> TODAY'S SUMMARY (4 articles)
Today's cybersecurity landscape highlights significant threats and trends. South Korea's president is advocating for a comprehensive overhaul of cybersecurity measures to address vulnerabilities in the AI era. A critical flaw in Atlassian's data center software has been revealed, impacting eight enterprise products and raising concerns about widespread security issues. Additionally, a cyberattack on Arizona’s court system has resulted in the theft of personal information for over one million individuals, with data dating back 30 years. These incidents underscore the urgent need for enhanced security protocols and innovative solutions to combat evolving cyber threats.
|
// AI-powered summary generated at 04:00
We have identified a new buffer overflow vulnerability in Samsung’s baseband implementation (mainly used in Exynos chipsets). The vulnerability can be exploited to achieve arbitrary code execution in the baseband runtime.
The vulnerability we are disclosing in this advisory affected a wide range of...
We have identified several new heap buffer overflow vulnerabilities in Samsung’s baseband implementation (mainly used in Exynos chipsets): three different heap buffer overflows in the same function, to be precise.
The most critical of these vulnerabilities can be exploited to achieve arbitrary code...
Le commune de Fabriano a été victime d'une cyberattaque par ransomware, ce qui a limité l'accès aux serveurs du comune et pourrait causer des perturbations pour les utilisateurs qui accèdent au site institutionnel et aux services informatiques communautaires. Les enquêtes sont en cours pour détermin...
We have written extensively about remote baseband vulnerability research in the past, examining various vendors’ baseband OS micro-architectures and exploring their implementations for remotely exploitable bugs. So have many others. One might say, our research exists in the context in which it lives...
Le 29 juillet 2024, une activité inhabituelle a été détectée sur le réseau de Redbrick, entraînant une sécurisation immédiate du système et le lancement d’une enquête avec des experts en cybersécurité. L’enquête approfondie a permis de conclure que certains fichiers avaient probablement été exfiltré...
Une cyberattaque a frappé OneBlood, une organisation à but non lucratif qui fournit du sang à plus de 300 hôpitaux dans le sud-est des États-Unis. L'attaque a entraîné une panne de son système logiciel, affectant la livraison de produits sanguins aux hôpitaux de Floride. L'incident est actuellement...
Synnovis has rebuilt “substantial parts” of its systems following the Qilin ransomware attack on June 3, enabling the restoration of core blood supplies to NHS hospitals
Au cours du week-end, le centre de santé Patterson a détecté une activité inhabituelle sur certains de ses systèmes de réseau. Son personnel informatique a rapidement évalué la situation et s'efforce de restaurer les systèmes affectés. L'équipe du PHC a mis en place des procédures afin de pouvoir co...
Le Baker Center for Children and Families à Boston a subi une violation de sécurité en juillet 2024, avec un accès non autorisé à son environnement de stockage numérique détecté le 28 juillet. Entre le 26 et le 28 juillet, des fichiers contenant des informations sensibles, notamment des noms, adress...
CrowdStrike has acknowledged the claims by the USDoD hacktivist group, which has provided a link to download the alleged threat actor list on a cybercrime forum
Zydus Pharmaceuticals notified affected individuals that their personal information may have been exposed and offered twelve months of free TransUnion credit monitoring, identity restoration services, and up to $1,000,000 in identity theft insurance. The letter also provided instructions on placing...
La police du Bengale a lancé une enquête après avoir constaté que le centre de données de l'aile des crimes informatiques de l'État a été compromis, les autorités soupçonnent une atteinte intentionnelle de la part de la société privée qui gère le centre de données. Les enquêteurs ont découvert que l...
Despite bans on AI code generation tools, widespread use and lack of governance are creating significant security risks for organizations
A joint advisory by the UK, US and South Korea have warned of a global espionage campaign by a North Korea threat actor, Andariel, targeting CNI organizations
Le district scolaire du comté de Charleston a subi une panne de réseau causée par une activité suspecte, affectant les écoles et les communautés locales. Les experts en cybersécurité estiment que ce type d'incident peut avoir un impact important, mais il existe des solutions pour gérer les pannes d'...
Cisco Talos found that ransomware and BEC accounted for 60% of all cyber incidents in Q2 2024, with ransomware rising by 22% compared to Q1
Cryptography is a fundamental part of electronics and the internet that helps secure credit cards, cell phones, web browsing (fingers crossed you’re using TLS!), and even top-secret military data. Cryptography is just as essential in the blockchain space, with blockchains like Ethereum depending on...
SonicWall observed a surge in malware attacks in H1 2024, with strains becoming more adept at defense evasion
Appsbroker CTS found that nine in 10 IT leaders believe the severity of cyber-attacks has increased over the past year
Google Colab AI, now just called Gemini in Colab, was vulnerable to data leakage via image rendering.
This is an older bug report, dating back to November 29, 2023. However, recent events prompted me to write this up:
Google did not reward this finding, and Colab now automatically puts Notebook cont...