> TODAY'S SUMMARY (88 articles)
Today's cybersecurity news highlights significant threats and trends. ASOS customers were targeted in a data breach where hackers stole personal details and shopping searches, prompting warnings about potential phishing attempts. In law enforcement, the FBI arrested members of the ShinyHunters group while also disrupting tools linked to the Flax Typhoon, a Chinese state-sponsored hacking group. Meanwhile, ransomware continues to pose a major risk, with new arrests and a trial involving a ransomware consultant accused of fraud. Citrix has issued critical patches for vulnerabilities in its NetScaler products, while researchers reported on the exploitation of flaws in AhsayCBS software. Lastly, a $10 million bounty has been offered for a Chinese hacker linked to a significant Microsoft Exchange Server attack, underscoring ongoing geopolitical cyber tensions.
|
// AI-powered summary generated at 16:00
La ville d'Inman a confirmé avoir été victime d'une attaque informatique en juin, les autorités sont toujours en train d'enquêter sur l'incident. Les détails sur les pertes financières éventuelles ne sont pas divulgués en raison de l'enquête en cours. L'affaire est traitée par le bureau du shérif du...
Posted by Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacke...
Jen Easterly and Ciaran Martin called for a universal, vendor-neutral cyber threat actor naming system
It’s been a whirlwind two months since AI-powered features landed in Burp Suite Professional. Thousands of security testers across the world have been using Burp AI to find vulnerabilities and secure
This is the first forensic evidence that journalists’ devices have been infected with Paragon’s Graphite spyware
In my first blog post about hacking my Tesla Powerwalls, I laid out all of the foundations and information about my home energy setup. You really need to read that blog post first as I'm going to be building on all of that work here, and assuming that
A CISA advisory urged all software vendors and downstream customers to check if they are impacted by unpatched versions of the SimpleHelp RMM tool
Researchers have found a flaw in Microsoft 365 Copilot that allows the exfiltration of sensitive corporate data with a simple email
WestJet a subi une faille de sécurité informatique affectant ses systèmes internes et son application, l'entreprise a activé des équipes spécialisées pour enquêter et limiter les impacts. Les opérations de l'entreprise sont toujours en cours et les équipes travaillent pour maintenir la sécurité opér...
La société australienne de services gérés Vertel a été victime d'une attaque de ransomware par le groupe Space Bears, qui a exfiltré des données sensibles. L'entreprise a confirmé l'incident et travaille avec des experts en cybersécurité pour comprendre l'étendue de l'attaque. Les hackers menacent d...
The cybersecurity provider also implemented recent fixes in Chromium that affected its Prisma Access Browser
The Hiller Companies LLC suffered a data security incident involving the potential exposure of personal information, including names and Social Security numbers. The incident occurred due to a malicious encryption perpetrated by unknown actors. The company is offering complimentary identity protecti...
Dairy Farmers of America suffered a data breach that exposed personally identifiable information (PII) of its employees. The incident was claimed by Play on June 22.
The new NIST guidance sets out 19 example implementations of zero trust using commercial, off-the-shelf technologies
Europol warns of “vicious circle” of data breaches and cybercrime
Aflac Incorporated a subi une faille de sécurité, entraînant l'accès non autorisé à des données sensibles de clients et d'employés, y compris des numéros de sécurité sociale et des informations de santé. L'entreprise a pris des mesures pour contenir l'incident et offre des services de surveillance d...
Erie Insurance reveals suspected network breach and ongoing outage
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes de Steeplechase Tool & Die.
Recommended authentication models for organisations looking to move 'beyond passwords'.
The legislation aims to expand the federal government’s role in helping healthcare providers protect and respond to cyber-attacks