> TODAY'S SUMMARY (16 articles)
Today's cybersecurity landscape highlights several key threats and trends. Attackers exploiting the FortiBleed vulnerability are locking victims out of Fortinet devices by creating new accounts and deleting existing credentials. A critical flaw in Atlassian products allows unauthorized file access, urging immediate patching. The npm package "tensorlake" has been compromised to deliver a credential-stealing worm, raising concerns about supply chain security. Meanwhile, a significant number of vulnerabilities have been discovered and patched in Java libraries by IBM and Red Hat. Additionally, SonicWall has disclosed a severe flaw with a CVSS score of 10, indicating a serious security pattern. Overall, the ongoing risks emphasize the importance of proactive security measures and timely updates in the face of evolving threats.
|
// AI-powered summary generated at 08:00
This blog post highlights key points from our new white paper Preventing Account Takeovers on Centralized Cryptocurrency Exchanges, which documents ATO-related attack vectors and defenses tailored to CEXes. Imagine trying to log in to your centralized cryptocurrency exchange (CEX) account and your p...
Indian banking malware attack exposes 50,000 users, stealing financial data via SMS interception and phishing
The UK and its Five Eyes partners have launched new security guidance for edge device manufacturers and network defenders
Don’t wait for a costly breach to provide a painful reminder of the importance of timely software patching
Check Point has observed cybercriminals toy with Alibaba’s Qwen LLM to develop infostealers
Contrast Security reveals a 12.5% annual increase in destructive cyber-attacks on banks
Le groupe d'ingénierie IMI a été victime d'une cyberattaque, qui a touché plusieurs de ses sites à travers le monde, et a isolé certaines de ses systèmes pour enquêter et contenir l'incident. L'entreprise a informé ses employés et clients de l'incident, mais a refusé de divulguer les données qui ont...
Une cyberattaque a perturbé le système de dispatch de REMSA Health, mais les responsables ont affirmé que les soins aux patients n'ont pas été affectés. Les employés ont été invités à ne pas utiliser leurs ordinateurs en raison de la prudence, mais le système d'urgence 911 et les services de télépho...
Trigger warning: incredibly wonky theoretical cryptography post (written by a non-theorist)! Also, this will be in two parts. I plan to be back with some more thoughts on practical stuff, like cloud backup, in the near future. If you’ve read my blog over the years, you should understand that I have...
La société japonaise de télécommunications NTT Communications a subi une cyberattaque qui a compromis les informations de 18 000 clients entreprises, notamment des noms, des numéros de téléphone, des adresses e-mail et des informations de service. La brèche de sécurité a été découverte le 5 février...
Début février, l'entreprise de construction Nijhuis Bouw, basée à Rijssen, a été victime d'une cyberattaque et retenue en otage par des cybercriminels pendant cinq jours. L'entreprise a décidé de payer une rançon, tandis que les données de milliers de locataires de cinquante organismes de logement p...
ESET Mail Security for Microsoft Exchange Server version 11.1.10010.0 and ESET Security for Microsoft SharePoint Server version 11.1.15007.0 have been released and are available for download from the ESET website or upgrade from ESET PROTECT repositories.
Le 5 février 2025, la Charleston School of Law a découvert qu'un tiers non autorisé avait accédé à son réseau interne, compromettant potentiellement des fichiers contenant des informations personnelles. Après enquête, il a été confirmé que des données telles que les noms complets et potentiellement...
Riverdale Country School, Inc. experienced a sophisticated cyber-attack that may have accessed or taken certain information on February 6, 2025. The information that could have been subject to unauthorized access includes name and Social Security number. The cyberattack was claimed by Qilin on Febru...
DaggerFly’s Lunar Peek campaign is using a new malware strain, identified by FortiGuard Labs, to compromise Linux networks
Picus Security reports infostealer surge after revealing credentials appear in 29% of malware
Left unchecked, AI's energy and carbon footprint could become a significant concern. Can our AI systems be far less energy-hungry without sacrificing performance?
A sophisticated phishing campaign targeting Microsoft ADFS has been observed, affecting more than 150 organizations
Check Point Research has found over 10 million stolen credentials associated with EMEA organizations exposed on cybercrime markets
Updated AU Incident - Education Cyber Attack, 04 February 2025: The University of Notre Dame Australia in Western Australia confirms cyber incident. Claims are that 62.3 Gb of data was exfiltrated. Containing employee and student contact data, medical documents, confidential agreements and licenses....