> TODAY'S SUMMARY (151 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. is offering a $10 million reward for Zhang Yu, a key figure in the Hafnium hacking campaign, which compromised thousands of systems. In a concerning incident, attackers hijacked top-level domains to issue fake security certificates for major organizations, including Google, posing a severe risk of trusted brand impersonation. Additionally, vulnerabilities in Microsoft, Adobe, and Atlassian products have been disclosed, prompting urgent updates as exploitation attempts have already begun. The FBI and Secret Service are warning about the ongoing FortiBleed credential-stealing campaign, which has impacted over 86,000 devices. Finally, a data breach in Arizona's court system exposed information on over 1.3 million individuals, underscoring the persistent threat of cyberattacks on sensitive data.
|
// AI-powered summary generated at 20:00
La société Kurita Water Industries a annoncé que sa filiale américaine, Kurita America Inc., a été victime d'une cyberattaque par ransomware, entraînant l'accès non autorisé à des serveurs et la potentialité de fuites de données de clients, partenaires et employés. Les serveurs compromis ont été déc...
Krispy Kreme, Inc. a été victime d'une cyberattaque le 29 novembre 2024, qui a entraîné des perturbations opérationnelles, notamment la fermeture de la commande en ligne aux États-Unis. L'entreprise travaille à contenir et à remédier à l'incident avec l'aide d'experts en cybersécurité et a notifié l...
A malicious PyPI package “aiocpa,” that stole crypto wallet data via obfuscated code, has been removed after being reported by Reversing Labs researchers
Brodsky Renehan Pearlstein & Bouquet Chartered (BRPB) a découvert une activité suspecte dans son réseau le 29 novembre 2024. Une enquête a révélé qu'un acteur non autorisé a copié des données sans permission, notamment des noms, des numéros de sécurité sociale, des informations de carte de paiement...
Stevens & Day suffered a data breach, providing customers with access to credit monitoring and fraud assistance services. The breach led to the notification of affected customers, who were offered free services to protect their information. The incident prompted the company to encourage customers to...
A new cyber-attack technique uses Godot Engine to deploy undetectable malware via GodLoader, infecting more than 17,000 devices
Hicks Thomas, LLP experienced a ransomware incident on November 20, 2024, which may have affected personal information, including date of birth, Social Security Number, and medical information. The incident occurred between November 20, 2024, and November 30, 2024. The organization is offering compl...
This vulnerability was patched in May 2024 but was only allocated a CVE in November after evidence of exploitation
Customers of Advantech’s EKI-6333AC-2G industrial-grade wireless access point have been urged to update their devices to new firmware versions
En 2024, le secteur de l'eau a fait l'objet d'une attention particulière des attaquants informatiques notamment dans le contexte des Jeux Olympiques et Paralympiques 2024 et de l'importance portée à la qualité de l'eau de la Seine. A plusieurs reprises au cours de l'année, des groupes...
European police have arrested 21 individuals linked to a violent Albanian gang after decrypting their Sky ECC communications
The CSO of T-Mobile has clarified that no customer information was stolen by Chinese hacking group Salt Typhoon
De multiples vulnérabilités ont été découvertes dans les produits Synology. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
North Los Angeles County Regional Center experienced a data incident in November 2024, involving unauthorized access to personal information, but no identity theft or fraud was reported. A cyberattack was claimed by Medusa on December 15, 2024.
APT-C-60 targets Japan with phishing emails, using job application ruse and malware via Google Drive
Bootkitty, the first Linux-targeting UEFI bootkit, bypassed kernel security in a proof-of-concept attack
Australian Finance Services Privacy Breach, 27 November 2024: Mortgage broker Finsure confirms ‘cyber incident’ impacting customers and brokers. Finsure has confirmed that the marketing data of a number of its brokers and customers was impacted as a result of breach of their third-party provider Act...
One of the priorities of the newly-approved Von der Leyen Commission II will be to strengthen the healthcare sector’s cyber resilience
A pro-Russian hacktivist collective, CyberVolk, has launched its own ransomware-as-a-service operations, SentinelLabs has found
La ville de Hoboken, dans le New Jersey, a été victime d'une cyberattaque par ransomware, ce qui a entraîné la fermeture de la mairie et la suspension des services en ligne. Les autorités locales et les services de police enquêtent sur l'incident pour déterminer comment restaurer les services de man...