Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
Debian has released Security Advisory DSA-6418-1 addressing multiple vulnerabilities in Thunderbird that may allow arbitrary code execution; users are urged to upgrade to version 1:140.13.0esr-2~deb13u1.
The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.
"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but a...
Starting August 10, 2026, Sucuri will begin moving customer account logins to a new authentication platform designed to provide a stronger, more modern sign-in experience.
The rollout will happen gradually over the following few weeks, so not every account will transition at the same time.
For most...
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
The macOS-focused infection chain is designed to deliver a shell script that profiles the host and...
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671.
"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory...
NTIA official Adam Cassady becomes the second person confirmed to be the State Department's ambassador-at-large for cyber policy.
Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction an...
L'autorité polonaise de protection des données (UODO) a émis des objections concernant un projet de révision de la loi sur les fondations familiales, qui prévoit de rendre publiques sur internet les données personnelles des personnes qui y sont associées.Le président de l'UODO a exprimé de sérieuses...
L'autorité italienne a sanctionné une société de production audiovisuelle pour l'utilisation de l'hypertrucage (« deepfake ») à des fins satiriques, jugeant que le réalisme des vidéos et l'insuffisance des avertissements violaient les principes de loyauté et de transparence, ainsi que l'obligation d...
Debian announced multiple vulnerabilities in libheif that could lead to denial of service, sensitive information disclosure, or arbitrary code execution from malformed image files, advising updates to version 1.19.8-1+deb13u1.
L'autorité espagnole de protection des données a déclaré une violation du principe de confidentialité à l'encontre d'une municipalité pour avoir affiché un document administratif contenant des données personnelles sur un poteau, le rendant ainsi accessible au public. En application du droit national...
L'Agence Espagnole de Protection des Données sanctionne un éditeur de site web pour le dépôt de témoins de connexion avant tout consentement et pour avoir conditionné le refus à la souscription d'un abonnement payant.Faits et contexteL'Agence Espagnole de Protection des Données (AEPD) a aujourd'hui...
Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way.
The post More than half of AI-generated patches are broken appeared first on CyberScoop.
The money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms.
IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.
WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress ec...
Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix...
What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?