[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 12:00

> T-Mobile to Pay $350m Settlement in Breach Case
Tens of millions were impacted by 2021 incident
> NIST Updates Healthcare Security Guidance
The updated document provides more actionable measures for healthcare organizations
> CVE-2022-22252: Huawei HWLog Vmalloc Use-After-Free
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to disclose sensitive information from the kernel. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that facilitate better s...
> Indian Insurance Portal Policybazaar Suffers Breach
The company claims that "no significant customer data was exposed" in the incident
> NCSC Tests Cyber Advisor Program
The Cyber Advisor service will certify individual consultants who can provide practical advice to help secure businesses
> CVE-2022-22253: Huawei HWLog Memory Corruption Via Race Condition
In this advisory we are disclosing a memory corruption vulnerability in the Huawei log device that allows any unprivileged process to trigger a kernel crash and reboot the device. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that fac...
> UK Seizes Nearly $27m in Crypto-Assets
Investigators trumpet money laundering crackdown
> Medical Device Maker to Pay $13m in False Claims Case
Biotronik accused of engaging in kickback scheme
> WordPress Transposh: Exploiting a Blind SQL Injection via XSS
Introduction You probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which resulted in more than $30,000 in bounties: [CVE-2021-24910] Transposh <= 1.0.7 “tp_tp” Unauthenticated Reflected Cross-Site Scripting [CVE-2021-24911] Transpos...
> Cyber-Attacks on Port of LA Double
Surge in threats coming from eastern Europe
> Malware-as-a-Service Creating New Cybercrime Ecosystem
It is easier than ever to launch cyber-attacks due to the rise of malware-as-a-service
> Tokyo MOU Port State Control authority
L'autorité de contrôle des ports de Tokyo MOU a révélé que ses données ont été compromises pendant des mois après avoir été victime d'une cyberattaque en juillet dernier. Cette attaque a causé des problèmes avec les données de contrôle des navires, ce qui a pu créer des difficultés pour la prise de...
> Google Brings Back Android App Permissions Section to the Play Store
The Android Developers team said it reversed the decision due to customer feedback
> Hacked Ukrainian Radio Stations Broadcast Fake News About President Zelensky’s Health
The so-far unidentified hackers broadcasted reports that Zelensky was hospitalized “in an intensive care ward”
> G.I.E. Vignerons du Sud-Ouest
Une coopérative agricole a été victime d'une cyberattaque en juillet 2022, plusieurs de ses machines ont été infectées par un logiciel malveillant. Le procès de l'auteur présumé de ces attaques, Ilia D., s'ouvre le 11 février devant la 13e chambre correctionnelle du tribunal judiciaire de Paris. Les...
> Global Firms Fear the Worst Over Risk Management Failures
Many left in the dark due to immature approaches
> PayPal Used to Send Malicious “Double Spear” Invoices
Threat actors combine techniques to trick users
> 🇫🇷/🇬🇧 Feed MISP public (12 juillet 2022)
🇫🇷 Le CERT-FR met à disposition un feed MISP public regroupant des indicateurs de compromission marqués TLP:CLEAR dont la diffusion est libre. Il est accessible à l'adresse https://misp.cert.ssi.gouv.fr/feed-misp. La documentation du projet MISP, plateforme open-source de partage d'indicateurs de...
> Mixed Messages as Neopets Scrambles to Respond to Mega Breach
Firm urges password reset despite claims attacker has live access
> China Fines Didi Global $1.19bn for “Heinous” Data Security Infringements
The fine was issued for violating the country’s network security law, data security law and personal information protection law