> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several significant threats and vulnerabilities. Wikimedia reported attempts by rogue AI agents to misuse its tools, indicating growing concerns over AI's potential for exploitation. Atlassian has patched a critical vulnerability affecting eight of its products, which could allow unauthenticated access to sensitive files. Additionally, Microsoft Exchange users are urged to apply a patch for a vulnerability (CVE-2026-96940) that enables unauthorized email access among authenticated users. Android's October update addresses 25 vulnerabilities, including a critical privilege escalation issue. Data breaches continue to be a major concern, with over 6.7 million accounts compromised at Angel One and personal information of over 1 million individuals stolen from Arizona's court system.
|
// AI-powered summary generated at 08:00
Liverpool fans were the most frequent and highest-value targets for ticket scams last season, losing over ÂŁ17,000 to fraudsters
Le ministère de l'Éducation (Mineduc) a déclaré avoir été victime d'une cyberattaque la semaine dernière, et a porté plainte contre les auteurs auprès des autorités compétentes. Les données sensibles des étudiants et du personnel sont protégées, et les mesures ont été prises pour éviter de nouveaux...
Le conseil municipal de Suva a été victime d'une cyberattaque avec ransomware qui a entraîné une perte de données et a perturbé ses opérations. Une équipe d'experts en cybersécurité a été assemblée pour restaurer le système et améliorer les mesures de sécurité. Le conseil a réussi à récupérer ses sy...
Cthulhu Stealer targets macOS, posing a major threat by disguising as legitimate software via DMG files
La société de prêt hypothécaire AnnieMac (American Neighborhood Mortgage Acceptance Company LLC) a été victime d'une cyberattaque qui a exposé les informations personnelles de 171 000 clients, notamment leurs noms et numéros de sécurité sociale. L'attaque a eu lieu entre le 21 et le 23 août 2024 et...
Le 23 août 2024, AnnieMac a détecté une activité suspecte sur certains systèmes de son réseau. Après avoir sécurisé les systèmes concernés et confirmé la sécurité globale du réseau, une enquête avec des spécialistes a révélé qu’un acteur inconnu avait accédé aux systèmes entre le 21 et le 23 août 20...
The US FAA has proposed new rules for aircraft to address cyber vulnerabilities caused by the increased interconnectivity of critical systems
The United States bore most of these cyber-threats, with a 46.15% rise in attacks compared to 2023
Recently, I found what appeared to be a regression or bypass that again allowed data exfiltration via image rendering during prompt injection. See the previous post here for reference.
Data Exfiltration via Rendering HTML Image Tags During re-testing, I had sporadic success with markdown rendering t...
FCC charges Lingo Telecom with $1m fine over voice deepfake during the 2024 New Hampshire primary election
The donation websites of the UK’s seven major political parties are missing critical security features to protect the accounts of donors, according to DataDome
Les Stadtwerke Burg, un fournisseur d'énergie allemand, a signalé un incident de sécurité dans son système d'information, entraînant des problèmes de communication, mais sans impact sur la fourniture d'énergie aux clients. Les données des clients sont considérées comme sécurisées et protégées. L'ent...
ESET claims new NGate Android malware relays NFC data to steal card details for ATM cash-out
Quarklabs researchers claim millions of contactless key cards could be cloned via a backdoor
Among the cryptographic missteps we see at Trail of Bits, “let’s build our own tool out of a hash function” is one of the most common. Clients have a problem along the lines of “we need to hash a bunch of different values together” or “we need a MAC” or “we need […]
The MoonPeak RAT as used by UAT-5394 showed a possible connection to North Korean threat Kimsuky
The LiteSpeed Cache flaw may expose millions of WordPress sites to severe security risks
Le groupe Cirano, qui comprend plusieurs médias à La Réunion, a été victime d'une attaque informatique rançongiciel massive la nuit dernière, paralysant les systèmes de diffusion. Les équipes travaillent à rétablir les fonctionnalités dans les meilleurs délais. Les médias touchés incluent Antenne Ré...
Australia’s data protection watchdog has decided to stop its investigation into US facial recognition company Clearview AI
Oregon Zoo revealed that an unauthorized actor potentially obtained payment card information used in transactions over six months