> TODAY'S SUMMARY (51 articles)
Today's cybersecurity news highlights several significant threats and trends. The FBI has issued warnings about ongoing FortiBleed attacks, where attackers can lock organizations out of their own Fortinet firewalls, indicating a serious vulnerability for admins. In AI developments, Anthropic's new model is reportedly better at identifying vulnerabilities, while a Chinese hacker successfully utilized AI tools to breach South Korean banks. Additionally, there has been a rise in sophisticated phishing kits that include advanced session management features, targeting banking and government sectors across multiple regions. A critical vulnerability in Atlassian products is currently being exploited, and a recent ransomware recovery scheme has revealed fraudulent practices, underscoring the ongoing challenges in cybersecurity integrity.
|
// AI-powered summary generated at 12:00
Microsoft found that Russian state actor Seashell Blizzard has deployed an initial access subgroup to gain persistent access in a range of high-value global targets
The Electronic Frontier Foundation has requested a US federal court to block Elon Musk’s DOGE access to US Office of Personnel Management Data
The virtual treasure chests and other casino-like rewards inside your children’s games may pose risks you shouldn’t play down
SecurityScorecard has uncovered a sophisticated campaign linked to North Korea’s Lazarus Group, distributing crypto-stealing malware
NZ Incident - Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries l...
L'entreprise allemande Eckert & Ziegler SE a été victime d'une cyberattaque qui a touché certaines parties de ses systèmes d'information. Les systèmes ont été temporairement mis hors ligne pour minimiser les effets de l'attaque et une task-force a été mise en place pour restaurer le fonctionnement n...
L'Université de la Bundeswehr à Munich a été victime d'une attaque de hackers, mais les réseaux de la Bundeswehr ne sont pas affectés. Les attaquants ont réussi à accéder à un service IT central du centre de données, mais selon les informations actuelles, aucune donnée n'a été supprimée ou chiffrée...
He now faces four years in federal prison.
Le 13 février, la Ville a été victime d'un incident de cybersécurité et a immédiatement mis ses systèmes informatiques hors ligne pour limiter les risques. Aucune preuve d'utilisation abusive des données sensibles n'a été trouvée, et les experts en cybersécurité travaillent à restaurer les services...
Une cyberattaque a eu lieu contre les écoles publiques de Baltimore, entraînant la fuite de données sensibles de milliers d'élèves et d'employés. Les informations volées incluent des numéros de sécurité sociale, des permis de conduire et des adresses. Le district scolaire offre deux ans de surveilla...
I’m supposed to be finishing a wonky series on proof systems (here and here) and I promise I will do that this week. In the midst of this I’ve been a bit distracted by world events. Last week the Washington Post published a bombshell story announcing that the U.K. had filed “technical capability not...
Bell Ambulance, Inc. a signalé une faille de sécurité dans ses données, les informations personnelles de certains individus ont pu être compromises, l'entreprise prend des mesures pour sécuriser son réseau et avertir les personnes potentiellement touchées. Les informations compromises incluent les n...
Le 13 février 2025, un incident de cybersécurité a été découvert, impliquant une tentative de perturbation des systèmes de l’entreprise par un acteur malveillant, probablement dans le but de déployer un ransomware et d’exiger une rançon. Dès la détection, l’accès non autorisé a été interrompu, les s...
NCSC CTO Ollie Whitehouse discussed a UK government-backed project designed to secure underlying computer hardware, preventing most vulnerabilities from occurring
DJH Services LLC informe qu’un incident de cybersécurité a touché les réseaux des entreprises DJH, entraînant un accès non autorisé à certaines données personnelles entre le 7 et le 13 février 2025. Dès la détection de l’intrusion, DJH a sécurisé ses systèmes, lancé une enquête approfondie avec des...
Baltimore City Public Schools a subi une faille de sécurité informatique le 13 février 2025, qui a entraîné la fuite de certaines informations personnelles. Les personnes concernées sont invitées à prendre des mesures pour protéger leur identité et leur crédit, notamment en utilisant les services de...
Romance scams cost Americans $697.3m in 2024, with crypto fraud schemes on the rise
Terra Holdings, LLC suffered a data breach between February 11, 2025, and February 13, 2025, where certain files were accessed or taken without authorization. The breach involved sensitive information, including names and other types of data. Terra Holdings is offering complimentary credit monitorin...
Terra Holdings, LLC suffered a data breach where unauthorized access to files containing names and Social Security numbers occurred between February 11, 2025, and February 13, 2025. The breach was discovered on February 13, 2025, but the affected individuals were not notified until May 8, 2026. Terr...
Writing smart contracts requires a higher level of security assurance than most other fields of software engineering. The industry has evolved from simple ERC20 tokens to complex, multi-component DeFi systems that leverage domain-specific algorithms and handle significant monetary value. This evolut...