> TODAY'S SUMMARY (151 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. is offering a $10 million reward for Zhang Yu, a key figure in the Hafnium hacking campaign, which compromised thousands of systems. In a concerning incident, attackers hijacked top-level domains to issue fake security certificates for major organizations, including Google, posing a severe risk of trusted brand impersonation. Additionally, vulnerabilities in Microsoft, Adobe, and Atlassian products have been disclosed, prompting urgent updates as exploitation attempts have already begun. The FBI and Secret Service are warning about the ongoing FortiBleed credential-stealing campaign, which has impacted over 86,000 devices. Finally, a data breach in Arizona's court system exposed information on over 1.3 million individuals, underscoring the persistent threat of cyberattacks on sensitive data.
|
// AI-powered summary generated at 20:00
Zscaler’s latest report finds 54.5% of IoT attacks target manufacturing, with the industry suffering more than three times the weekly attacks of other sectors
npm package @lottiefiles/lottie-player hacked with malicious code, draining crypto wallets via web3 pop-ups
Le centre médical Hofer Ärztezentrum, situé à Eppenreuther Straße, a été victime d'une cyberattaque lundi matin, affectant trois cabinets de médecins et leurs filiales. Depuis, les systèmes électroniques ne fonctionnent plus. Les mesures de riposte et les conséquences pour les patients sont en cours...
Google’s threat intelligence team uncovered four Chinese PR firms operating networks of inauthentic news sites
UK Minister Pat McFadden will say in a speech at a NATO conference that adversaries are looking at using AI on the physical and cyber battlefield
Un hôpital de Merseyside, l'Arrowe Park Hospital, a déclaré un "incident majeur" en raison d'une faille de sécurité informatique, obligeant les patients à ne se présenter que pour les cas d'urgence. Les processus de continuité des activités sont en place pour maintenir la sécurité des patients, mais...
Meta has closed down two million accounts it says were used in scams such as pig butchering
The UK’s Information Commissioner’s Office argues that regulatory concerns shouldn’t prevent firms sharing data to stop scams
La société ENGlobal Corporation a été victime d'une cyberattaque le 25 novembre 2024, entraînant l'accès illégal à son système d'information et la cryptation de certains fichiers de données. L'enquête et les efforts de remédiation sont en cours, mais l'accès au système d'information de l'entreprise...
Le Tennessee Bureau of Investigation (TBI) assiste les écoles du comté de Rutherford pour résoudre un problème de réseau informatique, mais refuse de fournir des détails sur l'enquête en cours. Les écoles ont signalé une perturbation du réseau le 25 novembre, qui a affecté les systèmes de l'école, m...
Microsoft has seized 240 websites associated with the “ONXX” phishing-as-a-service operation, and has sued the developer of this service
Barrett-Jackson Holdings, LLC suffered a data breach that involved the copying of files from their computer systems, potentially exposing sensitive information such as Social Security numbers, driver's license numbers, and bank account numbers. The breach was discovered on November 25, 2024, and the...
Beech Acres Parenting Center experienced a data security incident where unauthorized access to sensitive information occurred. The incident was discovered on November 23, 2024, and affected approximately 2 Maine residents. The potentially affected information includes names, dates of birth, Social S...
Russian-aligned TAG-110 uses custom tools to spy on governments, human rights groups and educational institutions in Europe and Asia
Bitdefender found that 77% of Black Friday-themed spam emails in 2024 have been identified as scams, with attackers becoming more creative in their campaigns
Australian Manufacturing Ransomware Attack, 22 November 2024: Victorian based Snow Brand Australia confirms SafePay ransomware attack. Stolen 24 gigabytes, including financial data invoices, purchase orders, and details of retail partners. Also employee data, medical certificates, superannuation det...
Corvus Insurance highlighted the growing complexity and competition within the ransomware ecosystem, with the threat level remaining elevated
The 25 most dangerous software weaknesses between June 2023 and June 2024 are responsible for almost 32,000 vulnerabilities
This post includes an analysis of an infostealer supply chain attack targeting Windows users
Phishing attacks, business email compromise and vendor email compromise attacks on manufacturing have surged in the past 12 months