[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 00:01

> Fake Receipt Generators Fuel Rise in Online Fraud
An investigation has revealed novel scams using tools like MaisonReceipts, creating realistic fake receipts to resell stolen or counterfeit good
> Accounting Firm Targeted by Malware Campaign Using New Crypter
An attack on a US accounting firm delivered PureRAT via Ghost Crypt, involving social engineering and advanced obfuscation techniques
> Detecting code copying at scale with Vendetect
Vendetect is our new open-source tool for detecting copied and vendored code between repositories. It uses semantic fingerprinting to identify similar code even when variable names change or comments disappear. More importantly, unlike academic plagiarism detectors, it understands version control hi...
> New CrushFTP Critical Vulnerability Exploited in the Wild
CVE-2025-54309 could allow remote attackers to obtain admin access via HTTPS
> Microsoft: Attackers Actively Compromising On-Prem SharePoint Customers
On-prem SharePoint customers have been told to assume compromise, with attackers observed to be exfiltrating data from victim servers across critical sectors
> [MàJ] Multiples vulnérabilités dans Microsoft SharePoint (21 juillet 2025)
**[Mise à jour du 23 juillet 2025]** Le 20 juillet 2025, Microsoft a publié des correctifs pour une vulnérabilité de type limitation insuffisante d'un chemin d'accès à un répertoire restreint, aussi appelé *path traversal*, affectant SharePoint Enterprise Server 2016, SharePoint Server 2019 et...
> Beyond Mimo’lette: Tracking Mimo's Expansion to Magento CMS and Docker
This post reports on activity from the 'Mimo' threat actor.
> Serviço Autônomo de Água e Esgoto de Barretos (SAAEB)
Le SAAEB a subi une tentative d'attaque cybernétique, les systèmes internes sont temporairement hors service, mais les données ont été sauvegardées grâce à la politique de sécurité de l'information. L'équipe technique travaille à la restauration des systèmes. Les services présentiels sont actuelleme...
> Fort Smith Public School District
Le district scolaire public de Fort Smith est victime d'une attaque informatique qui a perturbé les systèmes téléphoniques et internet. Le district travaille avec une entreprise tierce pour résoudre le problème et ne prévoit pas de perturbation pour le début de l'année scolaire. L'attaque a été sign...
> Bulletin d'actualité CERTFR-2025-ACT-030 (21 juillet 2025)
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
> Modernizing Medicine, Inc. (“ModMed”)
On July 21, 2025, ModMed became aware of potential unauthorized activity in certain computer servers, which ModMed subsequently determined involved servers containing limited data from some of our podiatry customers. We immediately took steps to prevent any further unauthorized activity and began an...
> Opus Card Systems, Inc.
Opus Card Systems, Inc. has experienced a data incident, resulting in potential unauthorized access to personal information. The company is offering monitoring services to affected individuals. The incident is not currently known to have resulted in any fraud.
> CISA Issues Advisories on Critical ICS Vulnerabilities Across Multiple Sectors
The US CISA has issued advisories for Industrial Control Systems vulnerabilities affecting multiple vendors including Johnson Controls, ABB, Hitachi Energy, and Schneider Electric
> JASCO Applied Sciences
JASCO Applied Sciences suffered a data breach after an unauthorized party gained access to their network, resulting in the acquisition of personal information. The breach was discovered on July 21, 2025, and around October 20, it was established that that some personal information had been acquired....
> Groupe Colabor Inc.
Le Groupe Colabor Inc. a identifié un incident de cybersécurité qui a eu un impact sur ses systèmes internes de TI, la société a pris des mesures pour protéger son réseau et ses données. L'enquête est en cours pour comprendre l'étendue et l'impact de l'incident. Les détails sur l'incident, y compris...
> Russia Linked to New Malware Targeting Email Accounts for Espionage
Russian military intelligence-linked hackers are using a new malware called “Authentic Antics” to secretly access Microsoft cloud email accounts, the UK's NCSC reports
> Baltimore Medical System Inc.
Baltimore Medical System Inc. suffered a data breach between July 2, 2025, and July 20, 2025, where an unauthorized actor accessed certain systems and accessed or copied files containing personal information. The breach affected approximately 3 Rhode Island residents, 4 Vermont residents, and an unk...
> Agrolab's
Le laboratoire d'analyses Agrolab's, plus grand laboratoire interprofessionnel laitier français, a subi une cyberattaque massive qui l'a paralysé pendant neuf jours. Bien que fortement impacté, l'entreprise s'est rétablie grâce à des sauvegardes épargnées et a atteint un chiffre d'affaires record de...
> New “LameHug” Malware Deploys AI-Generated Commands
Ukraine’s CERT-UA has identified a new AI-powered malware, dubbed “LameHug,” which executes commands on compromised Windows systems in cyber-attacks, targeting the nation’s security and defense sector
> Building secure messaging is hard: A nuanced take on the Bitchat security debate
The release of Bitchat last week was met with a mixture of glowing praise and sharp criticism. Both extremes bear some truth, but they also miss the mark and reveal gaps in how we discuss security in emerging products.