> TODAY'S SUMMARY (112 articles)
Today's cybersecurity news highlights several significant threats and trends:
1. Labcorp faces a $2.3 million fine due to cybersecurity failings and is implementing enhanced data security measures, including a new incident response plan.
2. Cryptocurrency exchange Bitget reports a staggering $351.6 million theft by suspected North Korean hackers, prompting investigations and withdrawal suspensions.
3. A critical vulnerability in the Elementor WordPress plugin allows unauthenticated attackers to create admin accounts, emphasizing the ongoing risk of exploited software flaws.
4. Fake desktop applications targeting payroll services have emerged, tricking HR staff into granting remote access to attackers.
5. CISA warns of exploited flaws in Adobe and WSO2 products, adding them to its Known Exploited Vulnerabilities catalog, highlighting the urgency for organizations to patch these vulnerabilities.
|
// AI-powered summary generated at 20:00
Oracle Linux has released security updates for version 10, addressing various fixes and CVE-2026-43186, including kernel enhancements and certificate updates, available on the Unbreakable Linux Network.
Oracle Linux has released updates for version 10, addressing security vulnerabilities related to CVE-2026-14164 with new rpm packages available for both x86_64 and aarch64 architectures.
Cars.no aurait exposé noms, téléphones et plaques, créant un risque élevé de phishing automobile ciblé.
Oracle Linux updated the nodejs-nodemon package for version 10 to address CVE-2026-69152, related to brace-expansion fixes, available for x86_64 and aarch64 architectures.
Une fuite Firebase présumée expose kiosques Pokémon, paiements, code source et accès à 217 machines connectées.
Phishing Ameli, cloaking et fausse boutique IA : le clic pourrait servir Ă identifier et qualifier de futures victimes.
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.
The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.
Nouveau faux mail AR24, CAPTCHA et vol d’identifiants : Tester en live ce phishing et vérifier une notification AR24.
Ubuntu has patched several vulnerabilities in ImageMagick across various LTS versions, which could allow for arbitrary code execution and denial of service through specific image handling flaws.
Une municipalité italienne a été sanctionnée pour avoir communiqué prématurément l'appartenance syndicale d'une employée à son futur employeur, l'autorité jugeant que la finalisation future du transfert de l'employée ne justifiait pas une telle divulgation anticipée en l'absence de base juridique sp...
La publication d'une décision administrative mentionnant le numéro de matricule et le motif de la rupture du contrat de travail d'un agent public, même en l'absence de son nom, constitue une diffusion illicite de données personnelles, car l'agent reste identifiable par le contexte.Faits et contexteL...
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech.
The post The FTC wants to regulate AI for ideological bias appeared first on CyberScoop.
An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didn’t ask it to remove another […...
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]
Franklin project adds new security providers, employs digital twins and AI
The company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors.
The post OpenAI says Daybreak will expand to offer specialized cyber services appeared first on CyberScoop.
Un pirate revendique 1,3 million de lignes volées à la FF Handball après plusieurs publications visant des groupes français.
Un vendeur du dark web propose accès casino, bases de joueurs et données crypto dans un catalogue spécialisé.
We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This d...
Hao Ren discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operation. An attacker could possibly use
this issue to trigger an out-of-bounds heap write, resulting in
arbitrary code execution. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubunt...