> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
Extensions load unknown sites into invisible Windows. What could go wrong?
Nova Scotia Power revealed that a ransomware attack has prevented meters from sending energy usage data to its systems, impacting billing
CVE-2025-47981 has the “unfortunate hallmarks of becoming a significant problem,” said WatchTowr’s CEO
Note: This post was written by Jason Edison, co-author of OSINT Techniques. We are now approaching the October 2025 sun-setting of support for Windows 10. As a follow up to their previous announcements regarding post 2025 support, Microsoft recently announced additional options for those who wish to...
The US allege that the hacker stole critical COVID-19 research from universities at the behest of the Chinese government
The addition of a backdoor to the Atomic macOS Stealer marks a pivotal shift in one of the most active macOS threats, said Moonlock
La DITTT a été victime d'une cyberattaque visant les données relatives aux immatriculations et aux permis de conduire. L'ampleur de l'attaque est en cours d'évaluation. Une enquête a été ouverte pour déterminer l'origine exacte de l'attaque et renforcer les dispositifs de sécurité existants.
M&S chairman Archie Norman provided more insights into the April ransomware attack, but did not confirm whether a payment was made to the attackers
An unidentified individual or group used illegal methods to gain unauthorized access to Daniels Law Group's file servers, potentially acquiring personal data belonging to clients and their family members. The incident occurred on or before July 1, 2025, and was discovered on July 9, 2025. It was cla...
The attack was claimed by Runsomewares on August 13.
Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team
Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected officia...
PeopleGuru suffered a data breach in which an unauthorized third party gained access to certain systems within its network, potentially exposing sensitive information including names, Social Security numbers, financial account information, and driver's license numbers.
ESET Direct Endpoint Management plugin for N-able N-sight RMM Service Release 2.0 has been released.
Researchers from Koi Security have detected 18 malicious Chrome and Edge extensions masquerading as benign productivity and entertainment tools
Check Point discovered around 500 suspected Scattered Spider phishing domains, suggesting the group is preparing to expand its targeting
Le Clusif organise une conférence le 23 octobre prochain en présentiel au Campus Cyber sur le thème des dépendances stratégiques et de leurs répercussions sur le paysage de la cybersécurité. Les dispositifs de sécurité des organisations reposent sur une collaboration étroite avec de multiples acteur...
Deptective, our new open-source tool, automatically finds the packages needed to install software dependencies. It does so not based on the software’s self-reported requirements, but by observing what the software needs at runtime.
Sonatype’s latest Open Source Malware Index report has identified more than 16,000 malicious open source packages, representing a 188% annual increase
The company behind AV/EDR evasion tool Shellter has confirmed the product is being used by threat actors
Las Vegas. August. Protocols are getting torn apart. This summer, PortSwigger returns to Black Hat USA and DEF CON 33 with a host of new talks, events and ways to meet PortSwigger and the the teams be