> TODAY'S SUMMARY (114 articles)
Today's cybersecurity landscape reveals several critical threats and trends. A member of the ShinyHunters hacking group has been detained in Jordan, cooperating with the FBI amid ongoing investigations into a significant data breach involving employee information. Meanwhile, vulnerabilities in Citrix NetScaler and Rejetto HFS have been actively exploited, with warnings from CISA regarding their severity and potential impact. Additionally, Denmark's population registry suffered a breach affecting 8.8 million individuals, raising concerns about data security in governmental databases. In the healthcare sector, IQVIA faced a hefty fine for inadequate data anonymization, underscoring the ongoing scrutiny over data protection practices. Lastly, Google has paused its open-source bug bounty program due to an influx of invalid AI-generated reports, reflecting challenges in managing AI vulnerabilities.
|
// AI-powered summary generated at 20:00
Security advisory details TTPs of prolific threat actors
Postal service was breached in January 2023
Le SIAAP, organisme public d'assainissement de la région parisienne, a été touché par une cyberattaque d'envergure le 17 novembre, affectant uniquement son système informatique de gestion. Les services d'assainissement opérationnels ne sont pas impactés, et des mesures ont été prises avec l'aide de...
Famed institution warns of ongoing disruption
Le 17 novembre 2023, la municipalité de Mössingen a subi une cyberattaque, entraînant la mise hors service complète de son infrastructure informatique. La ville travaille avec des autorités et des prestataires externes pour résoudre le problème, mais la durée de l'incident est encore inconnue. Le 20...
Le serveur du jeu en ligne indépendant "Ethyrial: Echoes of Yore" a été victime d'une attaque par ransomware, entraînant la perte de 17 000 comptes de joueurs, y compris leurs objets, titres et progression dans le jeu. Les développeurs de Gellyberry Studios ont décidé de reconstruire manuellement ch...
The CCZT program incorporates foundational principles from leading sources such as CISA and NIST
Attackers sought crypto donations of $100-$5000 using Bitcoin, Litecoin and Ethereum addresses
L'Etelä-Savon ammattiopisto Esedu en Finlande est actuellement affecté par une cyberattaque qui perturbe les cours en ligne, les systèmes et serveurs ayant dû être arrêtés. L'institution évalue l'ampleur du problème avec l'aide de son personnel informatique et d'experts externes, et a signalé l'inci...
A report described the coordinated attack, in which 22 critical infrastructure firms were targeted
Skimming threat actors ramp up their activity just in time for the holiday season
Le groupe Sabre Insurance a été victime d'une cyberattaque le 16 novembre 2023, mais ses contrôles de sécurité informatique ont réagi rapidement et efficacement pour contenir l'attaque avant que des zones sensibles ne soient compromises. L'entreprise, avec l'aide d'un partenaire spécialisé en sécuri...
WithSecure report highlights widespread code reuse
ALPHV/BlackCat tries unusual extortion technique
International Shoppes, LLC et Diplomatic Duty Free Shops of New York, Inc. ont subi un incident de cybersécurité le 1er décembre 2023, affectant leurs systèmes informatiques contenant des informations personnelles. Bien qu'il n'y ait aucune preuve d'utilisation abusive des informations, ils informen...
Fraudsters operated from Ukrainian call centers
Australian Football Cyber Attack, 16 November 2023: Port Adelaide Football Club Hackers post Port files online. Member data is believed not to be compromised though members should be wary of communications from the club.
The post Incident: Port Adelaide Football Club Hackers post Port files online a...
The initiative aligns with President Biden’s recent Executive Order
TL;DR: We identified 11 security vulnerabilities in YOLOv7, a popular computer vision framework, that could enable attacks including remote code execution (RCE), denial of service, and model differentials (where an attacker can trigger a model to perform differently in different contexts). Open-sour...
Nitrogen serves as initial-access malware, using obfuscated Python libraries for stealth