> TODAY'S SUMMARY (10 articles)
Today's cybersecurity news highlights several critical developments. Google has paused its Open Source Software Vulnerability Reward Program due to an influx of AI-generated, invalid vulnerability reports. In law enforcement news, an alleged leader of the ShinyHunters hacking group was arrested in Jordan and is aiding the FBI in identifying other members. Microsoft's official X account was compromised, promoting a crypto token, leading to an ongoing investigation. Additionally, a newly discovered zero-day vulnerability in Citrix NetScaler has been exploited shortly after previous flaws were patched. Finally, attackers are increasingly abusing legitimate remote monitoring and management (RMM) software, as indicated by a recent report showing it was involved in 45% of endpoint incidents.
|
// AI-powered summary generated at 08:00
McAfee said the library registers device information and drains battery life and mobile data
Users are tricked into connecting their cryptocurrency wallets to malicious smart contracts
Le Centre médical Mayanei Hayeshua en Israël a été victime d'une cyberattaque qui a perturbé ses services, notamment en désactivant les systèmes informatiques de tenue de dossiers. Les auteurs de l'attaque ne sont pas encore identifiés. En raison de l'attaque, l'hôpital n'accepte pas de nouveaux pat...
Attacks come after Prime Minister’s trip to Kyiv
Past and current staff and students are impacted
L'école nationale vétérinaire, agroalimentaire et de l'alimentation de Nantes, Oniris, a été victime d'une cyberattaque le lundi 7 août. Les données copiées par les attaquants comprennent les noms, prénoms et adresses mail professionnelles du personnel de l'établissement. Une plainte a été déposée e...
Latest innovation designed to speed up download process
Le Service de Santé de Madeira (Sesaram) au Portugal a été la cible d'une cyberattaque qui a provoqué une "dysfonction de son réseau informatique", entraînant la suspension des activités cliniques non urgentes. L'attaque a été décrite comme délibérée et malveillante, visant à perturber le fonctionne...
Des hackers liés à la Russie ont volé des informations hautement confidentielles lors d'une attaque contre l'entreprise britannique Zaun, spécialisée dans la sécurité périmétrique. Les données divulguées comprennent des détails sur des sites militaires et de renseignement sensibles au Royaume-Uni, t...
Phylum said the attack demonstrated a carefully crafted development cycle
ReversingLabs said the attackers displayed a sophisticated approach and techniques
Today, I published the following diary on isc.sans.edu: “Are Leaked Credentials Dumps Used by Attackers?“: Leaked credentials are a common thread for a while. Popular services like “Have I Been Pwned” help everyone know if some emails and passwords have been leaked. This is a classic problem: One da...
The US’ leading cybersecurity agency calls for us to “embody the hacker spirit” in its latest strategic plan
Guardio Labs detected the campaign and detailed its findings in a technical blog post
Le Trinkwasserverband (TWV) Stader Land, un fournisseur d'eau en Allemagne, a subi une cyberattaque qui a causé des "perturbations techniques" et affecté ses systèmes de messagerie. Bien que l'approvisionnement en eau soit une infrastructure critique, le TWV a assuré que la fourniture d'eau n'a pas...
Microsoft observed attackers continually attempting to compromise connected systems at the 2022 World Cup
Google Cloud figures also point to misconfiguration
Les systèmes informatiques de Crozer Health, situé dans le comté de Delaware, ont été victimes d'une attaque de ransomware par le propriétaire de l'entreprise, Prospect Medical Holdings Inc. Le ransomware est un type de logiciel malveillant qui crypte les fichiers, les rendant inutilisables jusqu'à ...
Security agencies urge timely patching
Risk assessment predicts critical infrastructure attacks could cost billions