> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. [...]
Amazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests from your expected ne...
Microsoft touted its latest action against malware infrastructure as a new approach aimed at the full cybercrime "supply chain." Europol said more than 300 servers were targeted.
Mandiant detailed the incident in a blog post Wednesday, but it’s unclear who was behind it or if they managed to get broad visibility into the victim’s internal traffic.
The post Malicious hackers exploit Cisco zero-day for highest access level at communications service provider appeared first on...
Claude Code génère déjà au moins 4% des commits publics de GitHub (135 000/jour). Une vague de code IA qui pousserait Microsoft à louer de la capacité chez AWS.
Le post GitHub submergé par l’IA : Microsoft contraint de faire appel à AWS a été publié sur IT-Connect.
Operation Endgame disrupted malware services like StealC and Amadey that enable ransomware, fraud, and attacks on critical infrastructure. Between June 15 and 19, 2026, Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK,...
Several security issues were fixed in Perl DBI module.
L'autorité autrichienne de protection des données (DSB) a communiqué le programme de ses contrôles prioritaires pour l'année 2026, qui se dérouleront en deux phases distinctes.La première phase, dont les procédures débuteront en mars 2026 à l'encontre de responsables de traitement et de sous-traitan...
L'autorité britannique de protection des données (ICO) a publié un rapport sur les pratiques de protection des données dans le secteur des technologies éducatives, suite à un programme d'audits.Ce rapport, intitulé "Technologies éducatives examinées", détaille les conclusions d'audits menés en 2024...
Millions of malicious apps slip past Google Play's defenses each year. Get the checklist to protect against Android malware.
La Commission Nationale de l'Informatique et des Libertés (CNIL) a mis en ligne un répertoire de ses informations publiques et s'est engagée dans une démarche d'ouverture de ses données.Ce répertoire recense les documents communicables contenant des informations publiques, tout en précisant que les...
La Commission Nationale de l'Informatique et des Libertés (CNIL) précise les modalités de transmission des rapports d’expertise indépendante, désormais obligatoire pour les organismes de la fonction publique recourant au vote électronique pour leurs élections professionnelles.Depuis 2024, les organi...
Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle.
The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog.
La Commission européenne a publié un code de bonnes pratiques concernant le marquage et l'étiquetage des contenus générés par l'intelligence artificielle (IA).Ce code, de nature volontaire, vise à aider les fournisseurs et les déployeurs de systèmes d'IA générative à respecter les obligations de tra...
It was discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operator. An attacker could possibly use
this issue to trigger a heap buffer over-read, resulting in information
disclosure. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04...
200+ C2 servers linked to StealC and Amadey shut down
From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI.
The post When Information Becomes the Attack Surface – Understanding AI Agent Traps appeared first on SecurityWeek.
Two members of the Scattered Spider cybercrime collective have admitted launching a cyberattack against Transport for London (TfL) that caused millions in damages.
Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were due to stand tria...
Researchers have found a critical FFmpeg flaw that could let attackers use a malicious video file to compromise vulnerable systems.
Several security issues were fixed in FFmpeg.