[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (2 articles)

|

// AI-powered summary generated at 04:00

> Pennsylvania Office of the Attorney General
Le Pennsylvania Office of the Attorney General a signalé une faille de sécurité des données en août 2025, qui a pu donner accès non autorisé à des informations personnelles. Les données concernées pourraient inclure des noms, des numéros de sécurité sociale et des informations médicales. L'office a...
> Plainview Volunteer Fire Department
Plainview Volunteer Fire Department suffered a data security incident on or about August 9, 2025. The investigation found suspicious activity within their network environment. A cyberattack against the Plainview Volunteer Fire Department was claimed by RansomHouse on October 1st.
> Black Hat USA 2025: Is a high cyber insurance premium about your risk, or your insurer’s?
A sky-high premium may not always reflect your company’s security posture
> #BHUSA: CISA Execs ‘Hopeful’ for Extension of Cybersecurity Information Sharing Act
Leaders of the US Cybersecurity and Infrastructure Agency (CISA) pushed back on layoff concerns and highlighted new initiatives
> Australian Regulator Sues Optus Over 2022 Data Breach
The Information Commissioner has applied for a civil penalty against Optus following the 2022 data breach that exposed the personal details of 9.5 million Australians
> From Chrome renderer code exec to kernel with MSG_OOB
Posted by Jann Horn, Google Project ZeroIntroduction In early June, I was reviewing a new Linux kernel feature when I learned about the MSG_OOB feature supported by stream-oriented UNIX domain sockets. I reviewed the implementation of MSG_OOB, and discovered a security bug (CVE-2025-38236) affect...
> US Federal Judiciary Tightens Security Following Escalated Cyber-Attacks
The judiciary announced stronger protections for its case management system following reports of a major breach of sensitive court documents in multiple states
> Android adware: What is it, and how do I get it off my device?
Is your phone suddenly flooded with aggressive ads, slowing down performance or leading to unusual app behavior? Here’s what to do.
> Bouygues Telecom Data Breach Exposes 6.4 Million Customer Records
Bouygues Telecom revealed the attackers stole personal data of 6.4 million customers, including contact details, contractual data and international bank account numbers
> AI Kill Chain in Action: Devin AI Exposes Ports to the Internet with Prompt Injection
Today let’s explore Devin’s system prompt a bit more. Specifically, an interesing tool that I discovered when reading through it. Hidden in Devin’s capabilities is a tool that can open any local port to the public Internet. That means, with the right indirect prompt injection nudge, Devin can be tri...
> From Chrome renderer code exec to kernel with MSG_OOB
Introduction In early June, I was reviewing a new Linux kernel feature when I learned about the MSG_OOB feature supported by stream-oriented UNIX domain sockets. I reviewed the implementation of MSG_OOB, and discovered a security bug (CVE-2025-38236) affecting Linux >=6.9. I reported the bug to L...
> Unigame - 843,696 breached accounts
In December 2019, the now defunct gaming website Unigame (maker of Hunter Online) suffered a data breach that was later redistributed as part of a larger corpus of data. The data included 844k email addresses and salted MD5 password hashes.
> Buttercup is now open-source!
Now that DARPA’s AI Cyber Challenge (AIxCC) has officially ended, we can finally make Buttercup, our CRS (Cyber Reasoning System), open source!
> Spartanburg County
Le comté de Spartanburg a été victime d'une cyberattaque, ce qui a entraîné la perturbation de certains services en ligne. Les responsables du comté ont déclaré que l'attaque avait été contenue et que les services essentiels continuaient de fonctionner normalement. Le comté travaille actuellement à...
> Inotiv, Inc.
Inotiv, Inc. a subi une faille de sécurité informatique le 8 août 2025, une enquête est en cours pour déterminer l'ampleur de l'incident. L'entreprise a pris des mesures pour contenir et remédier à la situation, mais les opérations commerciales ont été perturbées. L'incident a eu un impact temporair...
> #BHUSA: 1000 DoD Contractors Now Covered by NSA’s Free Cyber Services Program
The NSA’s CAPT program, launched in 2024 with Horizon3.ai, now benefits 1000 of the 300,000 US Defense Industrial Base companies
> FuturHealth, Inc.
FuturHealth, Inc. suffered a data breach where an unauthorized actor viewed and copied certain files stored within their network between August 8, 2025, and August 14, 2025. The breach involved the names and other types of personal information of some individuals. FuturHealth is offering complimenta...
> Markowitz Ringel Trusty & Hartog
An unauthorized actor accessed or acquired certain data on August 8, 2025, which included name and Social Security number. The incident was discovered on August 8, 2025, and the organization is notifying affected individuals. A cyberattack was claimed by Akira on September 22, 2025.
> Chromium: CVE-2025-8582 Insufficient validation of untrusted input in DOM
Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
> Chromium: CVE-2025-8581 Inappropriate implementation in Extensions
Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.