> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights a critical vulnerability in SonicWall's core product, identified as CVE-2026-102255, which has been rated a 10 in severity, indicating an urgent need for patching. Additionally, a ransomware fixer has been accused of defrauding clients by charging them more than the ransom amounts, pocketing the difference instead of providing legitimate decryption services. This underscores ongoing issues with trust and reliability in the cybersecurity space. As these incidents unfold, organizations must remain vigilant and prioritize updates and threat mitigation strategies.
|
// AI-powered summary generated at 04:00
Chainalysis estimates threat actors made at least $51bn through crypto crime in 2024
The security provider published mitigation measures to prevent exploitation
L'entreprise de services IT Conduent a été victime d'une cyberattaque, ce qui a entraîné l'interruption de services publics dans plusieurs États américains, affectant des milliers de familles qui dépendent de ces services. L'attaque a été rapidement maîtrisée, mais a nécessité une restauration sécur...
Secureworks Counter Threat Unit (CTU) has identified links between North Korean IT workers and fraudulent crowdfunding activities, with the group known as Nickle Tapestry orchestrating scams to support North Korean interests
Patch Tuesday saw Microsoft fix eight zero-days, three of which are being actively exploited
Des enquêtes sont en cours après une cyberattaque avec ransomware contre le système d'information scolaire de Speyer. Les détails de l'incident ne sont pas encore disponibles mais une quarantaine d'établissements scolaires sont affectés. Les autorités travaillent à élucider les circonstances de l'at...
Le collège La Salle à Brive a été victime d'une cyberattaque par ransomware, qui a volé toutes les données informatiques de l'établissement, notamment les bulletins scolaires des élèves. Les pirates ont demandé une rançon de 8 000 euros pour récupérer les données, mais l'établissement a refusé de pa...
A new Interim Final Rule on Artificial Intelligence Diffusion issued in the US strengthens security, streamlines chip sales and prevents misuse of AI technology
La firme Insight Partners a été victime d'une cyberattaque, ce qui pourrait entraîner des fuites de données sensibles. L'entreprise travaille actuellement à évaluer l'impact total de l'incident. Des informations commerciales confidentielles pourraient être compromises.
Pearson, une entreprise d'éducation basée au Royaume-Uni, a subi une attaque informatique, permettant aux acteurs menaçants de voler des données d'entreprise et des informations client. L'attaque a été possible en raison d'un jeton d'accès GitLab exposé dans un fichier de configuration public. Les d...
Browser-based cyber-threats surged in 2024, with credential abuse and infostealers on the rise
Barings Law is planning to sue the two tech giants over numerous alleged violations of data misuse, including for AI training
CVSSv3 Score:
4.1
An externally controlled reference to a resource in another sphere vulnerability [CWE-610] in multiple products may allow an unauthenticated attacker to poison web caches between the device and the attacker via crafted HTTP requests, where the Host header points to an ar...
A UK government consultation has proposed banning public sector and critical infrastructure organizations from making ransomware payments to disincentivize attackers from targeting these services
CISA claims US critical infrastructure providers are improving cyber hygiene and remediation activities
\[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...
The .uk registry Nominet has been breached by a recently disclosed zero-day vulnerability in Ivanti products
A joint government advisory has set out steps critical infrastructure firms should take to ensure any OT products they purchase are secure by design
Ellis Early Learning, Inc experienced a network disruption that led to unauthorized access to certain information stored on their network between January 10, 2025 to January 14, 2025. The affected information includes first and last name, in combination with other data. The incident was discovered o...
The Branch Group, Inc. experienced a data security incident where an unauthorized third-party attempted to access their network environment, potentially exposing personal information of employees. The incident was claimed by Cactus on February 24.