L'Office pour la protection des données personnelles tchèque (ÚOOÚ) a publié sa recommandation n° 1/2026 concernant l'utilisation de systèmes de vidéosurveillance par les prestataires de services de santé.Ce document a été élaboré pour répondre à des commentaires sur une méthodologie générale relati...
L'autorité espagnole de protection des données a sanctionné un opérateur de télécommunications pour avoir délivré un duplicata de carte SIM à un fraudeur, considérant que le manquement de l'agent du point de vente à appliquer correctement les procédures de vérification d'identité constituait un trai...
What wouldst thou ask of the monkey's paw?
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.
The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelli...
Explore a selection of the latest DFIR employment opportunities in this week’s Forensic Focus jobs round-up.
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfp...
Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an ordinary-looking ne...
We shipped Device Bound Session Credentials at Report URI, open-sourced the server-side implementation, and then discovered a long list of things the specification doesn't prepare you for.Some caused random logouts. One could deadlock a browser tab indefinitely. Two silently turned a device-bound se...
Pseudo, e-mail, numéro de téléphone : découvrez comment Maigret, user-scanner et Ignorant permettent de retrouver vos comptes en ligne en quelques minutes.
Le post Quels comptes avez-vous vraiment sur le Web ? Trois outils OSINT pour le découvrir a été publié sur IT-Connect.
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise.
The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft Secu...
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.
Ubuntu has issued security updates for systemd to address vulnerabilities that could allow local attackers to gain elevated privileges or terminate processes on specific LTS releases.
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data
We discovered a kit that gave us an insight into how modern online scams are built, promoted, and potentially used to target everyday consumers.
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.
Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said.
The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short...
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.
The p...
How polyglots are built, real-world cyberattack examples, and tips for detecting and preventing this threat.