[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Quishing Campaign Targets Chinese Citizens via Fake Official Documents
Cyber threat intelligence provider Cyble observed a new malicious QR code phishing campaign targeting Chinese citizens
> Cybersecurity Burnout Costing Firms $700m+ Annually
Hack The Box research claims employee burnout could be costing hundreds of millions in lost productivity
> 🇬🇧 Malicious activities linked to the Nobelium intrusion set (19 juin 2024)
Several cyberattacks against French diplomatic entities can be linked to the Nobelium intrusion set. Nobelium is an intrusion set active since at least October 2020, used against high-value targets, most likely for espionage purposes. Western diplomatic entities, such as embassies and Ministries...
> G7 to Develop Cybersecurity Framework for Energy Sector
The G7 nations agree to develop a cybersecurity framework for key technologies used to operate electricity, oil and natural gas systems
> CIISec Urges Employers to Target Young Talent in Gaming Centers
The Chartered Institute of Information Security has issued a new guide to help firms recruit more talent
> CDK
CDK, un fournisseur de logiciels pour les concessionnaires automobiles, a subi une cyberattaque qui a nécessité la fermeture de la majorité de ses systèmes. L'entreprise a informé ses clients de la situation et travaille à résoudre le problème, mais n'a pas encore fourni d'estimation du délai de rét...
> Olympia Gaming
Une cyberattaque a frappé Olympia Gaming, perturbant certaines opérations de casinos au Nevada. L'enquête est en cours pour déterminer l'ampleur de l'attaque et identifier les responsables. Aucun autre détail n'a été divulgué pour l'instant sur l'incident.
> 🇬🇧 Malicious activities linked to the Nobelium intrusion set (19 juin 2024)
🇬🇧 The following indicators of compromise are associated with the phishing campaigns by the Nobelium intrusion set described in the CERTFR-2024-CTI-006 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic.
> Fitzgerald, DePietro & Wojnas CPAs, P.C.
La société Fitzgerald, DePietro & Wojnas CPAs, P.C. a subi une cyberattaque en juin 2024, entraînant l'accès non autorisé à des informations sensibles de ses clients, notamment des numéros de sécurité sociale, des adresses et des informations financières. Suite à cette découverte, l'entreprise a env...
> U.S. Dermatology Partners
U.S. Dermatology Partners a subi une faille de sécurité le 19 juin 2024, entraînant l'accès non autorisé à des informations de patients, notamment des noms, dates de naissance et numéros d'assurance maladie. L'entreprise a pris des mesures pour renforcer la sécurité de ses systèmes et offre des serv...
> 92% of Organizations Hit by Credential Compromise from Social Engineering Attacks
A Barracuda report found that 92% of organizations experienced an average of six credential compromises caused by email-based social engineering attacks in 2023
> Fake Meeting Software Spreads macOS Infostealer
Recorded Future has found that Vortax, a purported virtual meeting software, is actually malicious software spreading three information stealers
> Themes from Real World Crypto 2024
In March, Trail of Bits engineers traveled to the vibrant (and only slightly chilly) city of Toronto to attend Real World Crypto 2024, a three-day event that hosted hundreds of brilliant minds in the field of cryptography. We also attended three associated events: the Real World Post-Quantum Cryptog...
> VMware Discloses Critical Vulnerabilities, Urges Immediate Remediation
VMware has disclosed critical vulnerabilities impacting its VMware vSphere and VMware Cloud Foundation products, with patches available for customers
> Quarter of Firms Suffer an API-Related Breach
Salt Security study finds 23% of organizations suffered a breach via production APIs in 2023
> Hudson school district
Le district scolaire de Hudson a été victime d'une cyberattaque qui a mis hors service son réseau et ses systèmes téléphoniques. Les détails de l'incident ne sont pas encore connus, mais les autorités ont déclaré qu'elles enquêtaient sur l'affaire. Les activités scolaires ont été perturbées en raiso...
> Report Reveals Record Exploitation Rate For Load Balancers
Action1 reveals cybercriminals are increasingly targeting NGINX and Citrix load balancers
> Los Angeles Public Health Department Discloses Large Data Breach
Los Angeles County Department of Public Health revealed a data breach impacting more than 200,000 individuals, with personal, medical and financial data potentially stolen
> Finding mispriced opcodes with fuzzing
Fuzzing—a testing technique that tries to find bugs by repeatedly executing test cases and mutating them—has traditionally been used to detect segmentation faults, buffer overflows, and other memory corruption vulnerabilities that are detectable through crashes. But it has additional uses you may no...
> Academics Develop Testing Benchmark for LLMs in Cyber Threat Intelligence
Researchers from the Rochester Institute of Technology introduced a benchmark designed to assess large language models’ performance in cyber threat intelligence applications