> TODAY'S SUMMARY (34 articles)
Today's cybersecurity landscape highlights several critical threats and trends. A significant zero-day vulnerability (CVE-2026-88) in Citrix NetScaler has been actively exploited, prompting urgent updates for affected systems. Similarly, the Rejetto HFS flaw (CVE-2026-61500) is being targeted, allowing attackers to gain administrative access and execute remote code. In the realm of healthcare, a bipartisan bill has been passed to strengthen cybersecurity measures, following over 730 breaches affecting hundreds of millions of Americans last year. On the AI front, Google has paused its open-source bug bounty program due to a surge in invalid, AI-generated vulnerability reports. Additionally, recent arrests connected to cybercrime groups like ShinyHunters signal ongoing efforts to combat organized hacking networks.
|
// AI-powered summary generated at 12:00
L'école spécialisée Astrid-Lindgren-Schule à Lemgo a été victime d'une cyberattaque qui a toujours des conséquences. Les systèmes de téléphone et d'e-mail de l'école ne fonctionnent toujours pas. Des experts travaillent actuellement à restaurer les données qui ont été cryptées lors de l'attaque. Ini...
La clinique TissuPath a envoyé une lettre de notification à tous les médecins référents principaux concernant l'incident et est en train de contacter toutes les personnes affectées. Le Centre de cybersécurité australien (Australian Cyber Security Centre - ACSC) de l'Australian Signals Directorate es...
SentinelOne observed that the imitating application targeted users within work environments
Les Stadtwerke Neumünster (SWN) en Allemagne ont été victimes d'une cyberattaque de type espionnage, ce qui les a conduits à mettre hors ligne tous leurs systèmes informatiques par mesure de précaution. Bien que les services essentiels tels que l'électricité, le gaz, le chauffage et l'internet reste...
Group-IB said cyber-criminals used the flaw to create archives packaged with DarkMe, GuLoader and Remcos RAT
The Check Point report also highlights an evolution of ransomware tactics
Many security-critical off-chain applications use a simple block delay to determine finality: the point at which a transaction becomes immutable in a blockchain’s ledger (and is impossible to “undo” without extreme economic cost). But this is inadequate for most networks, and can become a single poi...
Cybersecurity provider Barracuda used AI-powered account profiling to detect nearly a million cyber incidents in 2023
ITRC data finds 69% have suffered multiple identity crimes
Today, I published the following diary on isc.sans.edu: “More Exotic Excel Files Dropping AgentTesla”: Excel is an excellent target for attackers. The Microsoft Office suite is installed on millions of computers, and people trust these files. If we have the classic xls, xls, xlsm file extensions, Ex...
Credit reporting firm accused of sending millions of unwanted emails
Researchers find four vulnerabilities in popular model
Australian Telemarketer Breach, 23 August 2023: Pareto Phone, a Brisbane-based telemarketing company that contacts potential donors on behalf of charities, was hacked by cybercriminals in April. 70 charities, including Amnesty International Australia, Australian Conservation Foundation, Wilderness S...
La Haute École de Lucerne (HSLU) a été victime d'une attaque de ransomware ciblant une de ses environnements informatiques spécifiques, séparée des services IT centraux. Cette attaque n'a pas affecté le fonctionnement général de l'école car elle a visé principalement le département informatique. Les...
L'entreprise Heuschen & Schrouff, basée à Landgraaf et spécialisée dans la vente en gros de produits alimentaires asiatiques, a été victime d'une cyberattaque paralysant tous ses systèmes. Selon des sources de la chaîne provinciale L1, les pirates informatiques exigeraient une rançon sous forme de p...
The research also highlights a shift in hacker tactics toward exploiting network server flaws
Le Dakota Eye Institute a également rapporté une brèche de données touchant 107 143 patients, sans préciser la nature de l'incident mais a renforcé ses politiques de sécurité des données en réponse.
ESET's investigation also revealed that certain Spacecolon versions contain Turkish strings
DIGIHEALS will call for proposals for technologies originally designed for national security
Today, I published the following diary on isc.sans.edu: “Have You Ever Heard of the Fernet Encryption Algorithm?“: In cryptography, there is a gold rule that states to not develop your own algorithm because… it will be probably weak and broken! They are strong algorithms (like AES) that do a great j...