> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues and emerging threats. A significant privacy battle is brewing in California over updates to wiretapping laws that may limit private lawsuits against internet tracking. At the Pwn2Own Ireland event, hackers successfully exploited 32 zero-day vulnerabilities, showcasing the rapid pace at which security flaws are being targeted. In a concerning data breach, the FBI has removed a contractor linked to the exposure of sensitive employee information due to a missed patch, raising alarms about operational security in federal agencies. Meanwhile, ASOS confirmed a data breach that involved unauthorized push notifications claiming to leak customer data. Additionally, multiple vulnerabilities affecting Atlassian products and a critical flaw in Dell's System Update could allow attackers to gain unauthorized access. Overall, there is an evident rise in exploitation of known vulnerabilities and an increasing trend in data breaches across various sectors.
|
// AI-powered summary generated at 20:00
Recently Google published a blog about detecting browser data theft using Windows Event Logs.
There are some good points in the post for defenders on how to detect misuse of DPAPI calls attempting to grab sensitive browser data.
But, what about the Remote Debugging feature? This made me curious to r...
L'American Radio Relay League (ARRL), l'association nationale de radio amateur aux États-Unis, a confirmé avoir été victime d'une cyberattaque qui a affecté ses systèmes et services, notamment sa base de données "Logbook of The World". L'attaque a compromis des informations sensibles telles que des...
Dordt University suffered a data security incident due to a sophisticated cybersecurity incident, resulting in unauthorized access to its network and potential exposure of personal information between April 21, 2024, and May 16, 2024. The attack had been claimed by BianLian on June 13th, 2024.
Despite this setback, the auction house said bids can still be placed by phone and in-person
CPR said exploit builders in .NET and Python have been employed to deploy this malware
Australian Energy Privacy Breach, 15 May 2024: Victorian energy provide Sumo Energy slammed by data breach, as energy and internet customers have details leaked. Personal details of approximately 40,000 customers were compromised, including approximately 3,000 Australian passport numbers.
The post...
The National Cyber Security Centre launches an opt-in Personal Internet Protection service to safeguard individuals from cyber threats during the upcoming election
Google DeepMind’s SynthID can now be used to watermark AI-generated images, audio, text and video
Le district scolaire de Rockford, dans le Michigan, a été victime d'une cyberattaque par ransomware, ce qui a entraîné la fermeture de son réseau informatique et de ses téléphones. Les autorités scolaires ont pris des mesures pour protéger les données et ont contacté le FBI pour enquêter sur l'incid...
Santander has warned that customer and employee data has been breached following unauthorized access to a database held by a third-party provider
NCSC CTO argues current market rewards prioritize cost over security, hindering the development of secure technology
Voici le résumé de l'article :
La police fédérale australienne enquête sur une cyberattaque par ransomware contre une entreprise de soins de santé, MediSecure, qui a entraîné une violation de données. Le gouvernement australien a mis en place une réponse coordonnée pour gérer l'incident, avec la mi...
Trend Micro research claims CISOs are often ignored or dismissed as “nagging” by their board
Microsoft has released patches for three zero-day vulnerabilities including two actively exploited in the wild
La Central Contra Costa Transit Authority, un opérateur de bus et de paratransit en Californie, a subi une cyberattaque, ce qui a permis à un acteur non autorisé d'accéder à des fichiers et des données stockés dans son réseau. L'enquête est en cours pour déterminer quels sont les données précises qu...
Le Collège Ahuntsic à Montréal a fermé ses portes le 16 mai en raison d'une potentielle cyberattaque, entraînant l'annulation de toutes les activités d'enseignement et de formation continue. Les étudiants et employés ont été invités à ne pas utiliser les ordinateurs du collège pendant l'enquête. Le...
Comparitech said 2023 was a record year for breaches with 954 reported, up from 139 in 2022 and 783 in 2021
La chaîne de cliniques vétérinaires Ranzijn aux Pays-Bas a été victime d'une cyberattaque, entraînant le vol de données sur les animaux et leurs propriétaires. La société avertit ses clients de faire preuve de vigilance face à d'éventuels e-mails de phishing qui pourraient être envoyés en son nom. L...
Le 15 mai 2024, OBHC a été informé d’un incident perturbant certaines opérations de ses systèmes informatiques. L’entreprise a rapidement sécurisé ses systèmes, lancé une enquête avec des experts externes et informé les autorités. Le 20 mai 2024, l’enquête a révélé qu’un acteur malveillant avait acc...
The 15-year-old Ebury botnet is more active than ever, as ESET found 400,000 Linux servers compromised for cryptocurrency theft and financial gain