> TODAY'S SUMMARY (51 articles)
Today's cybersecurity news highlights several significant threats and trends. The FBI has issued warnings about ongoing FortiBleed attacks, where attackers can lock organizations out of their own Fortinet firewalls, indicating a serious vulnerability for admins. In AI developments, Anthropic's new model is reportedly better at identifying vulnerabilities, while a Chinese hacker successfully utilized AI tools to breach South Korean banks. Additionally, there has been a rise in sophisticated phishing kits that include advanced session management features, targeting banking and government sectors across multiple regions. A critical vulnerability in Atlassian products is currently being exploited, and a recent ransomware recovery scheme has revealed fraudulent practices, underscoring the ongoing challenges in cybersecurity integrity.
|
// AI-powered summary generated at 12:00
On February 26, 2025, Vitenas Cosmetic Surgery, PA detected an unauthorized attempt to infiltrate its computer network and launched a forensic investigation, which concluded on March 28, 2025. The investigation determined that some patient data—including names, dates of birth, Social Security number...
DermCare Management, une société de gestion de pratiques médicales basée en Floride, a subi une faille de sécurité qui a affecté plusieurs pratiques de dermatologie. Les informations personnelles et médicales de patients ont pu être compromises. L'enquête est toujours en cours pour déterminer l'éten...
Posted by Alex Rebert, Security Foundations, Ben Laurie, Research, Murali Vijayaraghavan, Research and Alex Richardson, SiliconFor decades, memory safety vulnerabilities have been at the center of various security incidents across the industry, eroding trust in technology and costing billions. Tradi...
61% of hackers use new exploit code within 48 hours, ransomware remains top threat in 2024
Ghostwriter cyber-attack targets Ukrainian, Belarusian opposition using weaponized Excel documents
In today’s rapidly evolving digital landscape, securing web applications at scale is a challenge, even for the most well-resourced organizations. Large enterprises operate thousands of applications an
Forescout observed the recently identified Chinese hacking group using medical imaging software applications to deliver malware
ReliaQuest claims 80% of ransomware attacks now focus solely on exfiltrating data as it is faster
In this blog, we’ll talk about one of our most popular, but rarely published report types and how adding threat modeling to your organization can save you from becoming the next billion-dollar headline.
SecurityScorecard revealed that the large-scale password spraying campaign can bypass MFA and security access policies by utilizing Non-interactive sign-ins
New Hiya data finds 26% of UK consumers encountered a deepfake scam call in Q4 2024
La ville de Fort St. John au Canada a été victime d'une cyberattaque qui a fortement impacté les services municipaux. Les équipes de la ville ont réagi rapidement en isolant les systèmes pour limiter l'activité non autorisée et une équipe d'intervention en cas de cyberincident a été activée pour éva...
O'Neill Wetsuits, L.L.C. a subi une faille de sécurité informatique entre le 23 et le 25 février 2025, entraînant l'accès non autorisé à certaines informations personnelles. L'entreprise a pris des mesures pour sécuriser ses systèmes et a engagé des experts en cybersécurité pour enquêter sur l'incid...
Elementor plugin flaw puts 2m WordPress websites at risk, allowing XSS attacks via malicious scripts
Genex Services, LLC experienced a data security incident due to a phishing attack that compromised the laptops of two employees, potentially affecting personal information. The incident was discovered on February 25, 2025. Genex is notifying all individuals whose information was potentially impacted...
All Star Recruiting Locums, LLC notified customers of a data breach that occurred on or around February 25, 2025, where an unauthorized third party may have accessed personal information. The attack was claimed under the RansomHub brand on March 21st, 2025.
Michigan man indicted for dark web credential fraud, purchased 2,500 logins from Genesis Market
An unauthorized party gained access to BCNYS internal systems from February 24, 2025, to February 25, 2025, potentially exposing personal information. The breach was discovered on August 4, 2025. BCNYS is offering complimentary credit monitoring to affected individuals.
Rogin Nassau LLC experienced a data security incident where some personal information may have been viewed or acquired without authorization. The incident occurred on February 25, 2025, and was discovered on August 21, 2025. The company is providing complimentary credit and identity monitoring servi...
Google Cloud's Key Management Service now features quantum-safe digital signatures to strengthen data integrity and prepare for emerging quantum computing challenges