> TODAY'S SUMMARY (84 articles)
Today’s cybersecurity landscape reveals several critical threats and trends. A 25-year-old crypto thief was sentenced for a SIM-swapping scheme that stole nearly $260,000. Cisco and Splunk have patched multiple vulnerabilities that could allow unauthorized access or remote code execution. Meanwhile, attackers targeted a critical flaw in Atlassian products, exploiting it within hours of public disclosure. Notably, a Russian-aligned group, UAC-0099, utilized a new infostealer and RAT against Ukrainian personnel. Additionally, reports indicate that thousands of Android devices shipped with pre-installed ad-fraud malware. Finally, the FBI warns of ongoing FortiBleed attacks that lock victims out of their Fortinet devices, emphasizing the evolving nature of cyber threats.
|
// AI-powered summary generated at 16:01
The Alan Turing institute urged government and academia to address systemic cultural and structural security barriers in UK AI research
Starting April 2025, Swiss critical infrastructure organizations will have to report cyber-attacks to the country’s authorities within 24 hours of discovery
Malicious use of AI is reshaping the fraud landscape, creating major new risks for businesses
Software developer Davis Lu cost his employer hundreds of thousands after deploying malware that caused crashes and failed logins
Fortra claims the number of unauthorized Cobalt Strike licenses in the wild fell 80% over two years
La coopérative vitivinicole Moncaro, basée à Montecarotto, a été victime d'une cyberattaque il y a 19 jours, bloquant tous les ordinateurs et les serveurs de l'entreprise. Les données et les archives sont inaccessibles, et les employés doivent utiliser leurs adresses e-mail personnelles pour travail...
Sellmark Corporation experienced a data security incident involving unauthorized access to its computer network, resulting in the theft of personal information of one Maine resident. The incident was discovered on August 14, 2025, and reported to law enforcement. Sellmark implemented additional secu...
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
An unauthorized actor gained access to Johnson-Peltier's computer network and potentially copied a limited number of files containing personal information, including names, Social Security numbers, and financial account information.
La plateforme de billetterie en ligne Aerticket a été victime d'une cyberattaque, entraînant des perturbations techniques. Les détails de l'incident ne sont pas encore disponibles. L'entreprise est probablement en train d'enquêter sur l'incident et de prendre des mesures pour rétablir la sécurité de...
Posted by Dirk GöhmannIn 2024, our Vulnerability Reward Program confirmed the ongoing value of engaging with the security research community to make Google and its products safer. This was evident as we awarded just shy of $12 million to over 600 researchers based in countries around the globe acros...
Yale New Haven Health a subi une violation de données qui a affecté 5,5 millions de patients, les informations personnelles volées incluent les noms complets, les dates de naissance et les numéros de sécurité sociale. L'organisation a embauché Mandiant pour aider à la restauration du système et à l'...
Circle Park experienced a data security incident that may have involved personal information, including names, addresses, and personal health information. The incident occurred on March 8, 2025, and was discovered on the same day. The investigation revealed that an unknown actor accessed and acquire...
Travelers found that ransomware groups are focusing on targeting weak credentials on VPN and gateway accounts for initial access, marking a shift from 2023
AI-driven cyberattacks are rapidly escalating, with a vast majority of security professionals reporting encounters and anticipating a surge, while struggling with detection
La société Crystal D, fournisseur de produits de promotion, a été victime d'une cyberattaque qui a perturbé ses opérations, notamment la communication et les livraisons. Pour l'instant, il n'y a pas d'indice que les hackers aient accédé à des informations sensibles des clients. Les efforts sont en c...
Symantec found that Medusa has listed almost 400 victims on its data leaks site since early 2023, demanding ransom payments as high as $15m
IES Communications, LLC suffered a cybersecurity incident involving a cyber threat actor attempting to deploy ransomware and gain unauthorized access to files containing personal information. The incident was discovered on March 17, 2025, and an investigation is ongoing to determine the full scope o...
Nippon Steel Solutions a été victime d'une attaque informatique, basée sur l'exploitation d'une vulnérabilité 0-day.
An arbitrary file upload vulnerability in the Chaty Pro plugin has been identified, affecting 18,000 WordPress sites