> TODAY'S SUMMARY (151 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. is offering a $10 million reward for Zhang Yu, a key figure in the Hafnium hacking campaign, which compromised thousands of systems. In a concerning incident, attackers hijacked top-level domains to issue fake security certificates for major organizations, including Google, posing a severe risk of trusted brand impersonation. Additionally, vulnerabilities in Microsoft, Adobe, and Atlassian products have been disclosed, prompting urgent updates as exploitation attempts have already begun. The FBI and Secret Service are warning about the ongoing FortiBleed credential-stealing campaign, which has impacted over 86,000 devices. Finally, a data breach in Arizona's court system exposed information on over 1.3 million individuals, underscoring the persistent threat of cyberattacks on sensitive data.
|
// AI-powered summary generated at 20:00
Le cabinet dentaire Jefferson Dental Center de South Bend, dans l'Indiana, a été victime d'une cyberattaque, entraînant une fuite de données personnelles de ses patients, notamment des noms, numéros de sécurité sociale, adresses, numéros de permis de conduire et dates de naissance. Le cabinet a noti...
L'institut de statistiques MONSTAT a été victime d'une cyberattaque en novembre dernier, qui a permis aux hackers d'accéder à ses données. Les données ont été verrouillées et sont restées inaccessibles jusqu'à nouvel ordre. Les hackers auraient demandé une rançon en échange de la restitution des don...
Over 1 million domains are vulnerable to “Sitting Ducks” attack, which exploits DNS misconfigurations
On or around November 14–15, 2024, an unauthorized actor gained access to Greenscape Land Design’s computer systems and potentially acquired files containing individuals’ personal information. Greenscape promptly contained the event, engaged third-party forensic specialists, and completed a review o...
GITSIT Solutions, LLC suffered a data breach where an unknown actor accessed certain computer systems and acquired files containing personal information. The breach occurred on November 14 and 15, 2024. GITSIT notified 16 Maine residents and offered credit monitoring services.
Misconfigurations in Microsoft Power Pages granting excessive access permissions expose sensitive data, risking PII to unauthorized users
Le centre de santé Ungava Tulattavik a été victime d'une cyberattaque qui a compromis des informations sensibles sur les patients et les employés. Les autorités ont bloqué l'attaque dès sa détection et une enquête est en cours. Le centre a mis en place des mesures pour sécuriser les systèmes et sout...
For the past year, we’ve worked with the Python Package Index (PyPI) on a new security feature for the Python ecosystem: index-hosted digital attestations, as specified in PEP 740. These attestations improve on traditional PGP signatures (which have been disabled on PyPI) by providing key usability,...
The FBI and CISA have confirmed that US officials’ private communications have been compromised
Over 80% of UK organizations suffered an API security incident in the past year, with each costing over ÂŁ400,000
La société allemande Vossko, spécialisée dans la transformation de produits alimentaires, a été victime d'une cyberattaque par ransomware le 14 novembre, qui a crypté ses systèmes internes et bases de données. Les systèmes ont été restaurés et la production a repris, mais l'enquête est toujours en c...
The UK’s financial regulators have discarded plans to force critical suppliers to disclose new vulnerabilities
On November 14, 2024, Westfield Fire District detected unauthorized access to its network during an IT outage, resulting in acquisition of certain files containing members’ personal information. By April 17, 2025, the district confirmed that personal data may have been compromised and notified affec...
On October 31, 2024 an unknown third party gained unauthorized access to the City of McKinney’s network environment, which was discovered and contained on November 14, 2024. A forensic investigation completed on December 30, 2024 determined that certain files containing personal information may have...
Hive0145 is targeting Spain, Germany, Ukraine with Strela Stealer malware in invoice phishing tactic
2025 could see our biggest AI fears materialize, according to a Google Cloud forecast report
In January, we identified and reported a vulnerability in the Lotus and Venus clients of the Filecoin network that allowed an attacker to remotely crash a node and trigger a denial of service. This issue is caused by an incorrect validation of an index, resulting in an index out-of-range panic. The...
Lazarus APT has been found smuggling malware onto macOS devices using custom extended attributes, evading detection
An individual who posted data allegedly stolen via MOVEit from Amazon and other big-name firms claims not to be malicious
Le département de la Réunion a été victime d'une cyberattaque le 13 novembre, mais grâce à l'intervention rapide des équipes informatiques, la fuite de données a été limitée. Les réseaux informatiques ont été temporairement interrompus pour éviter tout risque de propagation, et une cellule de crise...