> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
The data leak exposed personal data of 100m US citizens, resulting from a misconfigured database made accessible online
A CybSafe survey found that 52% of workers have not yet received any training on safe AI use
Le Centre Médical Universitaire (UMC) de Lubbock, au Texas, a été victime d'une attaque par rançon (ransomware) qui a perturbé ses systèmes, obligeant l'hôpital à détourner les patients vers d'autres établissements de santé locaux. Les services d'urgence et les cliniques de soins non urgents du cent...
UK train stations, including London Euston and Manchester Piccadilly, faced a cyber-attack displaying Islamophobic messages
Researchers discover mobile crypto drainer malware hidden in WalletConnect app garnering 10,000 downloads
CDC Biodiversité a été victime d'une cyberattaque par ransomware depuis le 26 septembre 2024. Une cellule de crise a été mise en place pour investiguer et résoudre l'incident, avec pour priorité la protection des informations des clients, fournisseurs et collaborateurs. L'objectif est de rétablir un...
The institute no longer requires regular password changes unless the authenticator has been compromised
Bitdefender is warning League of Legends fans not to fall for a phishing campaign designed to spread Lumma Stealer malware
Aurdel, filiale d'une entreprise de produits informatiques, Dist IT, a été victime d'une cyberattaque qui a causé un impact financier. L'attaque a commencé jeudi et les systèmes ont été mis hors ligne pour minimiser les dégâts, ce qui a entraîné des retards dans les livraisons. Les auteurs de l'atta...
L'affidé Qilin responsable de la cyberattaque contre Bertelkamp Automation a déposé, sur les serveurs de la franchise, des données qu'il attribue à Fleet Landing. La cyberattaque n'a pas été revendiquée sur le site vitrine de la franchise.
82% of all phishing sites target mobile devices, with 76% using HTTPS to appear secure
Une cyberattaque par ransomware en septembre dernier a exposé les informations de santé sensibles de plus de 400 000 personnes au sein d'American Addiction Centers, une chaîne de centres de réhabilitation pour la dépendance aux États-Unis. Les données volées incluent des numéros de sécurité sociale,...
Barton Gilman LLP suffered a data breach where personal information of a limited number of individuals was removed from their network due to unauthorized access between September 13, 2024, and September 26, 2024. The types of information involved include names and other personal data. The breach occ...
House GOP unveiled a bill to combat Chinese cyber threats to US infrastructure, led by CISA and FBI
On September 25, 2024, researchers from RedTeam-Pentesting.de published a report that details three vulnerabilities in the Firebox SSO Client & Agent software. The Firebox Authentication Gateway (SSO Agent) versions up to and including 12.10.2 and the Firebox Single Sign-On Client versions up to...
Authors: Boudewijn Meijer && Rick Veldhoven Introduction As defensive security products improve, attackers must refine their craft. Gone are the days of executing malicious binaries from disk, especially ones well known to antivirus and Endpoint Detection and Reponse (EDR) vendors. Now, atta...
Authors: Boudewijn Meijer && Rick Veldhoven Introduction As defensive security products improve, attackers must refine their craft. Gone are the days of executing malicious binaries from disk, especially ones well known to antivirus and Endpoint Detection and Reponse (EDR) vendors. Now, atta...
Adam Meyers, CrowdStrike VP for counter-adversary operations, appeared before a US congressional committee to answer questions about its July faulty software update
Authors: Boudewijn Meijer && Rick Veldhoven Introduction As defensive security products improve, attackers must refine their craft. Gone are the days of executing malicious binaries from disk, especially ones well known to antivirus and Endpoint Detection and Reponse (EDR) vendors. Now, atta...
Some 3191 email addresses for congressional staff are available on the dark web