> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights a critical vulnerability in SonicWall's core product, identified as CVE-2026-102255, which has been rated a 10 in severity, indicating an urgent need for patching. Additionally, a ransomware fixer has been accused of defrauding clients by charging them more than the ransom amounts, pocketing the difference instead of providing legitimate decryption services. This underscores ongoing issues with trust and reliability in the cybersecurity space. As these incidents unfold, organizations must remain vigilant and prioritize updates and threat mitigation strategies.
|
// AI-powered summary generated at 04:00
Wakefield & Associates, LLC experienced an unauthorized access and/or acquisition of certain files within their network, potentially exposing client information. The incident occurred on or before January 17, 2025, and was discovered earlier this year. A cyberattack against Wakefield & Associates wa...
De multiples vulnérabilités ont été découvertes dans SPIP SPIP. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).
Posted by Erik Varga, Vulnerability Management, and Rex Pan, Open Source Security TeamIn December 2022, we announced OSV-Scanner, a tool to enable developers to easily scan for vulnerabilities in their open source dependencies. Together with the open source community, we’ve continued to build this t...
Middle East real estate scams are surging as fraudsters exploit online listings and bypassed due diligence checks
Truth Social, launched by the Trump Media & Technology Group in 2022, has become a hotspot for scams like phishing and investment fraud
New Zealand: Law Firm Ransomware Attack, 16 January 2025. New Zealand law firm Bell & Graham confirms SafePay ransomware attack. Claimed stolen 15 gigabytes of data, including legal correspondence and a large amount of identification documents.
The post NZ Incident: New Zealand law firm Bell &am...
The US President’s second cybersecurity Executive Order will impose stricter security standards on software providers
Compliance with the Digital Operational Resilience Act (DORA) has cost many businesses over €1 million, according to research from Rubrik
Le groupe de cybercriminels DragonForce a revendiqué la responsabilité d'une cyberattaque contre Heart Centre, un réseau de cliniques de cardiologie en Nouvelle-Galles du Sud, en Australie. Cette attaque a entraîné le vol de données sensibles concernant des patients, notamment des diagnostics et des...
The leak likely comes from a zero-day exploit affecting Fortinet’s products
A proposed settlement order from the FTC will require GoDaddy to strengthen its security practices following multiple data breaches at the web hosting giant
L'application SportAdmin, utilisée par environ 1 700 clubs de sport en Suède, a été victime d'une cyberattaque qui a pu entraîner la fuite de toutes les données personnelles de ses utilisateurs. L'attaque a été détectée jeudi dernier et le système a été fermé temporairement avant d'être rouvert pour...
HP Wolf highlighted novel techniques used by attackers to bypass email protections, including embedding malicious code inside images and utilizing GenAI
A new EU action plan will be structured around four pillars: prevention, threat detection and identification, response to cyber-attacks and deterrence
Le bureau du greffier du comté de Pulaski a déclaré avoir récupéré après une cyberattaque. Les détails de l'incident ne sont pas précisés, mais le bureau a confirmé avoir repris ses activités normales. L'enquête sur l'incident est toujours en cours.
Marlboro-Chesterfield Pathology, une entreprise de services de pathologie basée en Caroline du Nord, a conclu un règlement d'une action collective suite à une cyberattaque par ransomware survenue en janvier 2025. L'attaque, attribuée au groupe SafePay, a compromis les données de 235 911 individus, i...
Improperly winding down a Google Apps domain can leave logins accessible.
CISA launched the JCDC AI Cybersecurity Playbook to enhance collaboration on AI cybersecurity risks
The FBI deleted Chinese PlugX malware from thousands of devices in the US, using a technique developed by French cybersecurity firm Sekoia.io
L'entreprise de services IT Conduent a été victime d'une cyberattaque, ce qui a entraîné l'interruption de services publics dans plusieurs États américains, affectant des milliers de familles qui dépendent de ces services. L'attaque a été rapidement maîtrisée, mais a nécessité une restauration sécur...