> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
The data breach exposed more than 10m customer conversations from an AI call center platform in the Middle East
The EU's Cyber Resilience Act requires cybersecurity standards for all connected products throughout their entire lifecycle
L'Agence pour la Modernisation Administrative (AMA) du Portugal a été victime d'une cyberattaque par ransomware, rendant son réseau informatique inaccessible au public. L'attaque a eu un impact significatif sur plusieurs services, notamment Authentication.Gov, Gov.ID et CERT.PT. L'AMA travaille avec...
Marriott will pay $52m to 50 US states for a data breach impacting 131.5 million American customers, and has agreed to implement stronger security practices
The non-profit digital library was also hit by at least two DDoS attacks in two days
La mairie de Guajará-Mirim au Brésil a été victime d'une cyberattaque qui a entraîné le vol de données. L'équipe technique de la mairie travaille actuellement pour récupérer le contrôle des systèmes et garantir la sécurité des informations. Les autorités locales ont promis de tenir la population inf...
Two former RAC employees have been handed suspended prison sentences for trading in personal data
Supply chain victim numbers surge as more than 240 million US residents are impacted by data breaches in Q3 2024
Une plainte fédérale accuse Visionworks of America Inc., basée à San Antonio, de ne pas avoir informé 40 000 clients d'une cyberattaque ayant exposé leurs données personnelles le 10 octobre 2024. Le plaignant, un client de l'Arizona, reproche à l'entreprise sa négligence dans la protection des donné...
De multiples vulnérabilités ont été découvertes dans Mitel Micollab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
The privacy flaw in Apple’s iPhone mirroring feature enables personal apps on an iPhone to be listed in a company’s software inventory when the feature is used on work computers
New BeaverTail malware targets tech job seekers via fake recruiters on LinkedIn and X
This post explores the risks and challenges of IP spoofing in cloud environments, particularly in setups using reverse proxies. It outlines various mitigation strategies to ensure accurate client IP identification for security purposes.
Barracuda researchers have identified a new wave of QR code phishing attacks that evade traditional security measures and pose a significant threat to email security
The UK government’s Cyber Team Competition offer applicants the chance to receive advanced training, mentorship and networking opportunities
Le groupe Healthcare Services Group (HSG) a déclaré une cyberattaque dans un dépôt auprès de la Securities and Exchange Commission (SEC), indiquant que des activités non autorisées ont eu lieu dans certains de ses systèmes le 9 octobre. L'entreprise a activé son processus de réponse à incident de cy...
The Australian government’s Cyber Security Bill 2024 will mandate cybersecurity standards for smart devices and introduce ransomware reporting requirements
The Appeals Centre Europe is supported by Meta’s Oversight Board Trust and certified by Ireland's media regulator
La communauté administrative d'Elbe-Heide a été victime d'une cyberattaque le 8 octobre, ce qui a nécessité l'arrêt de tous les systèmes pour prévenir d'éventuels dommages. Les processus numériques ont été suspendus, rendant les bureaux difficilement accessibles. Les experts travaillent à vérifier l...
Ivanti’s Cloud Services Appliance is being targeted by threat actors exploiting three zero-day bugs