> TODAY'S SUMMARY (16 articles)
Today's cybersecurity landscape highlights several key threats and trends. Attackers exploiting the FortiBleed vulnerability are locking victims out of Fortinet devices by creating new accounts and deleting existing credentials. A critical flaw in Atlassian products allows unauthorized file access, urging immediate patching. The npm package "tensorlake" has been compromised to deliver a credential-stealing worm, raising concerns about supply chain security. Meanwhile, a significant number of vulnerabilities have been discovered and patched in Java libraries by IBM and Red Hat. Additionally, SonicWall has disclosed a severe flaw with a CVSS score of 10, indicating a serious security pattern. Overall, the ongoing risks emphasize the importance of proactive security measures and timely updates in the face of evolving threats.
|
// AI-powered summary generated at 08:00
La société CPI UK, spécialisée dans l'impression de livres, a été victime d'une cyberattaque qui a touché ses systèmes informatiques le 7 février. Les experts techniques ont été appelés pour résoudre le problème et des progrès significatifs ont été réalisés pour restaurer les systèmes. La société s'...
This is the second part of a two three four-part series, which covers some recent results on “verifiable computation” and possible pitfalls that could occur there. This post won’t make much sense on its own, so I urge you to start with the first part. In the previous post we introduced a handful of...
Apple's defenses that protect data from being sent in the clear are globally disabled.
US and Europol dismantle neo-Nazi child abuse network in global crackdown against online exploitation
Patchstack urges admins to patch new WordPress ASE plugin vulnerability that lets users restore previous admin privileges
ESET Cloud Office Security version 532 has been released.
This new independent non-profit was set up by the UK insurance industry to bring more transparency around cyber events
A Bitdefender researcher was targeted by North Korea’s Lazarus with the lure of a fake job offer
Une cyberattaque a touché les systèmes informatiques du comté de Franklin en début de février, mais les données n'ont pas été perdues de manière permanente, selon les responsables. Les systèmes ont été restaurés en moins de 24 heures et des mesures ont été prises pour améliorer la sécurité. L'enquêt...
The UK’s National Cyber Security Centre has published a new set of resources for startups and researchers
Spain’s National Police force has arrested a suspected data thief who targeted government and military victims
Le Bureau d'Investigation Criminelle (CIB) de Taïwan a identifié un hacker chinois de 20 ans, surnommé "Crazyhunter", comme étant responsable d'une attaque ransomware contre l'hôpital MacKay Memorial et d'autres institutions taiwanaises. L'hôpital avait refusé de payer la rançon, et les données des...
Aux alentours du 6 février 2025, un serveur de l'association du barreau a été la cible d'une cyberattaque, ce qui a entraîné une réponse immédiate incluant la sécurisation du réseau, la notification aux autorités et le lancement d'une enquête approfondie. Celle-ci, menée avec l'aide d'experts indépe...
ESET PROTECT On-Prem version 12.0.13.0 has been released and is available to download and update.
Episource LLC a subi une attaque par ransomware qui a affecté plusieurs de ses clients dans le domaine de la santé, entraînant la fuite de données sensibles. L'attaque a été détectée le 6 février 2025 et les systèmes ont été mis hors ligne pour prévenir tout accès non autorisé. Les personnes touchée...
Capital Tax & Consulting LLC experienced a data incident in February 2025, where unauthorized access to their computer systems may have resulted in the acquisition of personal information. The incident occurred from January 30, 2025, through February 6, 2025. The organization is offering free credit...
A new phishing attack by UAC-0006 has been discovered targeting PrivatBank with malicious files in password-protected archives to evade detection
Strategic Retail Partners suffered a data breach between February 3, 2025, and February 6, 2025, resulting in unauthorized access to sensitive information. The breach exposed names, Social Security numbers, driver's license or state identification numbers, and financial account information. The comp...
Strategic Retail Partners experienced unauthorized access to their network between February 3, 2025, and February 6, 2025, resulting in the access and/or copying of sensitive information. The affected information includes names, driver's licenses, Social Security numbers, and other personal data. Th...
Chainalysis found that ransomware payments fell significantly year-over-year despite a recorded increase in the number of ransomware events in 2024