> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
Written by: Josh Goddard, Zander Work, Dimiter Andonov
UPDATE (Sep 16): Clarified hunting guidance specifics surrounding ld.so.preload files.
UPDATE (July 30): Added additional network IOC identified by Sonicwall as being associated with OVERSTEP.Â
Â
Introduction
Google Threat Intelligence Group (G...
BlackFog found that publicly disclosed ransomware attacks on retail grew significantly in Q2 compared to Q1, with UK firms heavily targeted
Cloudflare highlighted a huge rise in hyper-volumetric DDoS attacks in Q2 2025, with attackers seeking to overwhelm defenses
New libxml2 packages are available for Slackware 15.0 to fix security issues.
CyCognito research finds that a third of education sector APIs, web apps and cloud assets are exposed to attack
The Co-op is teaming up with The Hacking Games to inspire pathways into ethical cybersecurity careers
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led to the development of new security controls. Despite these efforts, we uncovered a vulnerable, buil...
Le groupe DELFINGEN a détecté une intrusion dans son système d'information, conduisant à des fuites de données dans quelques applications héritées de Schlemmer. Les équipes de DELFINGEN ont pris des mesures pour renforcer la protection et minimiser les impacts potentiels. L'entreprise est en contact...
New libxml2 packages are available for Slackware 15.0 and -current to fix security issues.
MITRE has introduced AADAPT framework, a new cybersecurity framework aimed at mitigating risks in digital financial systems like cryptocurrency
A new phishing campaign uses SVG files for JavaScript redirects, bypassing traditional detection methods
ESET researchers map out the labyrinthine relationships among the vast hierarchy of AsyncRAT variants
The latest report from AppOmni has revealed 91% confidence in SaaS security while 75% of organizations have faced incidents
Socket has identified a new malware loader called XORIndex incorporated into malicious packages published to the npm registry, with over 9000 downloads so far
Listen to all five episodes now, covering a wide range of cyber security topics.
Darknet giant Abacus Market has gone offline due to a likely exit scam, according to TRM Labs
The NCSC’s new Vulnerability Research Institute will help it develop outreach with the external cybersecurity community
In June 2025, MaReads, the website for readers and writers of Thai-language fiction and comics suffered a data breach that exposed 74k records. The breach included usernames, email addresses, phone numbers and dates of birth. MaReads is aware of the breach.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
Le konsern Aneo a été victime d'une attaque informatique via son sous-traitant Profitbase, ce qui pourrait avoir compromis les informations personnelles de 450 employés. Les données concernées incluent des informations sur les salaires et pourraient contenir des noms, adresses et numéros de téléphon...