> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
DePaoli Mosaic Company suffered a data breach on July 2, 2025, where personal information, including names, addresses, driver's licenses, and Social Security numbers, may have been exposed. The company is offering complimentary credit monitoring services to affected individuals. No evidence of fraud...
Cloudflare now blocks AI web crawlers by default, requiring permission from site owners for access
Google has patched a critical type confusion vulnerability in Chrome, the fourth zero-day fix in 2025
ESET Chief Security Evangelist Tony Anscombe looks at some of the report's standout findings and their implications for organizations in 2025
Proofpoint has identified similarities between the tactics of a pro-Russian cyber espionage group and a cybercriminal gang
The ICC said the new incident was the second “of its type” it has faced in recent years, relating to an espionage attack in 2023
ESET experts discuss Sandworm’s new data wiper, relentless campaigns by UnsolicitedBooker, attribution challenges amid tool-sharing, and other key findings from the latest APT Activity Report
CertiK found $2.47bn in crypto was stolen in H1 2025, largely due to two major security incidents – ByBit and Cetus
The threat actor Sarcoma has been held responsible for a ransomware attack on a Swiss health foundation
**[Mise à jour du 17 juillet 2025]** L'éditeur a publié un lien contenant une méthode d'évaluation permettant d'identifier des tentatives d'exploitation dans les journaux applicatifs et systèmes [12]. **[Mise à jour du 7 juillet 2025]** Le 17 juin 2025, Citrix a publié un bulletin de sécurité...
Interpol warns that scam centers are expanding beyond Southeast Asia
Both the US authorities and Microsoft have taken action to disrupt North Korean IT worker schemes
In September 2024, ANSSI observed an attack campaign seeking initial access to French entities’ networks through the exploitation of several zero-day vulnerabilities on Ivanti Cloud Service Appliance (CSA) devices. French organizations from governmental, telecommunications, media, finance, and...
Selon des sources anonymes, un affidé Qilin a conduit une cyberattaque contre la banque BNC, demandant 8 millions de dollars de rançon.
Une attaque cybernétique a visé la société C&M Software, fournisseur de services de technologie pour les institutions financières brésiliennes, affectant les comptes de réserve de certaines institutions. L'attaque a eu lieu lundi et le Banco Central a ordonné à C&M de bloquer l'accès aux institution...
While performing a penetration test for one of our Continuous Penetration Testing customers, we’ve found a Wing FTP server instance that allowed anonymous connections. It was almost the only interesting thing exposed, but we still wanted to get a foothold into their perimeter and provide the custome...
L'hôpital de Nymburk a subi une cyberattaque massive qui a perturbé ses systèmes informatiques, obligeant le personnel à effectuer des processus numériques manuellement. Les examens radiographiques et CT-scan ont déjà été remis en service, mais le retour à un fonctionnement normal prendra plusieurs...
Tipton, Marler, Garner and Chastain, P.A. suffered a data breach where an unauthorized actor viewed and/or copied a limited number of files containing names and Social Security numbers. The breach occurred on July 1, 2025, and was discovered on July 1, 2025. The incident was investigated, and the af...
A €460m cryptocurrency fraud scheme has been disrupted by authorities, leading to five arrests in Spain
US Defense Industrial Base (DIB) companies are “at increased risk” of cyber-attacks from Iran-aligned hacking groups