> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues and emerging threats. A significant privacy battle is brewing in California over updates to wiretapping laws that may limit private lawsuits against internet tracking. At the Pwn2Own Ireland event, hackers successfully exploited 32 zero-day vulnerabilities, showcasing the rapid pace at which security flaws are being targeted. In a concerning data breach, the FBI has removed a contractor linked to the exposure of sensitive employee information due to a missed patch, raising alarms about operational security in federal agencies. Meanwhile, ASOS confirmed a data breach that involved unauthorized push notifications claiming to leak customer data. Additionally, multiple vulnerabilities affecting Atlassian products and a critical flaw in Dell's System Update could allow attackers to gain unauthorized access. Overall, there is an evident rise in exploitation of known vulnerabilities and an increasing trend in data breaches across various sectors.
|
// AI-powered summary generated at 20:00
The UK AI Safety Institute tested four mainstream AI chatbots with basic jailbreak attacks
The malware-as-a-service Grandoreiro Trojan is now targeting 1500 global banks, says IBM
Un établissement scolaire de Hong Kong, le Hong Kong Institute of Contemporary Culture Lee Shau Kee School of Creativity, a été victime d'une cyberattaque par ransomware, entraînant la fuite de données personnelles de plus de 600 personnes. Les hackers ont encrypté 8 To de données, notamment des inf...
Two Chinese nationals have been charged with laundering over $73m in a pig butchering scheme
L'attaque contre Allied Telesis a eu lieu entre le 30 avril 2024 et le 20 mai 2024, période durant laquelle un acteur non autorisé a accédé à certains systèmes de l’entreprise et en a extrait des fichiers. Une telle attaque a été revendiquée le 27 mai 2024 sous la bannière de LockBit 3.0.
Community Counseling of Bristol County, Inc. (CCBC) has experienced a data security incident where an unauthorized party gained access to their network, potentially compromising personal and protected health information. The incident occurred between May 18, 2024, and May 20, 2024, and CCBC is offer...
This post is part of a series about machine learning and artificial intelligence.
Adversaries often leverage supply chain attacks to gain footholds. In machine learning model deserialization issues are a significant threat, and detecting them is crucial, as they can lead to arbitrary code execution....
Le comté de Malheur a évité une grave atteinte à sa sécurité en ligne grâce à une intervention rapide de son équipe d'information, qui a détecté et contrecarré une tentative de piratage informatique le 19 mai. L'attaque a été détectée tôt dimanche matin et les systèmes ont été sécurisés dans les 20...
Le centre de soins psychiatriques d'Okayama au Japon a été victime d'une cyberattaque par ransomware, entraînant la fuite de données personnelles de jusqu'à 40 000 patients, notamment leurs noms, adresses, dates de naissance et informations médicales. L'attaque a eu lieu le 19 mai et a été détectée...
Australian Medical Data Breach, 16 May 2024: E-script provider MediSecure is the health organisation at the centre of the large-scale ransomware data breach. Early indicators suggest the incident originated from one of our third-party vendors.
The post Incident Updated: Australian government invest...
Multiple UK councils have warned that residents’ personal data may have been compromised following a ransomware attack on NRS Healthcare
A new banking Trojan targeting Android devices shows multifaceted capabilities
AddComm, une entreprise de services de santé, a été victime d'une cyberattaque par ransomware, ce qui a entraîné la fuite de données sensibles, notamment des numéros de sécurité sociale (BSN). Les utilisateurs s'inquiètent de la sécurité de leurs données et critiquent la manière dont les autorités o...
Electronic prescriptions provider MediSecure said the attack originated from a third-party vendor, and has impacted individuals’ personal and health information
Microsoft warned Storm-1811 started vishing attacks in April to gain access to target devices
This post will guide you through using AddressSanitizer (ASan), a compiler plugin that helps developers detect memory issues in code that can lead to remote code execution attacks (such as WannaCry or this WebP implementation bug). ASan inserts checks around memory accesses during compile time, and...
Proofpoint said the attackers modified registry key names for persistence
Car manufacturer Nissan revealed that over 53,000 of its North America employees had their social security numbers accessed by a ransomware attacker
Recently Google published a blog about detecting browser data theft using Windows Event Logs.
There are some good points in the post for defenders on how to detect misuse of DPAPI calls attempting to grab sensitive browser data.
But, what about the Remote Debugging feature? This made me curious to r...
Nearly six out of ten surveyed ClubCISO members are confident AI is used securely in their organizations