[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> Ghanaian Nationals Extradited for Roles in $100M Romance and Wire Fraud Ring
Four senior members of a Ghana-based criminal network have been indicted for stealing over $100 million through romance scams and BEC frau
> Claude Code: Data Exfiltration with DNS (CVE-2025-55284)
Today we cover Claude Code and a high severity vulnerability that Anthropic fixed in early June. The vulnerability allowed an attacker to hijack Claude Code via indirect prompt injection and leak sensitive information from the developer’s machine, e.g. API keys, to external servers by issuing DNS re...
> Embargo Ransomware Gang Amasses $34.2m in Attack Proceeds
TRM Labs observed crypto payments worth $34.2m moved from victims addresses to a range of destinations likely associated with the group
> Automation improvements after a Tesla Powerwall outage!
So, a weird thing happened over the last couple of days, and my Tesla Powerwalls weren't working properly, or, at all, actually... What's even more strange is that Tesla has been completely silent about this and hasn't made a single announcement about the issue
> Eight Countries Face EU Action Over NIS2 Deadline Failings
Eight European countries have yet to transpose NIS2 into law, exposing them to regulatory action
> Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability
ESET Research discovered a zero-day vulnerability in WinRAR being exploited in the wild in the guise of job application documents; the weaponized archives exploited a path traversal flaw to compromise their targets
> UK Red Teamers “Deeply Skeptical” of AI
Commercial red team experts believe AI’s current impact on cyber is overstated
> ZDI-25-825: Apple macOS AudioToolboxCore Audio Conversion Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the AudioToolboxCore framework is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS ra...
> [webapps] JetBrains TeamCity 2023.11.4 - Authentication Bypass
JetBrains TeamCity 2023.11.4 - Authentication Bypass
> [webapps] ServiceNow Multiple Versions - Input Validation & Template Injection
ServiceNow Multiple Versions - Input Validation & Template Injection
> Yes24
Yes24, le plus grand détaillant de billets et de livres en ligne de Corée du Sud, a subi une attaque de ransomware qui a mis son site Web et son application mobile hors ligne pendant plusieurs heures. Il s'agit de la deuxième attaque de ce type en moins de deux mois pour l'entreprise. Les services o...
> [webapps] Ghost CMS 5.59.1 - Arbitrary File Read
Ghost CMS 5.59.1 - Arbitrary File Read
> [webapps] Ghost CMS 5.42.1 - Path Traversal
Ghost CMS 5.42.1 - Path Traversal
> Office of the Attorney General of Pennsylvania
Le bureau de l'avocat général de Pennsylvanie a été victime d'une cyberattaque qui a mis hors ligne ses systèmes téléphoniques et de messagerie électronique. Les enquêteurs travaillent pour déterminer la cause de l'incident et restaurer les services. Les procureurs continuent de travailler sur les a...
> [remote] Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
> [webapps] VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
> Linedata
Une cyberattaque a visé le fournisseur français de services de gestion de fonds Linedata, ce qui a entraîné la suspension de fonds utilisant Tutman Fund Solutions en tant que directeur corporatif autorisé. L'attaque a eu un impact sur environ 80 fonds. Linedata est une entreprise de technologie, de...
> [remote] Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
> [remote] Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
> Welcome Financial Group
Un groupe russe a revendiqué une attaque par ransomware contre Welrix I&F, une filiale de Welcome Financial Group, et a affirmé avoir acquis la base de données des clients. L'entreprise a alerté les autorités de cybersécurité et les autorités financières. L'attaque est la dernière d'une série de cyb...