> TODAY'S SUMMARY (88 articles)
Today's cybersecurity news highlights significant threats and trends. ASOS customers were targeted in a data breach where hackers stole personal details and shopping searches, prompting warnings about potential phishing attempts. In law enforcement, the FBI arrested members of the ShinyHunters group while also disrupting tools linked to the Flax Typhoon, a Chinese state-sponsored hacking group. Meanwhile, ransomware continues to pose a major risk, with new arrests and a trial involving a ransomware consultant accused of fraud. Citrix has issued critical patches for vulnerabilities in its NetScaler products, while researchers reported on the exploitation of flaws in AhsayCBS software. Lastly, a $10 million bounty has been offered for a Chinese hacker linked to a significant Microsoft Exchange Server attack, underscoring ongoing geopolitical cyber tensions.
|
// AI-powered summary generated at 16:00
ESET Endpoint Antivirus and ESET Endpoint Security for Windows version 12.0.2058.0 have been released and are available for download.
Cato Networks researchers demonstrated an attack leveraging Atlassian’s AI agent-enabling server
An alleged former member of the infamous Ryuk ransomware group has been extradited to the US
La chaîne de magasins de matériaux de construction Leymann-Baustoffe a été victime d'une attaque informatique, affectant également des filiales à Storkow, Beeskow, Eisenhüttenstadt et Francfort-sur-l'Oder. Les détails de l'attaque ne sont pas précisés dans l'article. L'entreprise est basée en Allema...
Pro-Israel Predatory Sparrow Group steals $90m in crypto from Iranian exchange Nobitex
Le district scolaire de Bonneville a subi une attaque informatique, ce qui a entraîné la fermeture de son réseau pour des raisons de sécurité. Les programmes d'école d'été sont actuellement perturbés en raison de cette attaque. Aucune donnée n'a été compromise ou perdue lors de l'attaque, grâce à l'...
Une attaque cybernétique a touché le conseil municipal de Glasgow, provoquant des perturbations dans les services en ligne et potentiellement entraînant le vol de données client. Les autorités sont en train d'enquêter sur l'incident et les services affectés sont temporairement indisponibles. Les cit...
Two critical Linux flaws allow unprivileged users to gain root access, affecting major distributions
Un prestataire de l'agence régionale bruxelloise du stationnement a été victime d'une cyberattaque, et des données de ses usagers ont été volées. Les données subtilisées incluent le nom, prénom, adresse postale, adresse électronique, numéro d'immatriculation du véhicule, numéro de téléphone et numér...
CGP&H, LLC suffered a data breach where an unknown actor gained access to certain parts of its network between June 19, and June 20, 2025, and may have accessed or acquired certain files. The breach may have exposed name and Social Security number/Individual Taxpayer Identification Number. A cyberat...
Barracuda observed a big spike in spam emails generated using AI tools, making up the majority detected in April 2025
Written by: Gabby Roncone, Wesley Shields
UPDATE (July 10)
In late June 2025, Google Threat Intelligence Group (GTIG) discovered continued UNC6293 operations that demonstrate an evolution in the group’s tradecraft. Using similar lure themes as previously observed activity, UNC6293 continued the ASP...
Upgraded GodFather banking malware now uses on-device virtualization to hijack apps, enabling real-time fraud
ClickFix techniques are enabling threat actors to bypass defenses using tools like MSHTA, says ReliaQuest
File parsers in Go contain unexpected behaviors that can lead to serious security vulnerabilities. This post examines how JSON, XML, and YAML parsers in Go handle edge cases in ways that have repeatedly resulted in high-impact security issues in production systems. We explore three real-world attack...
The new Cyber Growth Action Plan aims to support the UK’s cyber industry, including the development of innovative new technologies and startups
The group positions itself “not just as a ransomware group, but as a full-service cybercrime platform”, according to Cybereason
Activities which organisations must carry out to migrate safely to post-quantum cryptography in the coming years.
Payment processor Paddle has agreed to settle with the FTC over allegations related to tech support scams
Un cyberattaque a visé les systèmes informatiques de plusieurs écoles dans les villes de Demmin et Neustrelitz, en Allemagne, provoquant des perturbations dans l'utilisation des appareils électroniques. Les écoles touchées incluent le Regionalen Beruflichen Bildungszentrum, la Förderschule Neustreli...