> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
A patient’s death was linked to the 2024 ransomware attack on Synnovis, which disrupted NHS facilities
Introduction As you may know, Compass Security participated in the 2023 edition of the Pwn2Own contest in Toronto and was able to successfully compromise the Synology BC500 camera using a remote code execution vulnerability. If you missed this, head over to the blog post here https://blog.compass-se...
ESET Cloud Office Security v594 has been released.
ESET Endpoint Antivirus and ESET Endpoint Security for Windows version 11.1.2062.0 have been released and are available for download.
The ClickFix social engineering technique has become the second most common attack vector, behind only phishing, according to ESET research
The hackers are also suspected of being behind several cyber-attacks, including against the French Football Federation
A view of the H1 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
Interpol claims cybercrime has risen sharply in Africa with cyber-offences accounting for a "medium-to-high" share of all crime
Glasgow City Council has warned of service disruption and potential data loss after a security incident
Hawaiian Airlines a confirmé un incident de cybersécurité, qui a affecté certains de ses systèmes informatiques, mais les vols continuent d'opérer normalement, les réservations et les paiements semblent ne pas être affectés, mais l'incident a suscité des inquiétudes quant à la sécurité des données d...
Le Richard Lander School à Truro sera fermé pendant deux jours en raison d'une incident cybernétique qui a affecté ses systèmes informatiques. L'école a indiqué qu'il n'y a actuellement aucune preuve que des données personnelles ont été compromises. Une enquête est en cours et l'école travaillera av...
The threat actor used a combination of open-source and publicly available tools to establish their attack framework
Le 26 juin 2025, All Choice Rentals Ltd. a subi une attaque par ransomware affectant une partie de son réseau interne, rapidement contenue par l'équipe informatique avec l’aide d’experts en cybersécurité. Les systèmes ont été restaurés à partir de sauvegardes sécurisées, et les opérations de locatio...
ALPS a découvert une activité inhabituelle dans son SI le 26 juin. L'entreprise a lancé une enquête et prend des mesures pour renforcer la sécurité de ses systèmes. Une cyberattaque contre ALPS a été revendiquée par Qilin le 12 août 2025.
NSA and CISA are urging developers to adopt memory safe languages (MSLs) to combat vulnerabilities in software
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes d'Achen-Gardner Construction.
Greer CPW suffered a data breach where an unauthorized individual copied certain information from their network environment. The breach occurred on June 19, 2025, and was discovered on June 26, 2025. The potentially impacted information included personal and sensitive data.
Calling cyber security professionals, culture specialists and leaders to drive uptake of new Cyber security culture principles.
Semperis estimates that at least 15,000 enterprise SaaS applications are still vulnerable to a flaw discovered in 2023
Two SAP GUI vulnerabilities have been identified exposing sensitive data due to weak encryption in input history features