> TODAY'S SUMMARY (16 articles)
Today's cybersecurity landscape highlights several key threats and trends. Attackers exploiting the FortiBleed vulnerability are locking victims out of Fortinet devices by creating new accounts and deleting existing credentials. A critical flaw in Atlassian products allows unauthorized file access, urging immediate patching. The npm package "tensorlake" has been compromised to deliver a credential-stealing worm, raising concerns about supply chain security. Meanwhile, a significant number of vulnerabilities have been discovered and patched in Java libraries by IBM and Red Hat. Additionally, SonicWall has disclosed a severe flaw with a CVSS score of 10, indicating a serious security pattern. Overall, the ongoing risks emphasize the importance of proactive security measures and timely updates in the face of evolving threats.
|
// AI-powered summary generated at 08:00
Amazon Web Services has launched its Cyber Education Grant Program in the UK
Crazy Evil, a group of crypto scammers, exploit NFTs and cryptocurrencies with malware targeting influencers and tech professionals
Australian Not-for-Profit Ransomware Attack, 24 January 2025: New South Wales: Space Bears ransomware gang claims hack of Not-for-Profit provider Christian Community Aid. Compromised data reportedly includes various file types such as .jpg, .mp4, .mov, .xls, .doc, .mdf, .msg, and pdf.
The post Incid...
A new FBI advisory warned that North Korean IT worker schemes have escalated their activities in recent months to include data extortion
SentinelOne researchers highlighted similarities in the approaches used by the HellCat and Morpheus ransomware groups, suggesting shared infrastructure
Threat insights from Datadog Security Labs for Q4 2024.
Le développeur de jeux polonais Big Cheese Studio a été victime d'une attaque informatique vendredi matin, qui a entraîné la mise hors ligne de son site web et la compromission de son code de jeu et des données personnelles de ses employés. Les hackers menacent de rendre publiques ces informations s...
Le comté de Matagorda, au Texas, a déclaré l'état de catastrophe après qu'une cyberattaque a perturbé ses systèmes internes, mais il n'y a pas encore de preuve que des données personnelles de résidents aient été compromises. Les autorités locales enquêtent sur l'incident avec l'aide de plusieurs age...
Posted by Jianing Sandra Guo, Product Manager, Android, Nataliya Stanetsky, Staff Program Manager, Android
Today, people around the world rely on their mobile devices to help them stay connected with friends and family, manage finances, keep track of healthcare information and more – all from the...
Threat actors chained Ivanti CSA vulnerabilities for RCE, credential theft & webshell deployment
Arbitrage betting fraud rises, forcing bookmakers to adopt stricter measures against automated scams
While Trail of Bits is known for developing security tools like Slither, Medusa, and Fickling, our engineering efforts extend far beyond our own projects. Throughout 2024, our team has been deeply engaged with the broader security ecosystem, tackling challenges in open-source tools and infrastructur...
Splunk reveals that 82% of CISOs now report directly to the CEO, but many lack EQ
The network equipment giant urged customers to patch immediately
Le Panorama de la cybercriminalité du Clusif revient le 23 janvier 2025. Cette conférence sera accessible à la fois en présentiel (déjà complet) et également en streaming en accès libre depuis notre site ! La conférence vous propose un bilan de la cybercriminalité avec les événements marquants ainsi...
Cybercriminals are selling access to the malicious GenAI chatbot via Telegram, providing rapid assistance for a range of nefarious activities, according to Abnormal Security
President Trump has pardoned the founder of original dark web marketplace Silk Road
Le 23 janvier 2025, une entreprise a été victime d'une cyberattaque, détectée par son système de détection, et a immédiatement pris des mesures pour contenir l'impact, notamment en déconnectant son réseau et en faisant appel à des experts en cybersécurité. L'enquête n'a pas révélé d'impact financier...
Alpha Baking Co., Inc. a découvert une activité anormale sur son réseau informatique le 23 janvier 2025, qui a conduit à une enquête approfondie. Il a été déterminé qu'un tiers non autorisé a obtenu des fichiers contenant des informations personnelles, dont certaines appartiennent à vous. L'attaque...
PlushDaemon APT hacked South Korean VPN software with SlowStepper backdoor as part of a 2023 espionage campaign