> TODAY'S SUMMARY (151 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. is offering a $10 million reward for Zhang Yu, a key figure in the Hafnium hacking campaign, which compromised thousands of systems. In a concerning incident, attackers hijacked top-level domains to issue fake security certificates for major organizations, including Google, posing a severe risk of trusted brand impersonation. Additionally, vulnerabilities in Microsoft, Adobe, and Atlassian products have been disclosed, prompting urgent updates as exploitation attempts have already begun. The FBI and Secret Service are warning about the ongoing FortiBleed credential-stealing campaign, which has impacted over 86,000 devices. Finally, a data breach in Arizona's court system exposed information on over 1.3 million individuals, underscoring the persistent threat of cyberattacks on sensitive data.
|
// AI-powered summary generated at 20:00
Golden Age Home Health, un prestataire de soins à domicile basé à Oklahoma City, a subi une cyberattaque affectant les informations de santé protégées de 2 280 patients. Bien que la date de détection et les types de données concernées ne soient pas précisés, les patients impactés bénéficient de serv...
Artivion, Inc. suffered a security incident involving unauthorized access to its network, resulting in the potential exposure of sensitive information for three Maine residents. The incident occurred between November 20 and November 21, 2024. Artivion is offering complimentary credit monitoring and...
New Linux malware WolfsBane and FireWood have been linked to Gelsemium APT, a cyber-espionage group targeting critical systems
Group-IB revealed key differences in VietCredCare and DuckTail infostealer malware targeting Facebook Business accounts
L'éditeur de logiciels Blue Yonder, qui fournit des services à des chaînes de supermarchés aux États-Unis et au Royaume-Uni, a été victime d'une attaque de ransomware qui a perturbé son environnement de services gérés. Les géants de la distribution britanniques Morrisons et Sainsbury ont été affecté...
One of these flaws detected using LLMs was in the widely used OpenSSL library
The BianLian ransomware group has shifted exclusively to exfiltration-based extortion and is deploying multiple new TTPs for initial access and persistence
La société Artivion, Inc. a signalé une cyberattaque qui a eu lieu le 21 novembre 2024, entraînant la prise de mesures pour contenir et remédier à l'incident. L'incident a entraîné la perte et la cryptage de fichiers, mais la société estime que l'impact financier et opérationnel ne sera pas matériel...
Spreading malware via Telegram channels allows threat actors to bypass traditional detection mechanisms and reach a broad, unsuspecting audience
Over a fifth of large UK businesses aren’t sure of their compliance responsibilities under the new NIS2 directive
Australian Ransomware Attack, 20 November 2024: Notorious ransomware gang RansomHub has claimed an attack on a third-party firm that assists businesses with ASIC compliance. RansomHub claims to have exfiltrated 30 gigabytes of data.
The post Incident: RansomHub hits third-party ASIC compliance firm...
Five men have been indicted in connection with crimes committed by the Scattered Spider group
Five LPE flaws in Ubuntu’s needrestart utility enable attackers to gain root access in versions prior to 3.8
La ville d'Odessa au Texas a été victime d'une cyberattaque le 20 novembre, mais l'équipe de cybersécurité de la ville a réussi à détecter et à stopper l'attaque avant qu'elle ne cause des dommages. Les systèmes de la ville ont été mis hors ligne pour une journée pour s'assurer que tout fonctionnait...
60% of QR code emails are spam according findings from Cisco Talos, who also identified attackers using QR code art to bypass security filters
CrowdStrike unveiled a new Chinese-aligned hacking group allegedly spying on telecom providers
La chaîne de supermarchés italienne Conad a été victime d'une cyberattaque par le groupe de hackers Lynx, qui a volé des documents confidentiels et demande un ransom pour ne pas les diffuser sur le dark web. Les hackers affirment avoir obtenu des informations sur les ressources humaines et les clien...
Apple has urged customers to download the security updates, which address vulnerabilities relating to the JavaScriptCore and WebKit frameworks
OWASP has updated its Top 10 list of risks for LLMs and GenAI, upgrading several areas and introducing new categories
Une cyberattaque a touché le centre de chirurgie plastique Hand & Plastic Surgery Centre au Michigan, affectant près de 20 000 patients, avec des informations personnelles et de santé protégées exposées. Deux autres entreprises, Dove Healthcare au Wisconsin et Southeast Series of Lockton Companies e...