> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several key trends and threats. Microsoft has made Windows Subsystem for Linux (WSL) containers generally available, allowing administrators to manage their use effectively. A Cisco survey indicates that most organizations require over six months to implement new security controls, with only 8% demonstrating strong defenses against evolving AI threats. Cloudflare is set to introduce post-quantum website certificates by early 2027, signaling a move towards enhancing encryption standards in anticipation of quantum computing risks. Additionally, a critical vulnerability has been identified in the Perl DBI module on Ubuntu 26.04 LTS, which could allow for denial of service or code execution attacks. Lastly, discussions around AI regulation are ongoing, with tech firms agreeing to self-police development practices.
|
// AI-powered summary generated at 04:00
L'Autorité de protection des données néerlandaise (AP) a publié des orientations destinées à encadrer le développement et l'utilisation de l'intelligence artificielle (IA) générative en conformité avec le RGPD.L'autorité a publié des lignes directrices destinées aux développeurs et aux responsables...
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]
L'autorité de contrôle italienne sanctionne un professionnel pour l'installation d'un système de vidéosurveillance filmant la voie publique et enregistrant le son, en violation des principes de licéité, de minimisation et de transparence.Faits et contexteL'autorité italienne de protection des donnée...
L'autorité sud-coréenne de protection des données (PIPC) a apporté des clarifications concernant la nouvelle réglementation sur la collecte automatisée de données par le secteur financier.À compter du 20 août, une nouvelle disposition de l'acte d'exécution de la loi sur la protection des données per...
Lidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data had been stolen in a...
L'autorité polonaise a rappelé à l'ordre un responsable du traitement et son sous-traitant pour ne pas avoir respectivement vérifié et mis en œuvre des garanties suffisantes en matière de sécurité, suite à un accès non autorisé à une boîte de messagerie électronique.Faits et contexteL'autorité polon...
A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]
The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware "cryptors."
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) catalog....
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems.
Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in nat...
Legal intern Suzanne Castillo co-authored this post.
Playstation’s decision to kill physical game discs is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and negligent lawmakers share the blame–and they can do better.Â
We’ve seen th...
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version.
The collector was dormant. An empty allow-list kept it switched...
Following the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake.
Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare.
The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog.
German discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, Lidl said it was informed of the...
The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB.
The post Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ appeared first on CyberScoop.
It was discovered that PipeWire accepted unbounded Content-Length values
in its RAOP module. A remote attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2026-14324)
It was discovered that PipeWire performed multiple unbounded stack
a...
Sweeping sanctions and condemnation follow op that could have left half a million without power in the depths of winter
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care.
The post Officials once again warn defenders that Russian hackers are targeting network devices appeared first on CyberScoop.