[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has...
> Is Venmo safe? Here’s how to protect yourself
Is Venmo safe? Yes, provided you use it as intended. Learn how it works, the common scams to watch for, and how to protect your money.
> Don’t get fooled by TikTok resin art scams
Scammers are using stolen videos and fake artist profiles to trick people into buying resin art that never arrives. Here's how to spot the warning signs.
> Call of Duty Mobile scam uses fake free points to steal player accounts
A phishing site posing as a free Call of Duty Points giveaway is stealing Activision logins and two-factor authentication codes.
> Titan automatise le chantage aux données
Titan promet d’automatiser l’analyse des fuites, le calcul des rançons et la pression réglementaire.
> OpenAI’s agent escaped its sandbox during a security test
An OpenAI agent escaped its sandbox, stole credentials, and broke into Hugging Face. Here's what that actually means.
> In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws...
> Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replicatio...
> Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]
> Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malic...
> Google wants to store a selfie video of your face
A new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.
> Un faux portail FPR pour piéger des pirates
Un faux portail FPR imitait la Police nationale pour enregistrer les recherches et identités de pirates.
> Meta tackles AI-generated accounts with a free Facebook verification badge
Meta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The company says the goal is to give users a signal that they are dealing with a person, not a bot or an AI-generated account, w...
> The Good, the Bad and the Ugly in Cybersecurity – Week 30
Authorities arrest Kratos's developer, HollowGraph hides C2 in 2050 calendar events, and OpenAI's models breach Hugging Face to steal benchmark answers.
> Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]
> B9 : 36 000 profils bancaires annoncés piratés
B9 fait l’objet d’une fuite présumée de 36 000 profils, illustrant les risques cyber des banques 100 % en ligne.
> Uncle Sam tells overseas cybercrooks their visas are canceled
Policy targets online scammers, sextortionists, and potentially their immediate families
> Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage oper...
> Russian hackers exploit unpatched Zimbra servers to steal emails
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) has been running the...
> AegisAI Raises $36 Million for AI-Powered Email Security
The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek.