[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (109 articles)

|

// AI-powered summary generated at 20:00

> Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor
Written by: Josh Goddard, Zander Work, Dimiter Andonov UPDATE (Sep 16): Clarified hunting guidance specifics surrounding ld.so.preload files. UPDATE (July 30): Added additional network IOC identified by Sonicwall as being associated with OVERSTEP.    Introduction Google Threat Intelligence Group (G...
> Retail Ransomware Attacks Jump 58% Globally in Q2 2025
BlackFog found that publicly disclosed ransomware attacks on retail grew significantly in Q2 compared to Q1, with UK firms heavily targeted
> Cloudflare Blocks Record-Breaking 7.3 Tbps DDoS Attack
Cloudflare highlighted a huge rise in hyper-volumetric DDoS attacks in Q2 2025, with attackers seeking to overwhelm defenses
> Slackware: libxml2 Important Security Update 2025-196-02 - Multiple Issues
New libxml2 packages are available for Slackware 15.0 to fix security issues.
> Education Sector is Most Exposed to Remote Attacks
CyCognito research finds that a third of education sector APIs, web apps and cloud assets are exposed to attack
> Co-op Aims to Divert More Young Hackers into Cyber Careers
The Co-op is teaming up with The Hacking Games to inspire pathways into ethical cybersecurity careers
> I SPy: Escalating to Entra ID's Global Admin with a first-party app
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led to the development of new security controls. Despite these efforts, we uncovered a vulnerable, buil...
> Delfingen
Le groupe DELFINGEN a détecté une intrusion dans son système d'information, conduisant à des fuites de données dans quelques applications héritées de Schlemmer. Les équipes de DELFINGEN ont pris des mesures pour renforcer la protection et minimiser les impacts potentiels. L'entreprise est en contact...
> Slackware 15.0: libxml2 Critical DoS Buffer Overflow Advisory 2025-196-01
New libxml2 packages are available for Slackware 15.0 and -current to fix security issues.
> MITRE Launches New Framework to Tackle Crypto Risks
MITRE has introduced AADAPT framework, a new cybersecurity framework aimed at mitigating risks in digital financial systems like cryptocurrency
> Threat Actors Exploit SVG Files in Stealthy JavaScript Redirects
A new phishing campaign uses SVG files for JavaScript redirects, bypassing traditional detection methods
> Unmasking AsyncRAT: Navigating the labyrinth of forks
ESET researchers map out the labyrinthine relationships among the vast hierarchy of AsyncRAT variants
> SaaS Security Adoption Grows Amid Rising Breach Rates
The latest report from AppOmni has revealed 91% confidence in SaaS security while 75% of organizations have faced incidents
> North Korean Actors Expand Contagious Interview Campaign with New Malware Loader
Socket has identified a new malware loader called XORIndex incorporated into malicious packages published to the npm registry, with over 9000 downloads so far
> 'NCSC Cyber Series' podcast now available
Listen to all five episodes now, covering a wide range of cyber security topics.
> Abacus Market Shutters After Exit Scam, Say Experts
Darknet giant Abacus Market has gone offline due to a likely exit scam, according to TRM Labs
> NCSC Launches Vulnerability Research Institute to Boost UK Resilience
The NCSC’s new Vulnerability Research Institute will help it develop outreach with the external cybersecurity community
> MaReads - 74,453 breached accounts
In June 2025, MaReads, the website for readers and writers of Thai-language fiction and comics suffered a data breach that exposed 74k records. The breach included usernames, email addresses, phone numbers and dates of birth. MaReads is aware of the breach.
> Bulletin d'actualité CERTFR-2025-ACT-029 (15 juillet 2025)
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
> Profitbase
Le konsern Aneo a été victime d'une attaque informatique via son sous-traitant Profitbase, ce qui pourrait avoir compromis les informations personnelles de 450 employés. Les données concernées incluent des informations sur les salaires et pourraient contenir des noms, adresses et numéros de téléphon...