[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (19 articles)

|

// AI-powered summary generated at 08:00

> Iran-Backed Peach Sandstorm Hackers Deploy New Tickler Backdoor
The hacking subsidiary of the Iranian Islamic Revolutionary Guard Corps (RGC) has targeted satellite, communications, oil and gas and government sectors in the US and UAE
> Money Laundering Dominates UK Fraud Cases
KPMG research finds money laundering accounted for the majority of fraud cases heard in the first half of 2024
> Kernex Microsystems (India) Ltd.
Conformément au Règlement 30 de la Securities and Exchange Board of India, la société informe qu'un incident de cybersécurité a eu lieu le 28 août 2024, ciblant son infrastructure informatique par une attaque par ransomware. L'équipe technique de l'entreprise, assistée par des experts externes en cy...
> South Korean Spies Exploit WPS Office Zero-Day
ESET uncovers a South Korean cyber-espionage campaign featuring a zero-day exploit for WPS Office
> Planned Parenthood
L'organisation à but non lucratif Planned Parenthood a confirmé avoir été victime d'une cyberattaque qui a affecté ses systèmes informatiques, obligeant l'organisation à prendre certaines parties de son infrastructure en ligne pour contenir les dégâts. Le groupe de ransomware RansomHub a revendiqué...
> Microsoft 365 Copilot Vulnerability Exposes User Data Risks
The flaw in Microsoft 365 Copilot allowed data theft using ASCII smuggling and prompt injection
> MOVEit Hack Exposed Personal Data of Half Million TDECU Users
The Texas Dow Employees Credit Union told the Maine Attorney General the MOVEit data breach compromised information of over 500,000 members
> Provisioning cloud infrastructure the wrong way, but faster
Today we’re going to provision some cloud infrastructure the Max Power way: by combining automation with unchecked AI output. Unfortunately, this method produces cloud infrastructure code that 1) works and 2) has terrible security properties. In a nutshell, AI-based tools like Claude and ChatGPT rea...
> FBI Flawed Data Handling Raises Security Concerns
A US Justice Department watchdog has found “significant weaknesses” in the FBI’s physical and online media storage and disposal processes
> Suspected Cyber-Attack Causes Travel Chaos at Seattle Airport
The Port of Seattle revealed system outages at the city’s airport may have been caused by a cyber-attack, affecting early Labor Day travel
> CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
Performing a root cause analysis & building proof-of-concept for CVE-2024-38063, a CVSS 9.8 Vulnerability In the Windows Kernel IPv6 Parser
> Uber Hit With €290m GDPR Fine
The Dutch data protection regulator has imposed a €290m GDPR fine on Uber for storing driver data in the US without adequate safeguards
> A Third of Organizations Suffer SaaS Data Breaches
AppOmni report claims number of companies suffering SaaS-related data breaches has jumped five percentage points over past year
> Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information
This post describes vulnerability in Microsoft 365 Copilot that allowed the theft of a user’s emails and other personal information. This vulnerability warrants a deep dive, because it combines a variety of novel attack techniques that are not even two years old. I initially disclosed parts of this...
> Direct Signalétique
L'entreprise Direct Signalétique, basée à Hazebrouck, a été victime d'une cyberattaque, entraînant une paralysie de ses activités. Selon les informations, "il n'y a plus rien qui marche" au sein de l'entreprise. Les détails de l'attaque et de ses conséquences ne sont pas précisés dans cet extrait d'...
> Portal do Governo do Estado de Alagoas
Le 27 août, le Portal du Gouvernement de l'État d'Alagoas et les sites hébergés sur ses serveurs ont été ciblés par une tentative d'attaque cybernétique, mais les mesures de sécurité mises en place par l'Institut de Technologie en Informática et Informação (Itec) ont permis de contenir l'attaque san...
> WordPress GiveWP POP to RCE (CVE-2024-5932)
A few days ago, Wordfence published a blog post about a PHP Object Injection vulnerability affecting the popular WordPress Plugin GiveWP in all versions <= 3.14.1. Since the blog post contains only information about (a part) of the POP chain used, I decided to take a look and build a fully functi...
> JAS Worldwide
La société de fret mondiale JAS Worldwide a confirmé avoir été victime d'une cyberattaque par ransomware, qui a perturbé ses opérations et ses services à ses clients. L'entreprise a rapidement sécurisé ses systèmes et a lancé une enquête avec l'aide d'experts en cybersécurité, et a mis en place des...
> Klinik am Kurpark
La Klinik am Kurpark à Reinhardshausen a été victime d'une grave attaque informatique qui a perturbé ses systèmes IT et a probablement compromis des données personnelles de patients, employés et partenaires commerciaux. Les autorités compétentes ont été informées et une équipe d'experts en sécurité...
> Newly Discovered Group Offers CAPTCHA-Solving Services to Cybercriminals
Greasy Opal is a Czech Republic-based hacking group selling products that can be used for deploying cyber-attacks