> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights a critical vulnerability in SonicWall's core product, identified as CVE-2026-102255, which has been rated a 10 in severity, indicating an urgent need for patching. Additionally, a ransomware fixer has been accused of defrauding clients by charging them more than the ransom amounts, pocketing the difference instead of providing legitimate decryption services. This underscores ongoing issues with trust and reliability in the cybersecurity space. As these incidents unfold, organizations must remain vigilant and prioritize updates and threat mitigation strategies.
|
// AI-powered summary generated at 04:00
The US has issued sanctions against an individual and a company involved in recent high-profile compromises of government officials by Chinese state-affiliated hackers
CIA analysts Asif William Rahman has pleaded guilty to sharing classified documents about an Israeli attack
La société Apex Custom Software, spécialisée dans les logiciels de santé, a été victime d'une cyberattaque par le groupe de hackers 0mid16B, qui menace de divulguer les données volées si une rançon n'est pas payée. Les hackers affirment avoir accès à des informations sensibles, notamment des données...
At least half a million accounts have been compromised after a breach at hotel management software firm Otelier
La société General Digital Corporation (GDC) a découvert une activité suspecte dans son réseau informatique entre le 10 et le 20 janvier 2025. Une enquête a révélé qu'un acteur non autorisé a accédé au réseau et a pu consulter ou copier certaines informations, notamment des noms et des numéros de sé...
Fundamental Administrative Services LLC suffered a data breach after an unauthorized actor copied certain files from their computer network between October 27, 2024, and January 13, 2025. The breach may have affected personal information, including names, Social Security numbers, driver's license or...
The Supreme Court has upheld a law that could potentially ban TikTok in the US
La filiale Boost d'Ilem a été victime d'une cyberattaque ciblée le 19 janvier 2025, qui a affecté 15% de ses clients. Les équipes d'experts en cybersécurité d'Ilem ont réussi à restaurer les systèmes de plus de 70% des clients affectés en moins de trois jours. Ilem a pris des mesures pour renforcer...
Le prestigieux hôpital El Cruce-Néstor Kirchner a été victime d'une attaque cibernetique il y a six jours, attribuée à un hacker nommé MEDUSA, qui a exploité une vulnérabilité dans le système informatique de l'hôpital. L'attaque a affecté les informations stockées sur les serveurs de l'hôpital, susc...
SecurityScorecard identified a new campaign in which the North Korean Lazarus group aims to steal source code, secrets and cryptocurrency wallet keys from developer environments
Le 19 janvier 2025, le système d'information d'une entreprise a été victime d'une attaque par ransomware. Les mesures de défense ont été mises en place pour contrer l'attaque et récupérer le système, sans impact significatif pour l'instant. L'entreprise va renforcer sa sécurité en intensifiant la su...
Une cyberattaque a touché KAIKATSU FRONTIER Inc., filiale consolidée de AOKI Holdings Inc., et pourrait avoir entraîné une fuite de données personnelles de certains clients. L'incident, détecté le samedi 18 janvier 2025, a conduit à l'isolement immédiat du serveur concerné et à une enquête avec des...
Microsoft highlighted a new Star Blizzard campaign targeting WhatsApp accounts, as the group adapts its TTPs following the takedown of its infrastructure by law enforcement
Le district scolaire du comté de Harrison a été victime d'une cyberattaque le 18 janvier 2025, entraînant un accès non autorisé à certains systèmes informatiques. Les autorités ont immédiatement lancé une enquête et ont engagé des experts en cybersécurité pour évaluer la situation et sécuriser les s...
AliExpress, Shein, Temu, TikTok, WeChat and Xiaomi are accused of operating unlawful data transfers to China
The EU’s DORA regulation is in effect as of January 17, with mixed evidence around compliance levels among financial firms
Recently I came across a fantastic new paper by a group of NYU and Cornell researchers entitled “How to think about end-to-end encryption and AI.” I’m extremely grateful to see this paper, because while I don’t agree with every one of its conclusions, it’s a good first stab at an incredibly importan...
Le lycée Blacon High School, situé dans le Cheshire, a été contraint de fermer temporairement après avoir été victime d'une attaque par rançongiciel. L'établissement sera fermé les 20 et 21 janvier pour permettre à une entreprise de cybersécurité d'enquêter sur la violation de données. La réouvertur...
L'United Domestic Workers of America (UDW) a signalé une violation de données à la suite d'une cyberattaque, qui a permis à une partie non autorisée d'accéder à des informations sensibles de ses membres, notamment leurs noms, numéros de sécurité sociale et adresses. L'UDW a lancé une enquête avec l'...
De multiples vulnérabilités ont été découvertes dans SPIP SPIP. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).