> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
SentinelLabs observed North Korean actors deploying novel TTPs to target crypto firms, including a mix of programming languages and signal-based persistence
Deep cuts in cybersecurity spending risk creating ripple effects that will put many organizations at a higher risk of falling victim to cyberattacks
Two elevation of privilege vulnerabilities have been discovered on the popular Sudo utility, affecting 30-50 million endpoints in the US alone
Le Brisbane Entertainment Centre a été victime d'une attaque informatique, les données personnelles du personnel actuel et ancien ont été volées. Il s'agit de la dernière attaque informatique à toucher le Queensland. Les détails de l'attaque ne sont pas encore connus.
Miller Construction suffered a data breach where an unauthorized actor accessed certain files on their network, potentially exposing personal information. The breach occurred on or about July 3, 2025, and was discovered on the same date. The company is providing complimentary credit monitoring and i...
We’ve just passed a monumental milestone: 2 trillion events processed through Report URI!!! That’s 2,000,000,000,000 events for CSP, NEL, DMARC, and other browser-generated and email telemetry reports—ingested, parsed, and processed for our customers!This is a phenomenal milestone to achieve
New Android malware Qwizzserial has infected 100,000 devices, primarily in Uzbekistan, stealing SMS data via Telegram distribution
A third of AI-generated login URLs lead to incorrect or dangerous domains, according to Netcraft
Our CRS (Cyber Reasoning System), Buttercup, is now competing in the one and only scored round of DARPA’s AI Cyber Challenge (AIxCC) against six other teams to see which autonomous AI-driven system can find and patch the most software vulnerabilities.
The French cybersecurity agency identified Houken, a new Chinese intrusion campaign targeting various industries in France
The Treasury said that Aeza Group has provided infrastructure services for notorious infostealer and ransomware operators
ESET Research analyzes Gamaredon’s updated cyberespionage toolset, new stealth-focused techniques, and aggressive spearphishing operations observed throughout 2024
Benefits admin specialist Kelly Benefits has revealed a breach impacting over 500,000 individuals across 45 client organizations
Qantas admits that a “significant” volume of customer data may have been stolen from a contact center
Un hacker a attaqué le réseau informatique de la Congress-Centrum Saar GmbH, le laissant inactif. La direction a réagi immédiatement et a déposé plainte auprès de la police. Les enquêtes sont en cours pour déterminer l'impact sur les événements à venir.
Le site web du forum des fans de Morton a été victime d'une attaque cybernétique, ce qui a entraîné une interruption de service d'une semaine. Les administrateurs du site ont annoncé que les serveurs et logiciels du site avaient été attaqués, mais aucune information personnelle ou sensible n'a été c...
Cloudflare now blocks AI web crawlers by default, requiring permission from site owners for access
Harris, Burnett, Arend & Schmiesing CPA’s experienced a data breach where an unknown bad actor accessed individual’s information, potentially including names, social security numbers, and financial data.
First Baptist Church of Hammond suffered a data breach after an unknown cyber actor accessed its computer network and copied files containing names and Social Security numbers. The incident occurred between June 29 and July 2, 2025. The was claimed by Rhysida on July 29th.
Google has patched a critical type confusion vulnerability in Chrome, the fourth zero-day fix in 2025