> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
Cybercriminals have been observed disguising Octo2 as legitimate apps like Google Chrome and NordVPN
In the race to secure cloud applications, AWS Nitro Enclaves have emerged as a powerful tool for isolating sensitive workloads.
But with great power comes great responsibility-and potential security pitfalls. As pioneers in confidential computing security, we at
Trail of Bits have scrutinized the at...
SonicWall found that data breaches caused by malware attacks on US healthcare organizations have affected 14 million people so far in 2024
Cybersecurity leaders should prioritize response and recovery over prevention to effectively navigate the ever-evolving threat landscape, according to Gartner analysts
AppSec teams face a wide range of challenges when securing their API estate against attack threats. In our recent webinar, which demonstrated the enhanced API scanning features in Burp Suite Enterpris
The US Commerce Department wants to prohibit the sale or import of connected vehicles with Russian or Chinese-made hardware and software
Pavel Durov says he will share details of “bad actors” and clean up Telegram’s search function
L’année 2023 et le début de l’année 2024 ont été marqués par de nombreux incidents ciblant des entités du secteur social gérant des données à caractère personnel. Compte tenu des impacts qu’ont eu ces exfiltrations de données, le CERT-FR propose un retour d’expérience sur la gestion de ces...
A new Europol report argues that AI tools could revolutionize policing across the region
Le ministère de la Santé du Koweït a annoncé que les systèmes essentiels ont été restaurés après une cyberattaque qui a affecté certains hôpitaux et l'application Sahel. Les équipes techniques ont identifié les causes de la panne et ont mis en évidence des tentatives d'intrusion dans les systèmes, m...
Kryptina, a free Ransomware-as-a-Service tool available on dark web forums, is now being used by Mallox ransomware affiliates
The flaws are dangerous as the Houzez theme and Login Register plugin could allow privilege escalation by unauthenticated users
La VBG Unfallversicherung à Hambourg a été victime d'une attaque de ransomware sur l'un de ses serveurs, compromettant les adresses e-mail et les informations de contact des participants à ses séminaires en ligne. Les données potentiellement compromises incluent les adresses postales et les numéros...
An overall rise in cyber incidents coming from Russian-aligned adversaries in 2024 was accompanied by a decrease in high and critical-severity incidents
The Information Commissioner’s Office says it’s pleased that LinkedIn has temporarily suspended its generative AI model training
Le 23 septembre 2024, une activité inhabituelle a été détectée sur le réseau de l’organisation, entraînant des mesures immédiates de sécurisation. Une enquête appuyée par des experts en cybersécurité a révélé que certaines données avaient pu être acquises sans autorisation. À l’issue d’un examen app...
Officers in Germany have shut down 47 cryptocurrency exchanges they accused of facilitating cybercrime
Le 23 septembre 2024, Falco Sult a découvert qu’un de ses serveurs avait potentiellement été compromis. L’entreprise a rapidement fait appel à une société spécialisée en cybersécurité pour mener une enquête médico-légale afin de déterminer la nature et l’étendue de l’incident. L’enquête est toujours...
In February 2025, Transak USA LLC notified individuals of a data security incident involving potential unauthorized access to personal information. The cyberattack was claimed by stormous on 2024-10-31.
This post explains an attack chain for the ChatGPT macOS application. Through prompt injection from untrusted data, attackers could insert long-term persistent spyware into ChatGPT’s memory. This led to continuous data exfiltration of any information the user typed or responses received by ChatGPT,...