[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 04:00

> AP - autorité néerlandaise
L'Autorité de protection des données néerlandaise (AP) a publié des orientations destinées à encadrer le développement et l'utilisation de l'intelligence artificielle (IA) générative en conformité avec le RGPD.L'autorité a publié des lignes directrices destinées aux développeurs et aux responsables...
> Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]
> GPDP - autorité italienne
L'autorité de contrôle italienne sanctionne un professionnel pour l'installation d'un système de vidéosurveillance filmant la voie publique et enregistrant le son, en violation des principes de licéité, de minimisation et de transparence.Faits et contexteL'autorité italienne de protection des donnée...
> PIPC - autorité sud-coréenne
L'autorité sud-coréenne de protection des données (PIPC) a apporté des clarifications concernant la nouvelle réglementation sur la collecte automatisée de données par le secteur financier.À compter du 20 août, une nouvelle disposition de l'acte d'exécution de la loi sur la protection des données per...
> Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach
Lidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data had been stolen in a...
> UODO - autorité polonaise
L'autorité polonaise a rappelé à l'ordre un responsable du traitement et son sous-traitant pour ne pas avoir respectivement vérifié et mis en œuvre des garanties suffisantes en matière de sécurité, suite à un accès non autorisé à une boîte de messagerie électronique.Faits et contexteL'autorité polon...
> New CrashStealer malware poses as Apple crash reporting tool
A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]
> VPN service favored by ransomware groups is sanctioned by US
The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware "cryptors."
> U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) catalog....
> CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in nat...
> Sony Nerfs Videogame Ownership
Legal intern Suzanne Castillo co-authored this post. Playstation’s decision to kill physical game discs is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and negligent lawmakers share the blame–and they can do better.  We’ve seen th...
> Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-list kept it switched...
> Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach
Following the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake.
> Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog.
> Hackers breach Lidl’s IT service provider, steal customer data
German discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, Lidl said it was informed of the...
> Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’
The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB. The post Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ appeared first on CyberScoop.
> USN-8535-1: PipeWire vulnerabilities
It was discovered that PipeWire accepted unbounded Content-Length values in its RAOP module. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2026-14324) It was discovered that PipeWire performed multiple unbounded stack a...
> EU and UK officially blame Russian spies for cyberattack on Poland's power grid
Sweeping sanctions and condemnation follow op that could have left half a million without power in the depths of winter
> Open Directory Exposes Three Evilginx Phishing Operators
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
> Officials once again warn defenders that Russian hackers are targeting network devices
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care. The post Officials once again warn defenders that Russian hackers are targeting network devices appeared first on CyberScoop.