[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 04:00

> Wakefield & Associates, LLC
Wakefield & Associates, LLC experienced an unauthorized access and/or acquisition of certain files within their network, potentially exposing client information. The incident occurred on or before January 17, 2025, and was discovered earlier this year. A cyberattack against Wakefield & Associates wa...
> Multiples vulnérabilités dans SPIP (17 janvier 2025)
De multiples vulnérabilités ont été découvertes dans SPIP SPIP. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).
> OSV-SCALIBR: A library for Software Composition Analysis
Posted by Erik Varga, Vulnerability Management, and Rex Pan, Open Source Security TeamIn December 2022, we announced OSV-Scanner, a tool to enable developers to easily scan for vulnerabilities in their open source dependencies. Together with the open source community, we’ve continued to build this t...
> Middle Eastern Real Estate Fraud Grows with Online Listings
Middle East real estate scams are surging as fraudsters exploit online listings and bypassed due diligence checks
> Trump’s Truth Social Users Targeted by Rampant Scams Online
Truth Social, launched by the Trump Media & Technology Group in 2022, has become a hotspot for scams like phishing and investment fraud
> NZ Incident: New Zealand law firm Bell & Graham confirms ransomware attack | Cyberdaily.au
New Zealand: Law Firm Ransomware Attack, 16 January 2025. New Zealand law firm Bell & Graham confirms SafePay ransomware attack. Claimed stolen 15 gigabytes of data, including legal correspondence and a large amount of identification documents. The post NZ Incident: New Zealand law firm Bell &am...
> Biden Tightens Software Supply Chain Security Requirements Ahead of Trump Takeover
The US President’s second cybersecurity Executive Order will impose stricter security standards on software providers
> DORA Compliance Costs Soar Past €1m for Many UK and EU Businesses
Compliance with the Digital Operational Resilience Act (DORA) has cost many businesses over €1 million, according to research from Rubrik
> Heart Center
Le groupe de cybercriminels DragonForce a revendiqué la responsabilité d'une cyberattaque contre Heart Centre, un réseau de cliniques de cardiologie en Nouvelle-Galles du Sud, en Australie. Cette attaque a entraîné le vol de données sensibles concernant des patients, notamment des diagnostics et des...
> New Hacking Group Leaks Configuration of 15,000 Fortinet Firewalls
The leak likely comes from a zero-day exploit affecting Fortinet’s products
> GoDaddy Accused of Serious Security Failings by FTC
A proposed settlement order from the FTC will require GoDaddy to strengthen its security practices following multiple data breaches at the web hosting giant
> Sportadmin
L'application SportAdmin, utilisée par environ 1 700 clubs de sport en Suède, a été victime d'une cyberattaque qui a pu entraîner la fuite de toutes les données personnelles de ses utilisateurs. L'attaque a été détectée jeudi dernier et le système a été fermé temporairement avant d'être rouvert pour...
> Hackers Use Image-Based Malware and GenAI to Evade Email Security
HP Wolf highlighted novel techniques used by attackers to bypass email protections, including embedding malicious code inside images and utilizing GenAI
> EU To Launch New Support Centre by 2026 to Boost Healthcare Cybersecurity
A new EU action plan will be structured around four pillars: prevention, threat detection and identification, response to cyber-attacks and deterrence
> Pulaski Co. Clerk’s Office
Le bureau du greffier du comté de Pulaski a déclaré avoir récupéré après une cyberattaque. Les détails de l'incident ne sont pas précisés, mais le bureau a confirmé avoir repris ses activités normales. L'enquête sur l'incident est toujours en cours.
> Marlboro-Chesterfield Pathology
Marlboro-Chesterfield Pathology, une entreprise de services de pathologie basée en Caroline du Nord, a conclu un règlement d'une action collective suite à une cyberattaque par ransomware survenue en janvier 2025. L'attaque, attribuée au groupe SafePay, a compromis les données de 235 911 individus, i...
> Startup necromancy: Dead Google Apps domains can be compromised by new owners
Improperly winding down a Google Apps domain can leave logins accessible.
> CISA Launches Playbook to Boost AI Cybersecurity Collaboration
CISA launched the JCDC AI Cybersecurity Playbook to enhance collaboration on AI cybersecurity risks
> Chinese PlugX Malware Deleted in Global Law Enforcement Operation
The FBI deleted Chinese PlugX malware from thousands of devices in the US, using a technique developed by French cybersecurity firm Sekoia.io
> Conduent
L'entreprise de services IT Conduent a été victime d'une cyberattaque, ce qui a entraîné l'interruption de services publics dans plusieurs États américains, affectant des milliers de familles qui dépendent de ces services. L'attaque a été rapidement maîtrisée, mais a nécessité une restauration sécur...