> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]
Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 5.2.11-0+deb13u1.
Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or bypass of security rules. For the stable distribution (trixie), these problems have been fixed in version 1.9.15-0+deb13u1.
Curl fixed 18 vulnerabilities, including a 25-year-old bug, with issues spanning auth bypass, memory safety, and host validation in libcurl. Curl maintainers addressed eighteen vulnerabilities with a single update, and one of them goes back 25 years. That’s not a typo, it really sat there since the...
It was discovered that incorrect request handling in the internal web server of the PowerDNS DNS server could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 4.9.16-0+deb13u1. We recommend that you upgrade your pdns packages.
Once a new CISA director is in place, the agency will ramp up hiring efforts, Homeland Security Markwayne Mullin told lawmakers. The White House has not yet announced a nominee.
Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. [...]
Multiple security vulnerabilities were discovered in the SOGo groupware server, which could result in cross-site scripting or SQL injection. For the stable distribution (trixie), these problems have been fixed in version 5.12.1-3+deb13u2. We recommend that you upgrade your sogo packages.
Le Bureau du délégué à la protection des données finlandais a émis un avertissement à l'encontre de l'Agence des services d'aide juridique et de tutelle pour avoir traité les données de crédit de ses employés sans base légale.L'agence avait contrôlé les données de crédit de 70 puis de 600 fonctionna...
Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in
L'autorité grecque a prononcé une réprimande à l'encontre d'un organisme de crédit pour manquement au principe d'exactitude, en raison de retards dans la correction de données financières erronées, et lui a ordonné de revoir ses procédures de vérification.Faits et contexteL'autorité hellénique de pr...
La Commission de Protection des Informations Personnelles (PIPC) sud-coréenne a émis des recommandations de correction à l’encontre de trois entreprises majeures du secteur des services funéraires suite à une inspection préventive sur le traitement des données personnelles.L'inspection, initiée en j...
Most parcel mule scams start with fake job offers that trick victims into handling stolen goods.
Le Conseil de l'Union européenne a abandonné la proposition de la Commission européenne visant à remplacer les bannières de cookies par un signal de consentement automatisé.La Commission avait initialement proposé d'introduire un nouvel article 88 ter au RGPD afin de substituer aux bannières de cook...
Le Bundestag allemand a élu Moritz Hennemann comme nouveau Préposé fédéral à la protection des données et à la liberté d'information (BfDI).Il succède à Louisa Specht-Riemenschneider, qui se retire de ses fonctions pour des raisons de santé. Cette dernière continuera d'exercer ses fonctions jusqu'au...
In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.
Le Bureau du Commissaire à l'Information (ICO) a exhorté les dirigeants du secteur de l'aide sociale à s'engager publiquement en faveur d'une amélioration de la création, de la gestion et de l'accès aux dossiers de soins.Cet appel, lancé le 25 juin 2026, s'inscrit dans la campagne "Mieux Gérer les D...
Several security issues were fixed in AMD Microcode.
The Federal Communications Commission wants to require telecommunications providers to collect vast amounts of personal information from every person who wants a phone number in the name of combatting scam and spam calls. This plan will fail to combat the deluge of unwanted calls people in the Unite...
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 149.0.7827.196-1~deb13u1.