> TODAY'S SUMMARY (84 articles)
Today’s cybersecurity landscape reveals several critical threats and trends. A 25-year-old crypto thief was sentenced for a SIM-swapping scheme that stole nearly $260,000. Cisco and Splunk have patched multiple vulnerabilities that could allow unauthorized access or remote code execution. Meanwhile, attackers targeted a critical flaw in Atlassian products, exploiting it within hours of public disclosure. Notably, a Russian-aligned group, UAC-0099, utilized a new infostealer and RAT against Ukrainian personnel. Additionally, reports indicate that thousands of Android devices shipped with pre-installed ad-fraud malware. Finally, the FBI warns of ongoing FortiBleed attacks that lock victims out of their Fortinet devices, emphasizing the evolving nature of cyber threats.
|
// AI-powered summary generated at 16:01
Fastly found that organizations have introduced changes such as increasing CISO participation in strategic decisions in response to growing personal liability risks
Continuing their trend of radical change for the better, Let's Encrypt have announced that, this year, you will be able to request certificates with a validity period of only 6 days!Let's EncryptI remember sitting in the room for this DEF CON 23 panel discussion
CISA has added five more CVEs into its known exploited vulnerabilities catalog
Sumsub research finds European iGaming market is losing billions to fraud each year
Les Stadtwerke Schwerte, une entreprise de services publics en Allemagne, a été victime d'une cyberattaque, ce qui a des conséquences pour ses clients. Les autorités ont été informées de l'incident. Les détails sur l'impact de l'attaque et les mesures prises pour y remédier ne sont pas encore connus...
Le 4 mars 2025, les systèmes d'information de la filiale Unikorn du groupe Ennostar ont été attaqués par des pirates, mais grâce à la mise en œuvre du mécanisme de défense, l'incident n'a pas affecté les opérations de l'entreprise. Les mesures préventives sont actuellement mises en place et les site...
Phishing attack exploits social engineering techniques alongside Microsoft Teams and remote access software to deploy BackConnect malware
Le groupe hôtelier Adina Hotels fait face à une cyberattaque qui affecte ses réseaux, mais refuse de dévoiler les détails de l'incident. Les équipes hôtelières travaillent à restaurer les systèmes et à assurer la prise en charge manuelle des clients, tandis que les lignes téléphoniques sont redirigé...
Le 4 mars 2025, une activité non autorisée a été détectée sur les systèmes informatiques de Woods Hole Group (WHG), ce qui a conduit à interrompre certains services par précaution et à lancer une enquête avec des experts externes, tout en avisant les autorités compétentes. Des fichiers contenant des...
The US Cybersecurity and Infrastructure Security Agency confirmed it will keep defending against Russian cyber threats to US critical infrastructure
Harper Executive Group experienced a network disruption that led to unauthorized access or acquisition of certain information within their systems. The incident occurred on or around March 3, 2025, and was discovered on January 14, 2026. The affected information may have included first and last name...
A new phishing campaign has been identified using Havoc to control infected systems, leveraging SharePoint and Microsoft Graph API
Telecoms provider Vodafone has developed the new proof of concept with IBM, as it seeks to implement post-quantum cryptography ahead of anticipated quantum-based attacks
Take a moment to think beyond our current capabilities and consider what might come next in the grand story of evolution
The Information Commissioner’s Office is now investigating how TikTok uses 13–17-year-olds’ personal information
Threat actors are exploiting a zero-day bug in Paragon Partition Manager's BioNTdrv.sys driver during ransomware attacks
You and your team should incrementally update your threat model as your system changes, integrating threat modeling into each phase of your SDLC to create a Threat and Risk Analysis Informed Lifecycle (TRAIL). Here, we cover how to do that: how to further tailor the threat model we built, how to mai...
L'hôpital Whitman et les cliniques médicales de Colfax ont été victimes d'une cyberattaque, qui a mis hors service leurs systèmes informatiques internes. La cyberattaque a été détectée vendredi et une entreprise de cybersécurité travaille actuellement pour résoudre le problème. L'hôpital et les clin...
La ville de Mission au Texas a été victime d'une cyberattaque qui a forcé la fermeture de ses systèmes informatiques, laissant les policiers sans accès aux bases de données de l'État pour vérifier les plaques d'immatriculation et les permis de conduire. Les détails de l'incident, notamment la façon...
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...