Le site web du Bureau national des statistiques (NBS) du Nigeria est hors ligne depuis trois semaines suite à une cyberattaque qui a compromis ses opérations. La brèche a été confirmée le 18 décembre 2024, mais le bureau n'a pas fourni de mises à jour sur la restauration du site ou les développement...
Kelly Benefits a annoncé une faille de sécurité des données, mais les détails de l'événement ne sont pas précisés dans l'annonce. L'entreprise a publié un avis de sécurité des données pour informer les parties prenantes de la situation. Les conséquences de cette faille de sécurité ne sont pas encore...
Ian M discusses what makes a good password
Le 17 décembre 2024, Albion College a découvert un accès non autorisé à son réseau. Une enquête a été lancée immédiatement avec l’aide de spécialistes en cybersécurité, et les analyses ont révélé que des données personnelles, dont le nom complet et possiblement d’autres informations, ont été extrait...
Vector Security, Inc. suffered a data breach where unauthorized activity was detected in their IT systems, potentially exposing personal information of customers. The breach occurred as early as mid-December 2024, but the company took immediate action to contain the activity and launched an investig...
Emma W discusses the question everyone keeps asking us.
Fort Wayne Medical Education Program experienced a data privacy incident involving personal information accessed or acquired by an unauthorized actor between December 12, 2024, and December 17, 2024. The incident was discovered on December 17, 2024, and the organization took immediate action to secu...
CISA and EPA have published guidance for operators of water and wastewater systems to protect against cyber-attacks
Rhode Island's RIBridges system has suffered a major data breach, potentially exposing personal information, with Deloitte confirming the presence of malicious software
Grok is the chatbot of xAI. It’s a state-of-the-art model, chatbot and recently also API. It has a Web UI and is integrated into the X (former Twitter) app, and recently it’s also accessible via an API.
Since this post is a bit longer, I’m adding an index for convenience:
Table of Contents High Leve...
Large-scale campaign identified by Guardio Lans and Infoblox, exploiting malvertising and fake captchas to distribute Lumma infostealer for massive theft
The Serbian authorities have been using advanced mobile forensics products made by Israeli firm Cellebrite to extract data from mobile devices illegally
Azure Key Vault Contributors are not allowed access to Key Vault keys, certificates, and secrets. But did you know they can still gain access to this sensitive data? This post will cover a privilege escalation vector to access data in key vaults using the access policy permissions model.
New Ofcom guidance is designed to help tech companies comply with their obligations around tackling illegal online harms under the Online Safety Act
Over 200,000 YouTube creators have been targeted by malware-laden phishing emails with the aim of infecting their followers
Boston Interiors Home Furnishings LLC a subi une faille de sécurité qui a pu affecter les informations personnelles de cinq résidents du Maine. L'incident a été découvert le 17 décembre 2024 et a fait l'objet d'une enquête approfondie. Les informations qui ont pu être compromises incluent les noms,...
Ukrainian officials say Russian intelligence is using video games to trick children into helping the enemy
L’ARSOE, qui héberge les bases et outils liés à l’élevage, a été victime d’une cyberattaque, rendant l’application SYNEL inaccessible pour les éleveurs, sans délai de reprise connu. Afin de respecter les obligations de notification, les éleveurs doivent temporairement utiliser des documents papier e...
Le groupe de soins de santé Sunflower Medical Group au Kansas a été victime d'une cyberattaque en décembre, exposant les informations sensibles de plus de 220 000 patients, notamment des numéros de sécurité sociale, des informations médicales et des données d'assurance santé. Les hackers ont accédé...
The US Government is offering a $5 million reward for information leading to the disruption of financial mechanisms supporting North Korea following a six-year conspiracy