> TODAY'S SUMMARY (88 articles)
Today's cybersecurity news highlights significant threats and trends. ASOS customers were targeted in a data breach where hackers stole personal details and shopping searches, prompting warnings about potential phishing attempts. In law enforcement, the FBI arrested members of the ShinyHunters group while also disrupting tools linked to the Flax Typhoon, a Chinese state-sponsored hacking group. Meanwhile, ransomware continues to pose a major risk, with new arrests and a trial involving a ransomware consultant accused of fraud. Citrix has issued critical patches for vulnerabilities in its NetScaler products, while researchers reported on the exploitation of flaws in AhsayCBS software. Lastly, a $10 million bounty has been offered for a Chinese hacker linked to a significant Microsoft Exchange Server attack, underscoring ongoing geopolitical cyber tensions.
|
// AI-powered summary generated at 16:00
During Infosecurity Europe 2025, Nick Woodcraft, from the UK Government, shared his experience in implementing measures to protect domains within the .gov.uk DNS namespace
Engagement with ransomware actors doesn’t necessarily mean payment; it’s about getting the best outcomes, a leading negotiator had argued
ESET researchers analyzed a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group with likely ties to OilRig
A panel of CISOs at Infosecurity Europe urged their peers to use risk management and clear communication to tame a chaotic cyber landscape
Sophisticated nation-state and cybercriminal groups are using insiders to infect targets via hardware devices, despite a lack of reporting of this threat
[Mise à jour du 06 juin 2025] Une preuve de concept est publiquement disponible. [Publication initiale] Le 01 juin 2025, Roundcube a publié des correctifs concernant une vulnérabilité critique affectant son portail de messagerie ainsi que tous les produits l'incluant (par exemple cPanel et...
Malicious actors are making more use of AI in attacks, even as governments look to boost AI investments
At Infosecurity Europe 2025, Axonius’ Jon Ridyard proposed seven best practices to build mature vulnerability management processes
Un ataque cibernétique a paralysé le système de la préfecture de Rio Preto, affectant les services de santé, notamment le SAMU, dont le téléphone est hors service. Les services sont actuellement réalisés manuellement, ce qui provoque des retards et des files d'attente. La préfecture travaille pour r...
Endpoint and network security is still essential, even as malicious actors turn to supply chains, identities and AI
Le district scolaire Lexington-Richland Five a subi une cyberattaque majeure, ce qui a retardé les primes de rétention pour les employés. Le district a lancé une enquête et travaille avec les forces de l'ordre et des spécialistes tiers pour déterminer la nature et l'étendue de l'incident. Les employ...
Le groupe a subi une attaque cybernétique visant son intranet et ses systèmes d'information, mais a activé ses mécanismes de défense pour minimiser l'impact. Il n'y a actuellement pas d'impact significatif sur les opérations de l'entreprise. Le groupe continuera à renforcer ses mesures de sécurité p...
Australian Racing Industry Ransomware Attack, 05 Jun 2025: Victorian based RISE Racing confirms Sarcoma ransomware attack. Reports indicate that 1.6GB of sensitive data was stolen, including: Banking details, financial records, participant personal information and operational data related to the rac...
United Natural Foods, Inc. a subi une activité non autorisée sur certains de ses systèmes informatiques, ce qui a temporairement impacté sa capacité à remplir et à distribuer les commandes des clients. L'entreprise travaille activement pour évaluer, atténuer et remédier à l'incident avec l'aide de p...
Sorbonne Université a été victime d'une cyberattaque qui a endommagé ses outils numériques, mais les services essentiels sont toujours disponibles. Les données sensibles compromises incluent des adresses e-mail professionnelles, des coordonnées bancaires et des numéros de sécurité sociale. L'univers...
Moving to cloud-native architecture and modern platforms is allowing enterprises to automate operations and improve security
La Media Broadcast Satellite a été victime d'une attaque de ransomware il y a environ deux semaines et demi, ce qui a entraîné la perturbation de ses opérations. L'entreprise travaille actuellement à la suppression complète des dommages et à la reconstruction de son infrastructure informatique. Les...
Surmodics, Inc. a signalé une faille de sécurité dans ses systèmes d'information, une attaque par un acteur malveillant a eu lieu le 5 juin 2025, les systèmes critiques ont été restaurés et les données sont en cours de validation, l'entreprise a pris des mesures pour contenir l'incident et a informé...
Experts argue the case for “communities of support” to boost SMB cyber-resilience
Unauthorized actor accessed the bank's computer network between June 4, 2025, and June 5, 2025, and obtained certain files containing sensitive customer information. The bank identified one or more files containing the name, Social Security number, and/or financial account number of a Maine resident...