> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights a critical vulnerability in SonicWall's core product, identified as CVE-2026-102255, which has been rated a 10 in severity, indicating an urgent need for patching. Additionally, a ransomware fixer has been accused of defrauding clients by charging them more than the ransom amounts, pocketing the difference instead of providing legitimate decryption services. This underscores ongoing issues with trust and reliability in the cybersecurity space. As these incidents unfold, organizations must remain vigilant and prioritize updates and threat mitigation strategies.
|
// AI-powered summary generated at 04:00
A joint US-Japan alert attributed North Korean hackers with a May 2024 crypto heist worth $308m from Japan-based company DMM
A US judge has ruled in favor of WhatsApp in a long-running case against commercial spyware-maker NSO Group
Happy to share that I authored the paper “Trust No AI: Prompt Injection Along The CIA Security Triad”.
You can download it from arxiv.
The paper examines how prompt injection attacks can compromise Confidentiality, Integrity, and Availability (CIA) of AI systems, with real-world examples targeting v...
Researchers at iProov have discovered a dark web group compiling identity documents and biometric data to bypass KYC checks
La Banque de l'Habitat du Sénégal a été victime d'une attaque informatique qui a paralysé ses services, entraînant une interruption de ses activités. Les détails de l'attaque ne sont pas encore précisés, mais la banque a confirmé l'incident et a mis en place des mesures pour contenir et résoudre la...
La mairie de Guararema a annoncé que les protocoles réalisés entre le 30 novembre et le 23 décembre 2024 devront être refaits en raison d'une cyberattaque ayant perturbé la stabilité des systèmes. Les démarches effectuées en ligne ou en présentiel pendant cette période doivent être reprises au siège...
The vulnerabilities, now patched, posed significant risks, including unauthorized file uploads, privilege escalation and SQL injection attacks
Carruth Compliance Consulting a annoncé une violation de données après que des parties non autorisées ont accédé à son réseau informatique entre le 19 et le 26 décembre 2024, exposant des informations sensibles de consommateurs, notamment des numéros de sécurité sociale et des informations de compte...
US healthcare giant Ascension revealed that 5.6 million individuals have had their personal, medical and financial information breached in a ransomware attack
Cryptomining malware hits popular npm packages rspack and vant, posing risks to open source tools
An end of year summary for Hacking the Cloud in 2024.
A new digital operation has enabled Interpol to identify scores of human traffickers operating between South America and Europe
The Information Commissioner’s Office has warned that millions of Brits don’t know how to erase personal data from their old devices
An unauthorized third party gained access to certain Monroe University computer systems between December 9, 2024, and December 23, 2024, and acquired copies of some files on their network. The incident involved some personal information, but there is no evidence that it has been used for identity th...
Le Groupe a récemment été victime d'un incident de ransomware, au cours duquel un tiers non autorisé a accédé à ses serveurs. Grâce à des actions rapides et à l'utilisation de systèmes de sauvegarde, l'impact sur les opérations a été minimal, et une évaluation préliminaire indique que l'incident n'a...
OpenAI must also initiate a six-month public awareness campaign across Italian media, explaining how it processes personal data for AI training
La société Nikki-Universal, un fabricant de produits chimiques, a été victime d'une attaque de ransomware sophistiquée, au cours de laquelle les hackers ont volé 761,8 Go de données. Le groupe de ransomware Hunters International, connu pour ses tactiques agressives, a revendiqué la responsabilité de...
Le 22 décembre 2024, HEXPOL a détecté un accès non autorisé à son réseau informatique. L'entreprise a immédiatement sécurisé ses systèmes, lancé une enquête avec des experts en cybersécurité, et mené une analyse approfondie des fichiers potentiellement compromis. Le 25 juin 2025, il a été confirmé q...
The Security Service of Ukraine has accused Russian-linked actors of perpetrating a cyber-attack against the state registers of Ukraine
Graebel Companies, Inc. experienced a network disruption involving certain computer systems and services in December 2024, resulting in unauthorized access to files between December 19, 2024, and December 22, 2024. The incident was discovered in December 2024, and the company has since taken steps t...