> TODAY'S SUMMARY (48 articles)
Today's cybersecurity landscape highlights several critical threats and trends. ASOS has confirmed a data breach linked to unauthorized notifications sent through a third-party communication platform. Hackers compromised three country-code domain registries, obtaining HTTPS certificates for Google domains, which poses a significant risk for impersonation attacks. The emergence of AI-powered phishing tools, such as BlueKit, facilitates quick creation of convincing phishing pages, increasing the threat of account hijacking. Ongoing vulnerabilities in various platforms, including a critical flaw in Atlassian products and a significant number of patched issues in Chrome and Android, underscore the need for timely updates. Additionally, a notable ransomware attack on Advantest exposed personal information, further emphasizing the escalating risks to sensitive data.
|
// AI-powered summary generated at 12:00
Mastery Charter High School a subi une faille de sécurité en septembre 2024, ce qui a potentiellement compromis les informations personnelles de certaines personnes. L'école a pris des mesures pour enquêter et remédier à la situation, notamment en engageant des experts en cybersécurité et en signala...
Webb Institute suffered a criminal cyberattack that may have accessed personally identifiable information (PII) of certain individuals. The incident occurred on or about September 15, 2024, and was discovered on May 23, 2025. The school is offering complimentary access to Experian IdentityWorks for...
An FBI and CISA alert highlighted false claims of breaches of voter registration databases, designed to undermine confidence in US elections
Western Montana Mental Health Center experienced a network disruption on September 15, 2024, which led to unauthorized access to certain files. The breach involved personal and protected health information of approximately 6 Maine residents. The organization is offering complimentary identity protec...
La société Zacros a été victime d'une cyberattaque avec ransomware, qui a crypté certaines de ses serveurs. Une équipe d'urgence a été mise en place pour enquêter sur l'incident et restaurer les systèmes, avec l'aide d'experts externes et de la police. L'ampleur de la cyberattaque n'est pas encore e...
If you’ve encountered cryptography software, you’ve probably heard the advice to never use a nonce twice—in fact, that’s where the word nonce (number used once) comes from. Depending on the cryptography involved, a reused nonce can reveal encrypted messages, or even leak your secret key! But common...
Universal Companies, Inc. is notifying individuals of a security incident that occurred on September 14, 2024, in which unauthorized access was gained to certain systems, potentially compromising personal information. The incident was discovered and promptly investigated, and affected individuals ar...
Albany College of Pharmacy and Health Sciences (ACPHS) a détecté une activité anormale sur son réseau le 14 septembre 2024, ce qui a conduit à une enquête approfondie. L'enquête a révélé que des données personnelles, notamment des noms, avaient pu être accessibles et acquises entre le 31 août et le...
Over 600 patients and employees of Lehigh Valley Health Network in Pennsylvania had their medical record photos hacked and posted on the internet
On September 14, 2024, Fitzemeyer & Tocci Associates detected unauthorized access to its systems that occurred between September 5 and September 14, 2024. The breach may have involved names and Social Security numbers of affected individuals. The cyberattack was claimed by abyss on 2024-09-23.
Microsoft will introduce new security capabilities for solution providers outside of kernel mode, preventing events like the CrowdStrike global outage
Le centre d'imagerie médicale a été victime d'une cyberattaque impliquant l'enseigne de ransomware Qilin. Cette dernière est prête à divulguer les données volées mais n'a pas encore revendiqué l'attaque. Des patients du centre ont rapporté des effets de l'attaque.
As we creep toward the end of the year, I want to offer some updates for the next book and some major changes to the way we facilitate sales. First and foremost, the 11th Edition of OSINT Techniques is over half-way completed and still slated for release on or before January 1, 2025. It will […]
Ireland’s Data Protection Commission launches inquiry into whether Google followed GDPR rules over AI model training
Ransomware gangs are targeting schools and higher education, with victims facing soaring ransom and recovery costs
Hands-on security testers need the best tools for the job. Tools you have faith in, and enjoy using all day long. Burp Suite has long been that tool, and now, it's faster than ever. We’ve listened to
TfL has revealed that some customer data was accessed in a recent cyber-attack, potentially including the bank details of 5000 people
Mastercard aims to strengthen its cybersecurity capabilities by acquiring Recorded Future, a leading provider of threat intelligence
Le site de prêt-à -porter LolaLiza a été victime d'une cyberattaque, ce qui signifie que les données personnelles de ses clients, notamment nom, adresse électronique, numéro de téléphone portable, adresse postale et date de naissance, pourraient avoir été compromises. La divulgation de ces informatio...
Lazarus Group has been observed impersonating Capital One staff to lure developers into downloading malware on open source repositories