[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 08:00

> FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery Key. Hand it over once, and the attacker can restore the account's backup, read the privat...
> ATF cancels controversial commercial geolocation contract
The agency told CyberScoop the tool was a pilot that didn’t meet their needs. Members of Congress say it was accessed for hundreds of active cases.  The post ATF cancels controversial commercial geolocation contract appeared first on CyberScoop.
> New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign...
> Polymarket customers lose $3 million in supply-chain attack
Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]
> Cybersecurity firms targeted by fraudulent OpenAI organization invites
Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects. [...]
> Russian hackers were behind $2.5 billion hack of Jaguar Land Rover: Report
The hack on car giant Jaguar Land Rover last year was one the most disrupting, damaging, and costly hacks of the last few years.
> Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent oper...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données sanctionne un organe de presse pour avoir publié une vidéo non anonymisée d'une agression impliquant un mineur, jugeant que le principe de minimisation des données a été violé, et ce, malgré la viralité préalable de la vidéo.Faits et contexteL'autorité...
> ANSPDCP - autorité roumaine
L'autorité roumaine sanctionne un opérateur pour le dépôt de témoins de connexion non essentiels sans information préalable ni consentement valide, en application de sa loi nationale transposant la directive sur la vie privée et les communications électroniques.Faits et contexteL'Autorité nationale...
> Meta Is Testing Facial Recognition for Police and Military
We know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate news story.)
> DPA - autorité grecque
L'autorité hellénique sanctionne deux sociétés pour un total de 140 000 € pour des manquements liés à l'utilisation d'un système de vidéosurveillance, notamment le non-respect du droit d'accès, le défaut d'information et la communication illicite d'images aux autorités judiciaires.Faits et contexteL...
> PIPC - autorité sud-coréenne
Sanction d'un acteur du secteur des crypto-actifs pour des transferts internationaux de données personnelles réalisés sans le consentement spécifique et éclairé des utilisateurs, notamment en désignant un destinataire erroné.Faits et contexteL'autorité sud-coréenne de protection des données (PIPC) a...
> The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials
Exposed records from the private group included the personal information of a senior White House intelligence official and an active-duty special operations officer.
> CNIL
À l'invitation de la Commission Nationale de l'Informatique et des Libertés (CNIL), les autorités de protection des données des pays du G7 ont adopté des principes communs sur les technologies émergentes et la protection des mineurs.Réunies à Paris les 25 et 26 juin 2026, les autorités ont échangé s...
> Malware authors subvert AI detection systems
Enterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach. Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, according to a post from...
> Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the energy and govern...
> EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits
This Pride month, we’re calling on the dating app Grindr to prioritize LGBTQ+ user safety by making privacy the default across its platform. That means no more sharing personal data with advertisers or training AI on private information without users’ opt-in consent. Grindr is a dating app for the L...
> Hate “The Algorithm?” RSS Is One of the Tools You’ve Been Looking For
Poke your head into just about any online social network—or any general conversations about internet culture—and you’ll likely find a boogieman: the algorithm. Since at least the moment Facebook introduced (and apologized for) its News Feed, “the algorithm” has been shorthand for the ways the tech g...
> Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
Researchers warn many AI coding assistants now execute commands from project configurations
> Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.  The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek.