> TODAY'S SUMMARY (15 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Ten leading AI firms have pledged to enhance data protection in response to UK regulatory pressures. Meanwhile, Mozilla removed 16 malicious Firefox extensions designed to steal cryptocurrency recovery phrases and private keys. Citrix has issued an urgent patch for a critical NetScaler vulnerability that could allow remote code execution. The FBI successfully disrupted tools used by the China-linked Flax Typhoon group targeting critical infrastructure. Additionally, the Pwn2Own Ireland hacking contest awarded over $1.2 million for exploits, underscoring the ongoing prevalence of zero-day vulnerabilities. Lastly, a report revealed thousands of unprotected wind and solar park systems across Europe, raising concerns about their cybersecurity posture.
|
// AI-powered summary generated at 08:00
Cyrus D. Mehta & Partners PLLC suffered a data breach where an unauthorized third party accessed certain systems and removed data. The breach may have involved address, demographic information, date of birth, Social Security number, passport or other government identification, and other identifiers....
L'Alabama Office of Information Technology a détecté une activité anormale sur son réseau, ce qui a entraîné des perturbations temporaires des services en ligne. Les équipes travaillent pour identifier et atténuer les impacts, et les données personnelles des résidents de l'État n'ont pas été comprom...
The tech giant plans to leverage its Gemini Nano LLM on-device to enhance scam detection on Chrome
In May 2025, Myers detected an event involving unauthorized activity in portions of their computer network. Such an attack had been claimed by Akira on April 18.
The UNIDR Intrusion Path is designed to provide a simplified view of cyber-threats and security across the network perimeter
Here’s a brief dive into the murky waters of shape-shifting attacks that leverage dedicated phishing kits to auto-generate customized login pages on the fly
The FBI has detected indicators of malware targeting end-of-life routers associated with Anyproxy and 5Socks proxy services
PowerSchool said its customers had been hit by new extortion demands using data stolen in a previous attack, despite attacker claims the data had been deleted
Le Hessischen Apothekerverband a été victime d'une attaque cybernétique, les parties sécurisées de ses systèmes informatiques ont été compromises et chiffrées. Un groupe d'experts en forensique informatique a été chargé d'enquêter sur l'attaque et d'analyser les dégâts. Pour le moment, il n'y a aucu...
Tiffany & Co. a confirmé une violation de données touchant des clients en Corée du Sud, survenue le 8 avril via une plateforme tierce de gestion de données, exposant des informations personnelles sensibles comme les noms, adresses et historiques d’achats. Cet incident survient après une affaire simi...
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
Belk Inc. says a cyber incident disrupted its systems in May.
The Texas Access to Justice Foundation suffered a data breach between May 6, 2025, and May 9, 2025, resulting in unauthorized access to certain files containing personal information. The breach was discovered on May 9, 2025, and affected approximately one Maine resident. The compromised information...
Posted by Jasika Bawa, Andy Lim, and Xinghui Lu, Google Chrome Security
Tech support scams are an increasingly prevalent form of cybercrime, characterized by deceptive tactics aimed at extorting money or gaining unauthorized access to sensitive data. In a tech support scam, the goal of the scammer...
Cyber incidents targeting OT in US critical infrastructure have prompted renewed federal action
New LOSTKEYS malware has been identified and linked to COLDRIVER by GTIG, stealing files and system data in targeted attacks
Guidance for home users or small businesses who want to reduce the likelihood of being held to ransom by WannaCry (or other types of ransomware).
The data dump will likely shed light on LockBit’s recent activity and help law enforcement trace cryptocurrency transactions
DigiCert survey finds only 5% of global businesses are using post-quantum cryptography
Laying the groundwork for incident readiness.