> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
[This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program]
The national postal operator, Ukrposhta, reported that its mobile application experienced temporary disruptions following a cyberattack on its IT systems. The attack, which occurred during the night of June 24th/25th, caused instability and operational failures in the digital services. Ukrposhta con...
Platform engineering, security architecture, and operations teams are being asked to support 2 realities at once: modern application platforms such as Red Hat OpenShift, and long-lived Red Hat Enterprise Linux (RHEL) fleets that still run critical automation. These parallel systems introduce risk, e...
Cardiology Associates of Port Huron (CAPH), un cabinet médical du Michigan, a été potentiellement victime d'une violation de données par le groupe Orova. Orova prétend avoir acquis 496 Go de données, incluant des informations d'identification personnelles et des données de santé protégées (PHI) de 2...
Atlas Elektronik, une filiale de TKMS (ThyssenKrupp Marine Systems), un géant de la défense allemand, a été victime d'une cyberattaque. L'attaque a ciblé la succursale nord-américaine de l'entreprise, qui gère des projets pour l'armée américaine. Bien que l'entreprise ait confirmé que les données mi...
De multiples vulnérabilités ont été découvertes dans CPython. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une falsification de requêtes côté serveur (SSRF) et une injection de code indirecte à distance (XSS).
Suite à un cyberincident, Latvijas Valsts meži (LVM) a désactivé et rendus inaccessibles ses systèmes informatiques externes (LVM GEO, le service cartographique et l’application de chasse « Mednis ») ainsi que plusieurs systèmes internes assurant les échanges avec ses fournisseurs et clients, pour d...
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Google is rolling out new privacy controls for Search services and Google Play, giving you more control over saved history and personalized recommendations. [...]
A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards, supermarkets, and...
Intrusion revendiquée chez Akaolife : données RH, santé et France Travail au cœur d’un risque cyber majeur ?
CVE-2026-20230 under exploitation, while an earlier SD-WAN 0-day looks even worse than we thought
Researchers have identified a new backdoor program that has been used in enterprise intrusions since April and appears to be linked to an initial access broker that sells network footholds to ransomware gangs.
Dubbed Mistic by researchers from Symantec, the malware program...
A 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. [...]
A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE or not. No more bogus CVEs. 57 CVEs … Continue reading a C...
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]
According to a new site, 24% of the most popular websites in the world don't offer support for passkeys, which are considered the most secure way to log in to apps and services.