> TODAY'S SUMMARY (16 articles)
Today's cybersecurity landscape highlights several key threats and trends. Attackers exploiting the FortiBleed vulnerability are locking victims out of Fortinet devices by creating new accounts and deleting existing credentials. A critical flaw in Atlassian products allows unauthorized file access, urging immediate patching. The npm package "tensorlake" has been compromised to deliver a credential-stealing worm, raising concerns about supply chain security. Meanwhile, a significant number of vulnerabilities have been discovered and patched in Java libraries by IBM and Red Hat. Additionally, SonicWall has disclosed a severe flaw with a CVSS score of 10, indicating a serious security pattern. Overall, the ongoing risks emphasize the importance of proactive security measures and timely updates in the face of evolving threats.
|
// AI-powered summary generated at 08:00
Cisco Talos found that exploitation of public-facing applications made up 40% of incidents it observed in Q4 2024, marking a notable shift in initial access techniques
The Indian tech giant temporarily suspended some of its IT services, which have now been restored
La sociĂ©tĂ© Tata Technologies a confirmĂ© avoir Ă©tĂ© victime d'une attaque par ransomware, qui a entraĂźnĂ© la suspension temporaire de certains services IT. Les services de livraison aux clients ont toutefois Ă©tĂ© maintenus et n'ont pas Ă©tĂ© affectĂ©s. Une enquĂȘte approfondie est en cours pour dĂ©terminer l...
Cyber reports exposed major security flaws in DeepSeekâs R1 LLM
A global law enforcement operation has taken down infrastructure used by Cracked.io and Nulled.io, which provide cybercriminal tools and services
Le Service d'enregistrement des entreprises (BRS) du Kenya a assurĂ© que la sĂ©curitĂ© et l'intĂ©gritĂ© de son registre Ă©taient sa prioritĂ© absolue aprĂšs des rapports d'une Ă©ventuelle violation de donnĂ©es. L'agence a lancĂ© une enquĂȘte approfondie et a mis en place des mesures de sĂ©curitĂ© renforcĂ©es pour...
WEL Companies, Inc. experienced a data security incident where certain data stored on its network may have been accessed or acquired without authorization. The incident occurred on January 31, 2025, and affected personal information of 515 Maine residents. An attack against WEL Companies was claimed...
Google Play blocked 2.36 million policy-violating apps and banned 158,000 harmful developer accounts in 2024
HTTP client tools used to compromise Microsoft 365 environments with 78% of tenants targeted in 2024
ESET PROTECT HUB version 1.9.3 was released Monday, January 27.
New âContent Credentialsâ guidance from the NSA seeks to counter the erosion of trust.
PyPI now supports marking projects as archived. Project owners can now archive their project to let users know that the project is not expected to receive any more updates. Project archival is a single piece in a larger supply-chain security puzzle: by exposing archival statuses, PyPI enables downst...
SquareX researchers warn that browser syncjacking could lead to full browser and device hijacking
Researchers at Wiz uncovered a publicly accessible database belonging to Chinese GenAI provider DeepSeek that leaked sensitive data, including chat history
L'Université de Notre Dame en Australie a publié un communiqué concernant les cookies utilisés sur son site web, détaillant les différents types de cookies, leur durée de stockage et leur fonctionnalité. Les cookies sont utilisés pour tracker l'interaction des utilisateurs avec le contenu intégré, n...
New York Blood Center Enterprises revealed that it has been hit by a ransomware attack, disrupting activities and blood drives at its centers across the country
UK organizations are significantly increasing cybersecurity budgets, with a projected 31% growth in the next year
Le conseil scolaire enquĂȘte sur une Ă©ventuelle cyberattaque. Aucun dĂ©tail supplĂ©mentaire n'a Ă©tĂ© fourni sur l'incident. L'enquĂȘte est en cours pour dĂ©terminer si des donnĂ©es ont Ă©tĂ© compromises.
The UKâs National Cyber Security Centre has released a new paper making it easier to assess if a flaw is âunforgivableâ
Le 30 janvier 2025, la filiale Unimicron Technology (ShenZhen) Corp. a été victime d'une attaque par ransomware. L'entreprise a collaboré avec une équipe de forensique cybernétique externe pour analyser l'incident et mettre en place des mesures de défense. L'impact sur les opérations de l'entreprise...