> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
Utilise Azure RunCommands for execution and lateral movement.
La société japonaise Casio Computer Co. a confirmé une importante cyberattaque qui a permis à des parties non autorisées d'accéder à son réseau, entraînant une panne de système et des perturbations de services. L'entreprise a rapidement signalé l'incident aux autorités compétentes et a engagé des ex...
Drug and Alcohol Treatment Services, Inc., basée à Scranton, Pennsylvanie, a accepté de régler une action collective suite à une cyberattaque par ransomware et une violation de données survenue en octobre 2024. L'attaque a entraîné le vol des informations de santé et personnelles de 22 215 patients...
Infosecurity recently joined an Immersive Labs Cyber Drill to experience how organizations can enhance their preparedness through training and simulations
Cisco Talos has observed the financially motivated threat actor targeting organizations globally with a MedusaLocker ransomware variant called “BabyLockerKZ”
Le groupe Hospi Grand Ouest, qui gère neuf établissements de santé en Bretagne et Pays-de-la-Loire, a été victime d'une cyberattaque vendredi 4 octobre 2024, entraînant des perturbations sur son réseau. L'attaque est toujours en cours et les établissements doivent faire face à des tentatives d'intru...
A UK court has fined Sellafield Ltd ÂŁ332,500 for cybersecurity failings related to the running of the Sellafield nuclear facility
The Counter Ransomware Initiative has released new guidance discouraging organizations from making ransomware payments
La société de recouvrement de dettes Cabot Financial a été victime d'une cyberattaque, ce qui pourrait donner accès aux hackers aux détails personnels de milliers de clients. L'entreprise a déclaré l'incident à la Commission de protection des données et au Centre national de sécurité informatique et...
Le Pacific Pulmonary Medical Group (PPMG) en Californie a été victime d'une cyberattaque par l'Everest Ransomware Team, qui a volé des informations de santé protégées et des données personnelles de patients, notamment des numéros de sécurité sociale et des détails d'assurance santé. Les données ont...
The new LiteSpeed Cache flaw (CVE-2024-47374) allows unauthenticated code injection across more than six million active installations
HCF Management Inc. a informé les victimes d'une cyberattaque survenue en septembre 2024, qui a permis à un tiers non autorisé d'accéder à des informations sensibles telles que des numéros de sécurité sociale, des informations médicales et des coordonnées personnelles. L'enquête a révélé que l'accès...
Microsoft and the US government have collectively seized over 100 websites used by Russian nation-state actor Star Blizzard
China-aligned CeranaKeeper discovered targeting Thai govt institutions using cloud services for data exfiltration
As Felicity Oswald hands over to the new NCSC CEO, she reflects on why cyber security and intelligence are so connected.
A new report by Red Canary has found that while cybersecurity budgets have risen, many security leaders still feel overwhelmed by the growing threat landscape
The ICO blamed the Police Service of Northern Ireland for procedural failings that exposed the personal data of 9843 personnel, putting police officers at risk
L'État indien d'Uttarakhand a été victime d'une cyberattaque massive qui a paralysé son système d'information, rendant plus de 90 sites web gouvernementaux inaccessibles, y compris le centre d'appel du ministre en chef. L'attaque a également affecté les systèmes de bureaux électroniques et les servi...
Researchers see an uptick in crypto-doubling investment scams following the first presidential debate
Egress found that attackers are becoming more adept at bypassing email security, such as using compromised accounts and the use of commodity campaigns