[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (2 articles)

|

// AI-powered summary generated at 04:00

> ZDI-25-771: Trend Micro Apex One Console Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex One. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-54948.
> Incidents de sécurité dans les pare-feux SonicWall (05 août 2025)
[Mise à jour du 7 août 2025] Le 6 août 2025, SonicWall a remplacé une partie de son communiqué initial pour indiquer que les incidents de sécurité évoqués étaient vraisemblablement corrélés à la vulnérabilité CVE-2024-40766. Celle-ci a fait l'objet d'un bulletin de sécurité, SNWLID-2024-0015 (cf....
> PROGI
La plateforme PROGI, utilisée par les assureurs pour envoyer des devis de travail aux ateliers de carrosserie, a été victime d'une cyberattaque au début de la semaine. Les sites PROGI et PROGIPièces sont paralysés depuis lundi. Les compagnies d'assurances Beneva et Desjardins Assurances ont confirmé...
> Greenville, Texas
La ville de Greenville a subi une attaque de ransomware le 5 août, affectant l'accès aux dossiers de police et autres. Les services d'urgence 911 ne sont pas touchés, mais certains services en ligne sont actuellement indisponibles. Aucune preuve n'a été trouvée que des informations personnelles ont...
> Knowledge Base Digest - July 2025
Articles Custom Operator Roles (RBAC) - Enable and Disable Application Support Custom Operator Roles (RBAC) - Frequently Asked Questions for Application Enable and Disable Incident changes that update the "Last Update" field on the ThreatSync Incident Details page Use Ping and TCPDump diagnostics t...
> Cliff Viessman, Inc.
Cliff Viessman, Inc. experienced a data security breach on August 5, 2025, where an unauthorized party gained access to certain systems and copied files. The breach may have impacted the security of personal information. The company is providing credit monitoring services and fraud assistance to aff...
> Caldwell Trust Company
An unauthorized actor accessed Caldwell's computer network between August 4, 2025, and August 8, 2025, and accessed certain files. One or more files containing the name, Social Security number, and/or driver's license number of one Maine resident were identified. Caldwell is offering complimentary c...
> Ghost in the Zip Reveals Expanding Ecosystem Behind PXA Stealer
Python-based PXA Stealer has stolen data from more than 4000 victims in over 62 countries, according to SentinalLabs
> KLA Instruments
KLA Instruments detected an unauthorized party gained access to certain corporate systems, resulting in the exposure of personal information. A cyberattack against KLA Instruments was claimed by Meow on August 8, 2024.
> New Jersey Compensation Rating & Inspection Bureau
NJCRIB experienced a data breach between July 8, 2025, and August 5, 2025, where an outside threat actor accessed their computer systems and copied administrative files without authorization. The breach may have exposed personal information, including names and contact details. NJCRIB is offering cr...
> Active Cyber Defence (ACD) - the fourth year
The year four report covers 2020 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme.
> CI Engineering
Chemical & Industrial Engineering suffered a data breach in August 2025, where an unauthorized third party gained access to their computer network from June to August 2025. The impacted files contained personal information, including names, addresses, and other data elements. A cyberattack was claim...
> EOPPEP
Le 5 août 2026, l'EOPPEP (l'Organisme national grec de certification des qualifications et d'orientation professionnelle) a été victime d'une attaque par ransomware. L'incident a paralysé les systèmes d'information et les services électroniques de l'organisme pendant huit jours, et ce, jusqu'à l'ann...
> Active Cyber Defence (ACD) - The Third Year
The year three report covers 2019 and aims to highlight the achievements and efforts made by the Active Cyber Defence programe.
> #BHUSA: Microsoft and Google Among Most Affected as Zero Day Exploits Jump 46%
Forescout also observed a big rise in CVEs added to CISA’s KEV catalog, some of which impacted end-of-life products
> Web-Based AI Usage Surge Shifts Global Internet Traffic Patterns
Web traffic to AI sites surged 50% from Feb 2024 to Jan 2025, driven by browser-based GenAI tools
> OWASP ASVS 5.0.0 is here!
I've been a huge fan of OWASP for a very long time, having spoken at their conferences, contributed to their projects, consumed many of their resources and met some really awesome people along the way! Just recently, one of the very popular OWASP projects, the Application Security Verification
> Uptick in Akira Ransomware Actors Targeting SonicWall VPNs
Arctic Wolf has spotted an increase in Akira ransomware attacks targeting SonicWall SSL VPNs
> Pwn2Own Offers $1m for Zero-Click WhatsApp Exploit
The Pwn2Own competition is offering a $1m reward to any teams able to unearth a WhatsApp code execution exploit
> Every Reason Why I Hate AI and You Should Too
maybe it's anti-innovation, maybe it's just avoiding hype. But one thing is clear, I'm completely done with hearing about AI.