> TODAY'S SUMMARY (112 articles)
Today's cybersecurity news highlights several significant threats and trends:
1. Labcorp faces a $2.3 million fine due to cybersecurity failings and is implementing enhanced data security measures, including a new incident response plan.
2. Cryptocurrency exchange Bitget reports a staggering $351.6 million theft by suspected North Korean hackers, prompting investigations and withdrawal suspensions.
3. A critical vulnerability in the Elementor WordPress plugin allows unauthenticated attackers to create admin accounts, emphasizing the ongoing risk of exploited software flaws.
4. Fake desktop applications targeting payroll services have emerged, tricking HR staff into granting remote access to attackers.
5. CISA warns of exploited flaws in Adobe and WSO2 products, adding them to its Known Exploited Vulnerabilities catalog, highlighting the urgency for organizations to patch these vulnerabilities.
|
// AI-powered summary generated at 20:00
NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and I...
A growing number of UK venues have decided to act against privacy-busting smart glasses.
Read more in my article on the Hot for Security blog.
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe.
The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop.
Debian has released an advisory regarding vulnerabilities in libyaml-syck-perl, advising users to upgrade to version 1.34-2+deb13u3 to mitigate potential denial of service and code execution risks.
Our latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets to Radar.
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
Debian released an advisory regarding multiple vulnerabilities in WordPress, including risks of cross-site scripting and remote code execution, urging users to upgrade to version 6.8.7.
Kimsuky's phishing attacks get an AI boost
Access to accurate information about reproductive and maternal health can be critical. But on Meta's platforms, simply talking about prescription medication, abortion care, or one's own medical experiences can be enough to trigger content removals and account restrictions.
That's why EFF recently su...
This week on the Lock and Code podcast, we speak with Chris Parr about his inventive and all-too-funny stress-test of surveillance pricing.
Summary The FATF just released its first DeFi-specific report: Acknowledging DeFi’s operational benefits, the global AML/CFT standard-setter explains how jurisdictions,…
The post Understanding the FATF’s DeFi Report: A Functional Approach to Decentralized Finance Regulation appeared first on Chainal...
We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now...
Les institutions de l'Union européenne soulignent le rôle essentiel des données ouvertes, notamment celles du Portail européen de données, pour soutenir l'innovation en matière d'intelligence artificielle générative.L'intelligence artificielle générative, qui crée des contenus tels que du texte, des...
La Commission Nationale de l'Informatique et des Libertés (CNIL) a publié des recommandations visant à identifier et gérer les conflits d’intérêts pouvant survenir lorsque le délégué à la protection des données (DPO) exerce d’autres missions.Le RGPD autorise un DPO à exercer d’autres missions que ce...
What wouldst thou ask of the monkey's paw?
L'Office pour la protection des données personnelles tchèque (ÚOOÚ) a publié sa recommandation n° 1/2026 concernant l'utilisation de systèmes de vidéosurveillance par les prestataires de services de santé.Ce document a été élaboré pour répondre à des commentaires sur une méthodologie générale relati...
L'autorité espagnole de protection des données a sanctionné un opérateur de télécommunications pour avoir délivré un duplicata de carte SIM à un fraudeur, considérant que le manquement de l'agent du point de vente à appliquer correctement les procédures de vérification d'identité constituait un trai...
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.
The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelli...