[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (22 articles)

|

// AI-powered summary generated at 08:01

> Relishing new Fickling features for securing ML systems
We’ve added new features to Fickling to offer enhanced threat detection and analysis across a broad spectrum of machine learning (ML) workflows. Fickling is a decompiler, static analyzer, and bytecode rewriter for the Python pickle module that can help you detect, analyze, or create malicious pickle...
> Securing Perimeter Products Must Be a Priority, Says NCSC
UK’s National Cyber Security Centre warns of dangers of insecure perimeter products
> Drugs and Cybercrime Market Busted By German Cops
German police have dismantled the country’s largest underground marketplace: Crimemarket
> FINTRAC (Financial Transactions and Reports Analysis Centre of Canada)
L'agence canadienne de renseignement financier, FINTRAC, a été contrainte de déconnecter ses systèmes d'entreprise suite à un incident de cybersécurité survenu pendant le week-end. Bien que la nature de l'incident n'ait pas été révélée, l'agence a précisé que cela n'impliquait pas ses systèmes de re...
> South St. Paul Public Schools
Les écoles publiques de South St. Paul ont signalé une perturbation technologique en cours due à une activité non autorisée dans leur réseau informatique. Ils ont mis leurs systèmes hors ligne pour isoler le problème et ont engagé une entreprise de cybersécurité pour enquêter et restaurer les systèm...
> Who Am I? Conditional Prompt Injection Attacks with Microsoft Copilot
Building reliable prompt injection payloads is challenging at times. It’s this new world with large language model (LLM) applications that can be instructed with natural language and they mostly follow instructions… but not always. Attackers have the same challenges around prompt engineering as norm...
> American Renal Associates
L'American Renal Associates (désormais connu sous le nom d'Innovative Renal Care), qui compte plus de 230 établissements aux États-Unis, est devenu la dernière victime en date d'une attaque de ransomware dans le secteur clinique-hospitalier. Récemment, le groupe Medusa a mis à la disposition du publ...
> Stock Development, LLC
On March 2, 2024, Stock Development discovered that an unauthorized third party had accessed a portion of its network from April 25, 2023, through March 2, 2024. The breach may have exposed personal information—including full names, dates of birth, contact details, government identification numbers,...
> How we applied advanced fuzzing techniques to cURL
Near the end of 2022, Trail of Bits was hired by the Open Source Technology Improvement Fund (OSTIF) to perform a security assessment of the cURL file transfer command-line utility and its library, libcurl. The scope of our engagement included a code review, a threat model, and the subject of this b...
> Biden Warns Chinese Cars Could Steal US Citizens' Data
President Biden warned that connected vehicles built in China could be used to steal sensitive data of US citizens and critical infrastructure
> When try, try, try again leads to out-of-order execution bugs
Have you ever wondered how a rollup and its base chain—the chain that the rollup commits state checkpoints to—communicate and interact? How can a user with funds only on the base chain interact with contracts on the rollup? In Arbitrum Nitro, one way to call a method on a contract deployed on […]
> Five Eyes Warn of Ivanti Vulnerabilities Exploitation, Detection Tools Insufficient
Government agencies from the Five Eyes coalition said that Ivanti’s own tools are not sufficient to detect compromise
> UK Home Office Breached Data Protection Law with Migrant Tracking Program, ICO Finds
The Home Office failed to assess the privacy intrusion of the continuous collection of migrants’ location information in breach of UK data protection law, according to the ICO
> Hansab
Suite à un incident cybernétique, la société de sécurité et de logiciels Hansab a subi des perturbations importantes de ses systèmes informatiques, mais les opérations bancaires en Estonie, y compris les distributeurs automatiques, les paiements par carte et la banque en ligne, n'ont pas été affecté...
> Witherspoon Brajcich McPhee, PLLC
Le 1er mars 2024, WBM a détecté une activité suspecte sur son réseau. L’entreprise a rapidement vérifié la sécurité de ses systèmes et lancé une enquête approfondie avec des experts externes. L’enquête a révélé qu’un acteur non autorisé avait eu un accès intermittent à certains systèmes entre le 5 j...
> Pharma Giant Cencora Reports Cybersecurity Breach
The breach was discovered on February 21 2024, according to an SEC filing published on the same day
> Savvy Seahorse Targets Investment Platforms With DNS Scams
Infoblox said Savvy Seahorse uses fake ChatGPT and WhatsApp bots to lure victims
> Bad Schwalbach
Suite à une présumée attaque de pirates informatiques, le système de la ville de Bad Schwalbach (Rheingau-Taunus) a été mis hors service. Toutes les connexions Internet ont été coupées par précaution, et l'administration municipale n'est actuellement accessible que par téléphone et par une boîte e-m...
> Dark Web Market Revenues Rebound but Sector Fragments
Chainalysis study of crypto flows reveals darknet markets made $1.7bn in 2023
> US Government Warns Healthcare is Biggest Target for BlackCat Affiliates
The US government advisory warns healthcare organizations are being targeted by BlackCat amid an ongoing cyber-incident affecting Change Healthcare