> TODAY'S SUMMARY (2 articles)
Today's cyber news highlights significant legal actions against individuals involved in cybercrime. Raheim Hamilton, co-creator of the Empire Market dark web platform, received a 40-year prison sentence for drug conspiracy, alongside a forfeiture of over $100 million in Bitcoin. Additionally, the FBI has arrested the co-founder of a Canadian cybersecurity firm linked to the ShinyHunters hacking group, which has been notorious for data breaches and ransomware activities. These events underscore ongoing efforts by law enforcement to combat dark web marketplaces and ransomware operations.
|
// AI-powered summary generated at 04:00
This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVS...
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.5.
Prompt injection pervades discussions about security for LLMs and AI agents. But there is little public information on how to write powerful, discreet, and reliable prompt injection exploits. In this post, we will design and implement a prompt injection exploit targeting GitHub’s Copilot Agent, with...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.5.
This vulnerability allows remote attackers to bypass the SmartScreen security feature on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating...
Le Centre hospitalier du Gers a été victime d'une cyberattaque, possiblement liée à un ransomware, ce qui a entraîné un fonctionnement en mode dégradé de certains logiciels métiers. Une enquête est en cours et aucune donnée ne semble avoir été compromise à ce stade. Les admissions et la prise en cha...
This vulnerability allows remote attackers to host arbitrary documents on a trusted domain used by Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.3.
This vulnerability allows remote attackers to bypass the SmartScreen security feature on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating...
La société pétrolière pakistanaise Pakistan Petroleum Limited (PPL) a été victime d'une attaque cybernétique majeure, les hackers ayant chiffré les serveurs de l'entreprise et demandant une rançon. Les opérations financières de l'entreprise sont actuellement suspendues. Les autorités compétentes ont...
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-8610.
ESET PROTECT On-Prem 12.1, 12.0 and 11.1 servicing update has been released.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-8611.
This vulnerability allows local attackers to escalate privileges on affected installations of AOMEI Backupper Workstation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. User interaction on the part of an administ...
SecAlliance highlighted the evolution in smishing campaigns orchestrated by Chinese syndicates, which exploit digital wallet tokenization
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vacron Camera devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-8613.
Experts, including Allan Friedman, CISA's leading voice on SBOMs until July 2025, emphasized that AI BOMs should be standardized before being implemented
Critical vulnerabilities in NVIDIA's Triton Inference Server, discovered by researchers, could allow unauthenticated attackers to gain full server control through remote code execution
Sandbox-escape-style attacks can happen when an AI is able to modify its own configuration settings, such as by writing to configuration files.
That was the case with Amp, an agentic coding tool built by Sourcegraph.
The AI coding agent could update its own configuration and:
Allowlist bash commands...
IANS found that stagnant budget growth rates have significantly impacted CISOs ability to increase their teams’ headcount