> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several significant threats. A security researcher has identified a KVM guest-host escape flaw in Firecracker MicroVMs, potentially impacting AWS environments. Dell has released patches for 18 critical vulnerabilities in its Container Storage Modules (CSM), which could allow attackers to gain unauthorized access to storage and Kubernetes systems. Additionally, the hacking group ShinyHunters has exploited a zero-day vulnerability in PeopleSoft, raising alarms about increased risks for enterprises using the Oracle software. Organizations are advised to implement stringent security measures in response to these emerging threats.
|
// AI-powered summary generated at 04:00
Veeam found that 75% of organizations suffered at least one ransomware attack last year, with 26% hit four or more times
An advisory from the FBI and CISA says threat actors are deploying the Androxgh0st malware for victim identification and exploitation in target networks
La räddningstjänsten (service de secours) de la région de Jämtland en Suède a été la cible d'une cyberattaque dans la nuit de mercredi à jeudi, affectant leur système d'alerte. Le personnel a été alerté de l'incident après minuit grâce aux avertissements de leur système informatique. Actuellement, l...
Municipality of CalviĂ on the Spanish island of Majorca was hit by a ransomware attack last weekend
GitHub urges customers to apply a new patch and take action if impacted by credential rotation
La station de radio Donau 3 FM à Ulm a été victime d'une cyberattaque mercredi après-midi, entraînant la paralysie de ses ordinateurs. Face à cette situation, l'équipe a dû improviser en utilisant une table de mixage externe et des lecteurs de CD personnels pour continuer à diffuser son programme, p...
La Loterie des Îles Vierges a reporté son tirage du 18 janvier en raison d'une violation technologique qui a provoqué de multiples défaillances dans son système informatique. Tous les services de vente au détail et administratifs ont été suspendus jusqu'à nouvel ordre, et une équipe informatique ain...
The malware targets browsers, steals crypto wallet and messaging app data, and collects system information
La division Municipal Water de Veolia North America a été touchée par un incident de rançongiciel, affectant certaines applications logicielles et systèmes, ce qui a entraîné des retards dans les systèmes de paiement en ligne des clients. Veolia a pris des mesures défensives, comme la mise hors lign...
Le géant de la gestion de l'énergie et de l'automatisation, Schneider Electric, a été victime d'une attaque de ransomware Cactus, entraînant le vol de données d'entreprise au sein de sa division Sustainability Business le 17 janvier. L'attaque a perturbé la plateforme cloud Resource Advisor de l'ent...
We are disclosing LeftoverLocals: a vulnerability that allows recovery of data from GPU local memory created by another process on Apple, Qualcomm, AMD, and Imagination GPUs. LeftoverLocals impacts the security posture of GPU applications as a whole, with particular significance to LLMs and ML model...
L'entreprise Ecosystem a été victime d'une cyberattaque par le ransomware Akira le 17 janvier, ayant entraîné l'impact de serveurs internes et la suspension temporaire de ses services en ligne. Malgré la réouverture progressive des services et la restauration de la messagerie électronique, Ecosystem...
Kaspersky experts developed the tool after analyzing Shutdown.log, a file retaining reboot information
In its latest Email Security Risk Report, Egress found that businesses were 10% more negatively affected by phishing attacks in 2023 than in 2022
Ollie Whitehouse, the NCSC’s new Chief Technology Officer, outlines the cyber security challenges he’ll be prioritising.
Comparitech revealed crypto heists increased in volume by 42% last year
Volexity detects 1700 compromised Ivanti VPN devices following publication of two zero-days last week
L'Université d'État du Kansas a subi une perturbation de certains de ses systèmes réseau, notamment le VPN, les e-mails K-State Today et les vidéos sur Canvas ou Mediasite, suite à un incident de cybersécurité survenu autour du mardi 16 janvier. Les systèmes affectés ont été déconnectés pour enquête...
Group-IB report lifts the lid on infamous crypto-drainer malware Inferno Drainer
Netscout found a spike from 10,000 to 143,957 devices in scans between December 2023 and early January 2024