> TODAY'S SUMMARY (44 articles)
In Q3 2026, ransomware attacks reached a record high of 2,627, particularly impacting critical sectors like finance and healthcare. Citrix has issued urgent patches for a critical NetScaler vulnerability (CVE-2026-107406) that could allow remote code execution. Meanwhile, hackers hijacked multiple country code top-level domains (ccTLDs) linked to Google, raising concerns over domain security. An update on the ASOS breach reveals that customer data, including shopping habits, has been compromised, increasing phishing risks. The FBI has disrupted operations of Chinese state-sponsored hacking tools, while new vulnerabilities in AhsayCBS are being actively exploited. Additionally, the rise of pre-installed malware on low-cost Android devices highlights ongoing threats in mobile security.
|
// AI-powered summary generated at 12:00
Posted by Il-Sung Lee, Group Product Manager, Android Security
Protecting users who need heightened security has been a long-standing commitment at Google, which is why we have our Advanced Protection Program that provides Google’s strongest protections against targeted attacks.To enhance these ex...
ESET PROTECT Hub version 1.12.2 has been released.
Marbled Dust has been exploiting a vulnerability in user accounts associated with the Kurdish military operating in Iraq for over a year, according to Microsoft
Cyber espionage campaign linked to North Korean actor TA406 targeted Ukrainian government entities
Le 13 mai 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité CVE-2025-32756. Celle-ci permet à un attaquant non authentifié d'exécuter du code arbitraire à distance. L'éditeur indique que cette vulnérabilité est activement exploitée. Les exploitations constatées jusqu'ici...
CISA won't post standard cybersecurity updates on its website, shifting to email and social media
ENISA has officially launched the European Vulnerability Database as required by the NIS2 directive
A cloud attack targeting Amazon SES and persistence via AWS Lambda, AWS IAM Identity Center and AWS IAM
M&S Chief Executive, Stuart Machin, said that the firm has written to customers to inform them that some personal information was accessed by threat actors
The UK government wants to hear feedback on a possible new standard or legislation to improve enterprise IoT security
Nucor Corporation a récemment identifié une faille de sécurité informatique impliquant un accès non autorisé à certains systèmes d'information. L'entreprise a pris des mesures pour contenir et répondre à l'incident, y compris la mise en œuvre de son plan de réponse aux incidents et la notification d...
Les écoles publiques du comté de Botetourt enquêtent sur une faille de sécurité informatique qui a touché leur réseau. L'incident a temporairement affecté certains systèmes informatiques et l'école travaille à rétablir la pleine fonctionnalité. L'enquête est en cours avec l'aide d'experts en cybersé...
Hacktivist claims on Indian infrastructure raised alarms, but investigations showed minimal damage
Le service technique de la Coopérative Téléphonique informe qu’il a été constaté des cyberattaques portant atteinte et interférant directement avec les services d’Internet et de Nexo.Tv. Ces attaques ont un impact sur la capacité de la Coopérative à fournir un service de qualité optimale.
Anne Arundel Dermatology experienced a data breach due to unauthorized access to certain systems by an unknown third party. The breach occurred between February 14, 2025, and May 13, 2025. The affected data may include personal or health information.
The criminal proxy network infected thousands of IoT and end-of-life devices, creating dangerous botnet
Upper Dublin Family Dentistry experienced a data security incident where an unauthorized party gained access to their computer systems and may have accessed patient information, including names, Social Security numbers, and dental medical records.
Georgetown Preparatory School suffered a data breach where an unauthorized party gained access to certain systems on their network, copying files that contained personal information. The breach occurred on May 13, 2025, and was discovered on the same date. The school is offering identity monitoring...
During Infosecurity Europe 2025 experts will explore how to strengthen organizational resilience against persistent third-party risks
She@Cyber training program is focused on improving the representation of women and other underrepresented groups in the cybersecurity industry