> TODAY'S SUMMARY (15 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Ten leading AI firms have pledged to enhance data protection in response to UK regulatory pressures. Meanwhile, Mozilla removed 16 malicious Firefox extensions designed to steal cryptocurrency recovery phrases and private keys. Citrix has issued an urgent patch for a critical NetScaler vulnerability that could allow remote code execution. The FBI successfully disrupted tools used by the China-linked Flax Typhoon group targeting critical infrastructure. Additionally, the Pwn2Own Ireland hacking contest awarded over $1.2 million for exploits, underscoring the ongoing prevalence of zero-day vulnerabilities. Lastly, a report revealed thousands of unprotected wind and solar park systems across Europe, raising concerns about their cybersecurity posture.
|
// AI-powered summary generated at 08:00
Bastyr University suffered a data breach between April 23, 2025, and April 30, 2025, where certain files were accessed or taken without authorization. The potentially impacted data contained limited information related to individuals, including name and Social Security Number. Bastyr University is p...
Le Réseau de radiologie romand a subi une nouvelle cyberattaque le 30 avril 2025, entraînant le report ou la délocalisation de certains examens. Bien qu'aucune fuite de données ne soit confirmée pour cet incident, l'organisation a déjà été victime d'un vol de données en 2025. Le groupe assure que to...
Google says zero-day threats are trending upward even as total detections fell in 2024.
New WordPress malware disguised as a plugin gives attackers persistent access and injects malicious code enabling administrative control
A new ransomware campaign is automating LockBit deployment via the Phorpiex botnet, according to Cybereason
This post describes attacks using ANSI terminal code escape sequences to hide malicious instructions to the LLM, leveraging the line jumping vulnerability we discovered in MCP.
Administrators of a Telegram channel named CoderSharp have been advertising Gremlin Stealer since March 2025
From the near-demise of MITRE's CVE program to a report showing that AI outperforms elite red teamers in spearphishing, April 2025 was another whirlwind month in cybersecurity
Dvuln researchers highlighted the growing impact of infostealers on the cybercrime landscape, enabling attackers to bypass traditional defenses
Google claims 19% more zero-day bugs were exploited in 2024 than 2022 as threat actors focus on security products
Version française: 🇫🇷 ANSSI and its partners at the Cyber Crisis Coordination Center (C4) have observed informatic attacks conducted by APT28 operators between 2021 and 2024. The attackers are publicly linked to the Russian Federation. The APT28 intrusion set has been used againt various entities...
Europol has launched a new initiative designed to combat recruitment of youngsters into violent organized crime groups
English version : 🇬🇧 L’ANSSI et ses partenaires du Centre de coordination des crises cyber (C4) ont observé entre 2021 et 2024 des attaques informatiques conduites par les opérateurs d’APT28, qui sont publiquement rattachés par différentes sources à la Russie. Le mode opératoire d’attaque APT28 a...
Mount Rogers Community Services detected a ransomware attack on April 29, 2025, which began around April 27, 2025, allowing unauthorized access to its systems. Impacted data may include personal health, demographic, billing, and insurance information. Mount Rogers is working with law enforcement and...
The provided text appears to be a mix of characters and does not contain any information about a specific data breach. It seems to be a jumbled collection of characters and does not provide any details about the victim, breach summary, or date discovered.
Members of the World Uyghur Congress living in exile were targeted with a spear phishing campaign deploying surveillance malware, according to the Citizen Lab
Episciences experienced a data breach between April 27, 2025, and April 29, 2025, where an unauthorized actor gained access to certain files within their network, potentially copying files containing name and Social Security Number. The breach was discovered on April 29, 2025, and Episciences notifi...
50% of mobile devices run outdated operating systems, increasing vulnerability to cyber-attacks, according to the latest report from Zimperium
According to the 2025 Global Threat Landscape Report from FortiGuard, threat actors are executing 36,000 scans per second
New ChoiceJacking attack allows malicious chargers to steal data from phones.