> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
La mairie de Clairefontaine-en-Yvelines a été victime d'une cyberattaque sur son réseau informatique, obligeant à l'isoler d'internet pour sécurisation. Tous les services administratifs sont impactés, rendant impossible l'accueil du public, et la mairie restera fermée jusqu'à nouvel ordre. La sociét...
Le site web de l'Université de Moncton a été victime d'un "cyber incident" le 14 octobre, ce qui a entraîné la mise hors ligne de plusieurs fonctionnalités pour des raisons de sécurité. Les équipes de l'université travaillent à remettre le site en ligne le plus rapidement possible, mais la situation...
NHS England has issued an alert regarding a critical Veeam Backup & Replication vulnerability that is being actively exploited, potentially leading to remote code execution
La société japonaise Yorozu Corporation a été victime d'une cyberattaque par ransomware en octobre 2024, qui a perturbé ses opérations et retardé la soumission de son rapport financier semestriel. L'entreprise a demandé et obtenu une extension de deux mois pour soumettre son rapport, qui sera mainte...
En octobre 2024, le Groupe Althays a été victime d’une cyberattaque par ransomware, déclenchant immédiatement l’activation d’une cellule de crise avec le soutien de Stoïk. L’entreprise a mené une communication transparente, sécurisé ses infrastructures, restauré les systèmes client par client, et re...
Access Now announced that the US Customs and Border Protection agency released records on its app following the NGO’s lawsuit
In October 2024, Trinity Petroleum Management, LLC detected unauthorized access to its systems that occurred between October 10 and October 14, and on December 18, 2024 determined that names and Social Security numbers may have been exfiltrated. The company retained legal counsel, engaged external f...
Methodist Homes of Alabama & Northwest Florida suffered a data breach due to suspicious activity in their network. The breach occurred between October 2, 2024, and October 14, 2024, and affected certain personal information of individuals. The organization is offering complimentary credit monitoring...
A new Sonatype report reveals a 156% surge in open source malware, with over 704,102 malicious packages identified since 2019, as OSS adoption continues to skyrocket
La Johannesstift-Diakonie de Berlin a été victime d'une cyberattaque dimanche, entraînant la mise hors service de la plupart de ses systèmes informatiques et la cryptation de tous ses serveurs. Les équipes d'urgence ont été déployées et les systèmes de secours ont été activés pour maintenir le fonct...
La Mutuelle d'Ivry (Mif) a été victime d'une cyberattaque le week-end du 12 octobre, entraînant une fuite partielle de données personnelles de moins de 10 000 sociétaires. Les mots de passe, accès clients et actifs n'ont pas été compromis, mais des documents PDF contenant des informations personnell...
Russian-backed APT29 has been spying on US and European organizations since at least 2021, a US-UK joint advisory said
L'enseigne française Guy Demarle a été victime d'une cyberattaque en octobre, entraînant la fuite de données personnelles de ses clients, notamment noms, prénoms, adresses postales, e-mails et numéros de téléphone. L'entreprise a informé la CNIL et avertit ses clients des risques de phishing et d'us...
S.V.D.P. Management, Inc. notified individuals whose personal information may have been involved in a data breach that occurred between September 26, 2024, and October 12, 2024. The breach involved unauthorized access or acquisition of personal information, including names and other data elements. T...
Operation MiddleFloor targets Moldova’s October elections, spreading EU disinformation via email
La Calgary Public Library a fermé ses portes en raison d'une cyberattaque qui a compromis certains systèmes, obligeant la fermeture de toutes les bibliothèques physiques et la mise hors ligne de tous les serveurs et accès informatiques. L'incident a également affecté le festival Imaginairium, qui a...
La société finlandaise Polar, fabricant de montres connectées, a été victime d'une cyberattaque qui a compromis les informations de commande de certains clients de son magasin en ligne aux États-Unis. Les attaquants ont tenté d'effectuer des achats frauduleux en utilisant les comptes compromis et on...
This is a joint post with the Hugging Face Gradio team; read their announcement here! You can find the full report with all of the detailed findings from our security audit of Gradio 5 here. Hugging Face hired Trail of Bits to audit Gradio 5, a popular open-source library that provides a web interfa...
BayMark Health Services, le plus grand fournisseur de services de traitement des troubles de l'usage de substances en Amérique du Nord, a notifié ses patients d'une violation de données qui a exposé des informations personnelles et de santé, notamment des numéros de sécurité sociale et des informati...
Legacy Treatment Services, Inc. experienced a cybersecurity incident that impacted connectivity to their network, potentially exposing personal data of those served by both Legacy and Community Treatment Solutions between October 6, 2024, and October 11, 2024. The attack was claimed under the Interl...