> TODAY'S SUMMARY (15 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Ten leading AI firms have pledged to enhance data protection in response to UK regulatory pressures. Meanwhile, Mozilla removed 16 malicious Firefox extensions designed to steal cryptocurrency recovery phrases and private keys. Citrix has issued an urgent patch for a critical NetScaler vulnerability that could allow remote code execution. The FBI successfully disrupted tools used by the China-linked Flax Typhoon group targeting critical infrastructure. Additionally, the Pwn2Own Ireland hacking contest awarded over $1.2 million for exploits, underscoring the ongoing prevalence of zero-day vulnerabilities. Lastly, a report revealed thousands of unprotected wind and solar park systems across Europe, raising concerns about their cybersecurity posture.
|
// AI-powered summary generated at 08:00
Panaseer's latest cybersecurity study revealed that US companies have paid $155M in data breach lawsuit settlements over just six months
Backslash Security found that naĂŻve prompts resulted in code vulnerable to at least four of the of the 10 most common vulnerabilities across popular LLMs
Look out for AI-generated 'TikDocs' who exploit the public's trust in the medical profession to drive sales of sketchy supplements
MTN Group a confirmé avoir été victime d'une attaque de cybersécurité, mais a insisté sur le fait que ses systèmes principaux, y compris son réseau et ses plateformes de services financiers, n'ont pas été compromis. L'entreprise a activé ses protocoles de réponse à la cybersécurité et a informé les...
Une cyberattaque a touché Swiss Post Cargo Deutschland, affectant environ 1600 clients commerciaux, la société travaille à la stabilisation de ses systèmes et à la mise en place de systèmes de remplacement. Les systèmes de la Poste en Suisse n'ont pas été touchés. Les données des clients ont été vol...
ELENOR-corp ransomware, a new version of Mimic, is targeting healthcare organizations using advanced capabilities
Emera Inc. et Nova Scotia Power ont annoncé une faille de sécurité informatique impliquant un accès non autorisé à certaines parties de leur réseau canadien. Les entreprises ont activé leurs protocoles de réponse aux incidents et de continuité des activités. Il n'y a pas eu de perturbation des opéra...
MDG Design and Construction LLC a été victime d'une attaque de ransomware le 25 avril 2025, ce qui a pu compromettre les informations personnelles de certaines personnes. Les informations qui pourraient avoir été accessibles incluent les noms, les numéros de sécurité sociale, les numéros de permis d...
A misconfigured tracking tool has exposed protected health information of 4.7 million Blue Shield members to Google Ads
On April 25, 2025, Western New York Energy detected an unauthorized third-party access to its network environment, potentially exposing individuals’ first and last names. The company engaged forensic specialists, secured and rebuilt affected systems, notified the FBI, and enhanced its security polic...
A critical path traversal vulnerability in Commvault’s backup and replication solutions has been reported
While the Verizon annual report showed that ransomware is rising, it also found that ransom payments are in decline
Le CPAS de Rebecq a été victime d’une cyberattaque par rançongiciel le 24 avril dernier, les données ont été compromises et une rançon a été exigée pour les restituer. Le CPAS de Rebecq a confirmé l’attaque et les autorités sont probablement en train d’enquêter sur l’incident. Les détails de l’attaq...
NCC Group found that ransomware attacks fell by 32% in March compared to February, but described this finding as a “red herring”
ETSI’s says new technical specification for securing AI models and systems sets international benchmark
La ville d'Ellwangen a été victime d'une attaque de hackers, les systèmes informatiques de la ville ont été touchés, notamment ceux des écoles. Les premières irrégularités ont été détectées le 24 avril. La ville a pris des mesures de sécurité immédiates.
Ofcom’s Protection of Children Codes and Guidance lists 40 new child safety measures for tech firms
An unauthorized third party accessed certain GPEC systems on April 22, 2025, and may have accessed and copied certain files within those systems. The investigation determined that the affected files may have contained personal information, including names and other sensitive data. The breach was con...
After a 180% rise in last year’s report, the exploitation of vulnerabilities continues to grow, now accounting for 20% of all breaches
This post explains how malicious MCP servers can exploit the Model Context Protocol to covertly exfiltrate entire conversation histories by injecting trigger phrases into tool descriptions, allowing for targeted data theft against specific organizations.