Le géant du Jean, Levi Strauss, déclare une intrusion par ingénierie sociale ayant permis l’exfiltration de données internes.
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hija...
Information published.
Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 20...
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker...
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.
"We are proactively expanding protections in response to ongoing monitoring of threat actor...
La Berlin Brandenburgische Wohnungsbaugenossenschaft a été victime d'une cyberattaque. Des acteurs non autorisés ont pu accéder temporairement à certaines parties de ses systèmes informatiques, qui ont été compromis. Une enquête est en cours pour déterminer si des données sensibles des locataires on...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-80...
Digitide Solutions a annoncé un incident de cybersécurité dans l'une de ses filiales, confirmant un accès non autorisé à des données. Bien qu'aucune perte opérationnelle ou financière majeure ne soit actuellement signalée, une enquête interne est en cours.
Les autorités de la ville de Suisun ont déclaré l'état d'urgence le samedi 8 août après qu'une cyberattaque ait mis hors service la ligne de répartition des urgences et d'autres systèmes clés. L'infection par un logiciel malveillant est survenue vendredi vers 5h45, forçant la ville à fermer son rése...
Or how I learned to stop worrying and love dangerous AI
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond.
The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42.
Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?
Nice video of the Arctic bobtail squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.
A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.
Researchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites.
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]
Calling all defenders
Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applicatio...