> TODAY'S SUMMARY (114 articles)
Today's cybersecurity landscape reveals several critical threats and trends. A member of the ShinyHunters hacking group has been detained in Jordan, cooperating with the FBI amid ongoing investigations into a significant data breach involving employee information. Meanwhile, vulnerabilities in Citrix NetScaler and Rejetto HFS have been actively exploited, with warnings from CISA regarding their severity and potential impact. Additionally, Denmark's population registry suffered a breach affecting 8.8 million individuals, raising concerns about data security in governmental databases. In the healthcare sector, IQVIA faced a hefty fine for inadequate data anonymization, underscoring the ongoing scrutiny over data protection practices. Lastly, Google has paused its open-source bug bounty program due to an influx of invalid AI-generated reports, reflecting challenges in managing AI vulnerabilities.
|
// AI-powered summary generated at 20:00
Authored by Margit Hazenbroek At Fox-IT (part of NCC Group) identifying servers that host nefarious activities is a critical aspect of our threat intelligence. One approach involves looking for anomalies in responses of HTTP servers. Sometimes cybercriminals that host malicious servers employ tactic...
Authored by Margit Hazenbroek At Fox-IT (part of NCC Group) identifying servers that host nefarious activities is a critical aspect of our threat intelligence. One approach involves looking for anomalies in responses of HTTP servers. Sometimes cybercriminals that host malicious servers employ tactic...
Consumers urged to think before they buy connected technology
Authored by Margit Hazenbroek At Fox-IT (part of NCC Group) identifying servers that host nefarious activities is a critical aspect of our threat intelligence. One approach involves looking for anomalies in responses of HTTP servers. Sometimes cybercriminals that host malicious servers employ tactic...
Patch Tuesday includes fixes for three actively exploited bugs
Russian-Moldovan national faces maximum 30-year jail stretch
Le district scolaire de Meredosia-Chambersburg a réussi à rétablir la majorité de son système informatique après avoir été la cible d'une cyberattaque de type ransomware, qui a rendu les ordinateurs inutilisables et a exigé une rançon. Les serveurs du réseau ont été déconnectés et retirés pour des r...
Planet Home Lending a informé ses clients d'une violation de données personnelles suite à une cyberattaque du groupe de ransomware LockBit exploitant la faille Citrix Bleed, affectant plus de 200 000 clients avec des informations telles que noms, adresses, numéros de sécurité sociale, numéros de prê...
2922 projects contained at least one unique secret, including from AWS, Redis and Google
L'Agence Nationale d'Investigation (NIA) de l'Inde a ouvert une enquête sur une attaque de ransomware contre le National Aerospace Laboratories (NAL), le plus grand organisme de recherche aérospatiale du pays, survenue le 15 novembre de l'année dernière. Le groupe criminel cybernétique LockBit est s...
Un agriculteur suisse a été victime d'une cyberattaque qui a permis aux pirates de prendre le contrôle de son robot de traite, ce qui a entraîné la mort d'une vache. Les cybercriminels ont demandé une rançon de 10 000 dollars à l'agriculteur. Cette attaque montre que les exploitations agricoles sont...
Sophos report based on 232 IR cases across 25 sectors from January 1 2022 to June 30 2023
This is a joint post with the PyPI maintainers; read their announcement here! This audit was sponsored by the Open Tech Fund as part of their larger mission to secure critical pieces of internet infrastructure. You can read the full report in our Publications repository. Late this summer, we perform...
TA402 launches new targeted phishing campaigns
CISA highlights links to newer Blacksuit variant
Le gouvernement du comté de Bladen a été victime d'une cyberattaque qui a entraîné des irrégularités dans leurs systèmes, et une équipe d'experts en cybersécurité a été mobilisée pour mener une enquête et sécuriser les serveurs. Malgré l'attaque, les services d'urgence sont restés opérationnels grâc...
Critical infrastructure providers under pressure from state-backed groups
Les écoles de North Muskegon seront fermées le mercredi 15 novembre en raison d'une violation de la cybersécurité. Notre département technique, le MAISD et l'équipe de cybersécurité de notre compagnie d'assurance travaillent ensemble pour enquêter. Nous n'avons pas accès aux téléphones ou à Internet...
Le district scolaire de Beaverton a été victime d'un incident de cybersécurité qui a potentiellement compromis les mots de passe des élèves, affectant l'accès à leurs emails, documents Google, Canvas et autres plateformes éducatives. Les équipes informatiques du district travaillent à la réinitialis...
Australian Pathology Ransomware Attack, 14 November 2023: Australian pathology company Tissupath, reported a ransomware attack at a third-party IT supplier, Core Desktop. About 130,000 victims of a data hack at pathology company TissuPath in August involving referrals issued between 2011 and 2020 wa...