> TODAY'S SUMMARY (15 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Ten leading AI firms have pledged to enhance data protection in response to UK regulatory pressures. Meanwhile, Mozilla removed 16 malicious Firefox extensions designed to steal cryptocurrency recovery phrases and private keys. Citrix has issued an urgent patch for a critical NetScaler vulnerability that could allow remote code execution. The FBI successfully disrupted tools used by the China-linked Flax Typhoon group targeting critical infrastructure. Additionally, the Pwn2Own Ireland hacking contest awarded over $1.2 million for exploits, underscoring the ongoing prevalence of zero-day vulnerabilities. Lastly, a report revealed thousands of unprotected wind and solar park systems across Europe, raising concerns about their cybersecurity posture.
|
// AI-powered summary generated at 08:00
Les écoles de West Lothian ont été victimes d'une attaque de ransomware, un type de logiciel malveillant qui empêche l'accès aux données. Le conseil de West Lothian a confirmé l'attaque et a mis en place des plans de contingence pour minimiser les perturbations. Une enquête criminelle est en cours a...
Une cyberattaque par rançongiciel a été détectée dans l'entreprise *terre d'Oc* dans la nuit du 5 au 6 mai 2025, entraînant une possible divulgation de données personnelles (nom, prénom, adresse postale, téléphone), mais sans impact sur les données bancaires. L'entreprise a immédiatement mobilisé se...
In AWS, deleting and recreating an IAM role results in a new identity that breaks existing trust policies. This behavior improves security by preventing identity spoofing but can cause failures in cross-account access and third-party integrations if not properly understood.
Le 6 mai, le district scolaire de Flemington-Raritan a subi une attaque par ransomware, mais aucune donnée personnelle n’a été confirmée comme compromise et l’enseignement n’a pas été perturbé, hormis une mise hors ligne temporaire les 8 et 9 mai. Les informations sensibles comme les plans d’éducati...
GMA Network a subi une faille de sécurité, mais les données compromises n'étaient pas sensibles. L'entreprise mène une enquête approfondie avec ses partenaires technologiques. GMA Network est déterminée à maintenir l'intégrité et la sécurité de ses opérations.
Ireland’s data protection watchdog accuses the Chinese social media giant of violating GDPR with transfers of European users’ data to China
EIZO Rugged Solutions, Inc. suffered a data breach where an unauthorized party gained access to certain computer systems, acquiring copies of files containing personal information. The attack was claimed under the Play brand on May 12th.
Optima Tax Relief, LLC suffered a data breach between May 1, 2025, and May 6, 2025, resulting in unauthorized access to certain files containing personal information of five Maine residents. The attack was claimed by Chaos on June 6th.
Comparitech observed a significant decline in ransomware attacks in April, partly as a result of the RansomHub gang “going dark”
Talisman Civil Consultants experienced a data breach where an unauthorized party accessed their network, potentially taking personal information. The breach occurred on May 6, 2025. The attack was claimed by Qilin on June 12.
La division Public Safety and Security d'Airbus au Mexique a été victime d'une cyberattaque avec rançongiciel début mai, mais aucune rançon n'a été payée. L'incident a été maîtrisé grâce à la mobilisation des équipes de sécurité et aucun système utilisé par les clients n'a été affecté. L'incident fa...
Recently OpenAI added an additional memory feature called “chat history”, which allows ChatGPT to reference past conversations. The details of the implementation are not known. The documentation highlights that: “It uses this to learn about your interests and preferences, helping make future chats m...
Le 5 mai 2025, Global Crossing Airlines Group Inc. a découvert une activité non autorisée dans ses réseaux et systèmes informatiques, ce qui a été déterminé comme étant le résultat d'un incident de cybersécurité. L'entreprise a activé ses protocoles de réponse aux incidents et a pris des mesures pou...
Qilin. Non revendiqué à date, mais données volées déjà divulguées.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
Liberty Township a été victime d'une attaque de ransomware le 5 mai 2025, entraînant une fuite de données de 48 Go, notamment des informations de connexion en texte brut pour de nombreux sites, y compris des portails sécurisés. Les mots de passe n'étaient pas complexes et ont été réutilisés sur plus...
Infinite Services a subi une attaque de ransomware le 5 mai 2025, lorsqu'un groupe de menace a pu accéder à l'un de ses serveurs, contenant des informations personnelles de patients et d'employés. L'entreprise a choisi de notifier tous les employés et anciens employés potentielllement affectés, leur...
The Model Context Protocol (MCP) is a protocol definition for how LLM apps/agents can leverage external tools. I have been calling it Model Control Protocol at times, because due to prompt injection, MCP tool servers control the client basically.
This post will explain in detail why that is, and I w...
The Institute of Culinary Education suffered a data breach where an unauthorized actor gained access to certain systems and copied files, potentially exposing personal information of some individuals. The incident occurred on or around May 5, 2025. The attack was claimed by Payoutsking, and discover...
South African Airways a subi une attaque informatique majeure qui a perturbé l'accès à ses plateformes en ligne. L'entreprise a réussi à restaurer ses systèmes en quelques heures et a lancé une enquête pour déterminer l'ampleur de l'incident. Les opérations de vol et les canaux de service client ont...