[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 00:01

> UK and Romania Crack Down on ATM Fraudster Network
Investigators assessed that the criminal group’s stolen funds amount to €580,000
> ToolShell: An all-you-can-eat buffet for threat actors
ESET Research has been monitoring attacks involving the recently discovered ToolShell zero-day vulnerabilities
> Rogue CAPTCHAs: Look out for phony verification pages spreading malware
Before rushing to prove that you're not a robot, be wary of deceptive human verification pages as an increasingly popular vector for delivering malware
> Active Campaign Exploits Cloud Flaws for Cryptomining
Wiz believes the active campaign is part of a broader crypto-scam infrastructure, which uses a wide range of exploitation techniques
> CRA, l’ANSSI encourage l’implication d’organismes d’évaluation de la conformité
CRA, l’ANSSI encourage l’implication d’organismes d’évaluation de la conformité anssiadm jeu 24/07/2025 - 07:37 Pour certains acteurs, la conformité au règlement CRA impliquera dès juin 2026 des évaluations qui seront menées par des organismes d’évaluation de la conf...
> Baden-Württembergischer Landesverband für Prävention und Rehabilitation gGmbH (bwlv)
Le Baden-Württembergischer Landesverband pour Prävention et Rehabilitation a été victime d'une attaque informatique, mais grâce à des mesures de sécurité, les systèmes ont été isolés et la prise en charge des patients n'a pas été affectée. Les auteurs de l'attaque ont pu chiffrer certaines parties d...
> Ridgefield Public Schools
Ridgefield Public Schools a subi une attaque de ransomware, ce qui a entraîné la fermeture de son réseau et une enquête sur les conséquences potentielles pour les données. Les autorités ont été informées et aident à l'enquête. Le district travaille à restaurer ses services de manière sécurisée et mé...
> Multiples vulnérabilités dans les produits Mitel (24 juillet 2025)
De multiples vulnérabilités ont été découvertes dans les produits Mitel. Elles permettent à un attaquant de provoquer une injection SQL (SQLi) et un contournement de la politique de sécurité.
> Sotheby's
Sotheby's experienced a data breach where an unknown actor removed certain data from their environment. The breach was discovered on July 24, 2025, and affected two Maine residents. The stolen data included names, Social Security numbers, and financial account information.
> After $380M hack, Clorox sues its “service desk” vendor for simply giving out passwords
Massive 2023 hack was easily preventable, Clorox says.
> Slackware 15.0: httpd Critical DoS and Access Control Fix SSA:2025-204-01
New httpd packages are available for Slackware 15.0 and -current to fix security issues.
> New York Proposes Cybersecurity Regulations for Water Systems
A series of new cybersecurity regulations related to the water industry have been set out by New York state agencies
> Beyond Convenience: Exposing the Risks of VMware vSphere Active Directory Integration
Written by: Stuart Carrera, Brian Meyer Executive Summary Broadcom's VMware vSphere product continues to be a top choice for private cloud virtualization, underpinning important systems and critical infrastructure. Far from losing its appeal, organizations still rely heavily on vSphere for its stab...
> From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944
Introduction In mid 2025, Google Threat Intelligence Group (GTIG) identified a sophisticated and aggressive cyber campaign targeting multiple industries, including retail, airline, and insurance. This was the work of UNC3944, a financially motivated threat group that has exhibited overlaps with publ...
> Suspected XSS Forum Admin Arrested in Ukraine
The individual is accused of numerous illicit cybercrime and ransomware activities that have generated at least $7m in profit
> France: New Data Breach Could Affect 340,000 Jobseekers
The French employment agency’s partner web portal has been accessed by a malicious actor
> Inside EthCC[8]: Becoming a smart contract auditor
At EthCC[8], Trail of Bits blockchain security engineer Nicolas Donboly laid out a clear, actionable path for aspiring smart contract auditors, drawing from his own experience transitioning from a non-technical background into a leading security role.
> Clorox Sues IT Service Provider Cognizant for Causing 2023 Cyber-Attack
Cognizant handed over a password to the cybercriminal without asking any authentication questions
> US Government Warns of Wide-Ranging Interlock Attacks
A joint US government advisory highlighted novel initial access techniques deployed by Interlock, and urged businesses and critical infrastructure to stay vigilant
> Creams Cafe - 159,652 breached accounts
In May 2025, 160k records of customer data was allegedly obtained from Creams Cafe, "the UK's favourite dessert parlour". The data included email and physical addresses, names and phone numbers. Creams Cafe did not respond to repeated attempts to disclose the incident, however multiple impacted HIBP...