The FBI has issued a warning about the Hiatus RAT malware targeting Xiongmai and Hikvision web cameras and DVRs, urging users isolate these devices from networks
The US Cybersecurity and Infrastructure Security Agency recommended users turn on phishing-resistant MFA and switch to Signal-like apps for messaging
Le module d’assistance cyber en ligne de Cybermalveillance.gouv.fr évolue ! Le dispositif rejoint par le Clusif en 2022 devient le 17Cyber, et il est toujours disponible en page d’accueil de notre site. Ce service est proposé par la Police Nationale, la Gendarmerie Nationale et Cybermalveillance.gou...
A Dragos report observed 23 new ransomware groups targeting industrial organizations in Q3 2024
An unauthorized party gained access to Nth Degree's network environment, potentially accessing personal information between December 12, 2024, and December 20, 2024. The incident was discovered on May 14, 2025. Nth Degree is offering complimentary credit monitoring services to affected individuals.
Cornwell Quality Tools suffered a data breach where an unknown actor gained access to their network and potentially acquired certain files containing personal information. The breach occurred on or around December 12, 2024. The attack was claimed by Cactus on February 4, 2025.
Bitsight found that 40% of US organizations who used Kaspersky products before the government ban came into effect still appear to be using them
Forescout identified a new type of malware capable of terminating engineering processes, used to target Siemens engineering workstations
Une cyberattaque par ransomware a causé une panne d'internet qui a retardé les trains de la Pittsburgh Regional Transit (PRT) et a mis hors ligne plusieurs de ses systèmes. L'attaque a été détectée le 19 décembre et la PRT a immédiatement lancé une enquête et engagé des experts en cybersécurité. Les...
The EU Data Protection Board (EDPB) published a long-awaited opinion on how GDPR should apply to AI models
Mainly North Korean hackers stole over $2bn from crypto platforms in 2024, says Chainalysis
On December 19, 2024, Miedema Produce, Inc. discovered suspicious activity on its systems that may have exposed the names and Social Security numbers of current and former employees. A forensic investigation concluded on January 24, 2025 and, while no misuse has been detected, the company deployed e...
Cybersecurity firm Recorded Future has been listed as an “undesirable” organization by the Prosecutor General's Office of the Russian Federation
A Morphisec researcher showed how an attacker could manipulate FIRST’s Exploit Prediction Scoring System (EPSS) using AI
Gaylord Specialty Healthcare experienced a cybersecurity incident that impacted connectivity to their network, potentially exposing personal data between December 16, 2024, and December 19, 2024. The attack was claimed by Safepay on January 22, 2025.
Interpol wants to change the term “pig butchering” to “romance baiting”
Baker University suffered a data breach in December 2024, resulting in unauthorized access and/or acquisition of certain files and folders within their network. The breach may have impacted sensitive information, including names and other personal data. The university is offering complimentary credi...
We’ve updated the CIR 'Enhanced Level' scheme standard and will be ready to accept applications in the new year.
A CISA Directive sets out actions all US federal agencies must take to identify and secure cloud tenants in their environments
SlashNext reports a 202% increase in overall phishing messages and a 703% surge in credential-based phishing attacks in 2024