was claimed by Worldleaks on September 23.
This post is about an important, but also scary, prompt injection discovery that leads to full system compromise of the developer’s machine in GitHub Copilot and VS Code.
It is achieved by placing Copilot into YOLO mode by modifying the project’s settings.json file.
As described a few days ago with...
In a new investigation launched at DEFCON 33, Analyst1’s Jon DiMaggio revealed probable Russian government involvement in the Kaseya attack
487 attaques par ransomware ont été recensées en juillet, en hausse de 41% sur un an
Les cybercriminels ne prennent pas de vacances. Preuve en est avec le dernier rapport de Check Point Research, l’équipe de recherche sur les menaces de la société israélienne. L’étude publiée le 11 août met en avan...
Posted by Dave Kleidermacher, VP Engineering, Android Security & Privacy
Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that protected KVM (pKVM), the hypervisor that powers the Android Virtualizatio...
A new technique has bypassed GPT-5’s safety systems via narrative-driven steering to elicit harmful output
Over 29,000 Microsoft Exchange servers remain unpatched against a vulnerability that could allow attackers to seize control of entire domains in hybrid cloud environments
Does your business truly understand its dependencies, and how to mitigate the risks posed by an attack on them?
The sophisticated campaign aims to steal credentials of sponsor license holders to facilitate immigration fraud, extortion and other monetization schemes