[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (151 articles)

|

// AI-powered summary generated at 20:00

> Jefferson Dental Center
Le cabinet dentaire Jefferson Dental Center de South Bend, dans l'Indiana, a été victime d'une cyberattaque, entraînant une fuite de données personnelles de ses patients, notamment des noms, numéros de sécurité sociale, adresses, numéros de permis de conduire et dates de naissance. Le cabinet a noti...
> Institut statistique du Montenegro(MONSTAT)
L'institut de statistiques MONSTAT a été victime d'une cyberattaque en novembre dernier, qui a permis aux hackers d'accéder à ses données. Les données ont été verrouillées et sont restées inaccessibles jusqu'à nouvel ordre. Les hackers auraient demandé une rançon en échange de la restitution des don...
> Sitting Ducks DNS Attacks Put Global Domains at Risk
Over 1 million domains are vulnerable to “Sitting Ducks” attack, which exploits DNS misconfigurations
> Greenscape Land Design, Inc.
On or around November 14–15, 2024, an unauthorized actor gained access to Greenscape Land Design’s computer systems and potentially acquired files containing individuals’ personal information. Greenscape promptly contained the event, engaged third-party forensic specialists, and completed a review o...
> GITSIT Solutions, LLC
GITSIT Solutions, LLC suffered a data breach where an unknown actor accessed certain computer systems and acquired files containing personal information. The breach occurred on November 14 and 15, 2024. GITSIT notified 16 Maine residents and offered credit monitoring services.
> Microsoft Power Pages Misconfiguration Leads to Data Exposure
Misconfigurations in Microsoft Power Pages granting excessive access permissions expose sensitive data, risking PII to unauthorized users
> Ungava Tulattavik Health Center
Le centre de santé Ungava Tulattavik a été victime d'une cyberattaque qui a compromis des informations sensibles sur les patients et les employés. Les autorités ont bloqué l'attaque dès sa détection et une enquête est en cours. Le centre a mis en place des mesures pour sécuriser les systèmes et sout...
> Attestations: A new generation of signatures on PyPI
For the past year, we’ve worked with the Python Package Index (PyPI) on a new security feature for the Python ecosystem: index-hosted digital attestations, as specified in PEP 740. These attestations improve on traditional PGP signatures (which have been disabled on PyPI) by providing key usability,...
> Massive Telecom Hack Exposes US Officials to Chinese Espionage
The FBI and CISA have confirmed that US officials’ private communications have been compromised
> API Security in Peril as 83% of Firms Suffer Incidents
Over 80% of UK organizations suffered an API security incident in the past year, with each costing over ÂŁ400,000
> Vossko
La société allemande Vossko, spécialisée dans la transformation de produits alimentaires, a été victime d'une cyberattaque par ransomware le 14 novembre, qui a crypté ses systèmes internes et bases de données. Les systèmes ont été restaurés et la production a repris, mais l'enquête est toujours en c...
> Bank of England U-turns on Vulnerability Disclosure Rules
The UK’s financial regulators have discarded plans to force critical suppliers to disclose new vulnerabilities
> Westfield Fire District
On November 14, 2024, Westfield Fire District detected unauthorized access to its network during an IT outage, resulting in acquisition of certain files containing members’ personal information. By April 17, 2025, the district confirmed that personal data may have been compromised and notified affec...
> City of McKinney
On October 31, 2024 an unknown third party gained unauthorized access to the City of McKinney’s network environment, which was discovered and contained on November 14, 2024. A forensic investigation completed on December 30, 2024 determined that certain files containing personal information may have...
> Hive0145 Targets Europe with Advanced Strela Stealer Campaigns
Hive0145 is targeting Spain, Germany, Ukraine with Strela Stealer malware in invoice phishing tactic
> AI Threat to Escalate in 2025, Google Cloud Warns
2025 could see our biggest AI fears materialize, according to a Google Cloud forecast report
> Killing Filecoin nodes
In January, we identified and reported a vulnerability in the Lotus and Venus clients of the Filecoin network that allowed an attacker to remotely crash a node and trigger a denial of service. This issue is caused by an incorrect validation of an index, resulting in an index out-of-range panic. The...
> Lazarus Group Uses Extended Attributes for Code Smuggling in macOS
Lazarus APT has been found smuggling malware onto macOS devices using custom extended attributes, evading detection
> Amazon MOVEit Leaker Claims to Be Ethical Hacker
An individual who posted data allegedly stolen via MOVEit from Amazon and other big-name firms claims not to be malicious
> Département de la Réunion
Le département de la Réunion a été victime d'une cyberattaque le 13 novembre, mais grâce à l'intervention rapide des équipes informatiques, la fuite de données a été limitée. Les réseaux informatiques ont été temporairement interrompus pour éviter tout risque de propagation, et une cellule de crise...