[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> WK Kellogg Confirms Data Breach Tied to Cleo Software Exploit
WK Kellogg breach exposed employee data after attackers exploited flaws in Cleo software
> Precision-Validated Phishing Elevates Credential Theft Risks
New phishing method targets high-value accounts using real-time email validation
> Introducing a new section on snapshot fuzzing for kernel-level testing in the Testing Handbook
Snapshot Fuzzing enables security engineers to effectively test software that is traditionally difficult to analyze, such as kernels, secure monitors, and other complex targets that require non-trivial setup. Whether you’re auditing drivers or other kernel-mode components, including antivirus softwa...
> Ransomware Attacks Hit All-Time High as Payoffs Dwindle
While ransomware attack claims are at an all-time high, financial losses from actual attacks may be reducing
> Three-Quarters of IT Leaders Fear Nation-State AI Cyber Threats
73% of respondents in an Armis survey said they worried about nation-state actors using AI for cyber-attacks
> So your friend has been hacked: Could you be next?
When a ruse puts on a familiar face, your guard might drop, making you an easy mark. Learn how to tell a friend apart from a foe.
> Microsoft Fixes Over 130 CVEs in April Patch Tuesday
Microsoft has issued security updates to fix 130+ vulnerabilities this month, including one zero-day
> NCSC Warns of Spyware Targeting Chinese and Taiwanese Diaspora
The UK and allies have warned of new mobile spyware targeting Uyghur, Tibetan and Taiwanese communities
> SIAPA (Sistema Intermunicipal de los Servicios de Agua Potable y Alcantarillado)
Le système intermunicipal des services d'eau potable et d'assainissement (SIAPA) a été victime d'une cyberattaque qui a paralysé ses services administratifs, obligeant l'organisme à activer ses protocoles de sécurité et à signaler l'incident à la Fiscalía del Estado. Pendant la résolution de la situ...
> Nippon Life India Asset Management Limited
La société Nippon Life India Asset Management Limited, l'un des plus grands gestionnaires d'actifs en Inde, a signalé une cyberattaque sur son infrastructure IT le 9 avril. La société a pris des mesures immédiates pour enquêter et répondre à l'incident, y compris la fermeture des systèmes affectés p...
> Google Releases April Android Update to Address Two Zero-Days
Google’s latest Android update fixes 62 flaws, including two zero-days previously used in limited targeted attacks
> Bertie County Schools
Le 17 avril, une cyberattaque contre les écoles du comté de Bertie, en Caroline du Nord, a été revendiquée sur le site vitrine de l'enseigne de rançongiciel Qilin. Le 9 avril, les écoles annonçaient, sur leur page Facebook, l'indisponibilité de leur système de téléphonie et de leurs accès à Internet...
> ESET Endpoint Encryption version 5.4.14.0 has been released
ESET Endpoint Encryption version 5.4.14.0 has been released.
> NIST Defers Pre-2018 CVEs to Tackle Growing Vulnerability Backlog
NIST marks CVEs pre-2018 as “Deferred” in the NVD as agency focus shifts to managing emerging threats
> ESET Security for Microsoft SharePoint Server version 12.0.15004.0 has been released
ESET Security for Microsoft SharePoint Server version 12.0.15004.0 has been released and is available for download.
> Half of Firms Stall Digital Projects as Cyber Warfare Risk Surges
Armis survey reveals that the growing threat of nation-state cyber-attacks is disrupting digital transformation
> CISA Warns of CrushFTP Vulnerability Exploitation in the Wild
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-31161 to its Known Exploited Vulnerabilities (KEV) catalog
> 1 billion reasons to protect your identity online
Corporate data breaches are a gateway to identity fraud, but they’re not the only one. Here’s a lowdown on how your personal data could be stolen – and how to make sure it isn’t.
> Boards Urged to Follow New Cyber Code of Practice
The British government has launched a new code of practice designed to boost corporate cyber governance
> LDAP Clear-text credentials retrievable with IP modification
CVSSv3 Score: 2.1 An insufficiently protected credentials [CWE-522] vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server....