> TODAY'S SUMMARY (10 articles)
Today's cybersecurity news highlights several critical developments. Google has paused its Open Source Software Vulnerability Reward Program due to an influx of AI-generated, invalid vulnerability reports. In law enforcement news, an alleged leader of the ShinyHunters hacking group was arrested in Jordan and is aiding the FBI in identifying other members. Microsoft's official X account was compromised, promoting a crypto token, leading to an ongoing investigation. Additionally, a newly discovered zero-day vulnerability in Citrix NetScaler has been exploited shortly after previous flaws were patched. Finally, attackers are increasingly abusing legitimate remote monitoring and management (RMM) software, as indicated by a recent report showing it was involved in 45% of endpoint incidents.
|
// AI-powered summary generated at 08:00
Uptycs found that QwixxRAT spread via Telegram and Discord
The disclosure occurred within Freedom of Information responses issued by law enforcement
Les écoles de la ville de Cleveland ont été victimes d'une attaque de ransomware le mardi 15 août, affectant moins de 5% des appareils connectés au réseau de l'école. Malgré cette attaque, la majorité des appareils utilisés par les élèves, le personnel et les enseignants n'ont pas été touchés, assur...
Feedzai report details the opinions of anti-money laundering pros
The PSNI Chief Constable said he is confident the data is in the hands of Dissident Republican groups
Knight Barry Title, Inc. a signalé une violation de données au procureur général du Texas après qu'une cyberattaque a permis à des pirates d'accéder au réseau informatique de l'entreprise et aux informations sensibles des consommateurs, telles que les noms, numéros de sécurité sociale, informations...
Results come from analysis of 100 leading cybercrime sites
Device takeover, account hijacking and info theft could occur
One of the biggest challenges for blockchain developers is objectively assessing their security posture and measuring how it progresses. To address this issue, a working group of Web3 security experts, led by Trail of Bits CEO Dan Guido, met earlier this year to create a simple test for profiling th...
The breach was discovered on July 9 after an unauthorized third party accessed ADSC’s IT infrastructure
Trellix cybersecurity researchers discussed the implications of these flaws in a new blog post published on Sunday
La société Clorox a annoncé le lundi avoir été victime d'une cyberattaque qui a perturbé certaines de ses opérations commerciales. En réponse à cette attaque, l'entreprise a déconnecté certains systèmes suite à une activité non autorisée. Clorox a mis en œuvre des solutions de contournement pour cer...
Group-IB said Gigabud doesn’t execute malicious actions immediately but waits for user authorization
The vulnerabilities put critical infrastructure organizations at risk of attacks such as remote code execution (RCE) and denial of service (DoS)
Lundi matin, les écoles publiques du comté de Prince George ont été victimes d'une cyberattaque. Selon PGCPS, l'attaque a affecté 4 500 comptes utilisateurs sur 180 000, principalement des comptes de personnel. Les principaux systèmes d'information pour les entreprises et les étudiants, Oracle et Sc...
A Polish national arrested in the US could face up to 45 years in prison if convicted on all counts
Environ 300 détaillants indépendants ont été touchés par une cyberattaque chez le fournisseur informatique Swan Retail, ce qui a affecté leur capacité à commercer en ligne, à traiter les paiements et à honorer les commandes depuis dimanche, selon les informations de Retail Week.
Une cyberattaque a visé une maison d'édition à Munich, avec des données potentiellement dérobées et déposées sur le Darknet. Des personnalités telles que Bettina Wulff, Uli Hoeneß ou Bushido, qui ont publié leurs biographies chez cet éditeur, n'ont cependant pas à s'inquiéter. Selon Setzler, l'édite...
The security flaws were uncovered by Patchstack security researcher Rafie Muhammad
Les groupes de cyber-délinquants GhostSec et Stormous revendiquent un vol de plus de 70 giga-octets de données sur le système d’information d’Econocom. Certains fichiers semblent trop récents pour être issus du vol de données par le groupe Pysa en 2020, suggérant une nouvelle intrusion. Econocom n'a...