> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
An executive order signed Monday aims to accelerate the government's transition to post-quantum cryptography (PQC), a new generation of encryption designed to protect data from the powerful quantum computers expected in the future.
Four flaws in Dify exposed cross-tenant data, documents and AI conversations. Two critical bugs enabled unauthenticated access and data theft. Zafran Labs researchers disclosed four vulnerabilities in Dify, the open-source AI platform used by major companies like Volvo and Maersk to run over a milli...
L'autorité italienne de protection des données (Garante per la protezione dei dati personali - GPDP) a aujourd'hui publié une décision de sanction à l'encontre de la société Action Fit, comprenant le prononcé d'une amende de 3 930 €, pour des manquements liés à l'envoi de communications commerciales...
What did the Proton team learn at Infosecurity Europe 2026? Find out our key observations and takeaways from the conference
L'Office du Commissaire à l'Information (ICO) a annoncé l'entrée en vigueur de nouvelles obligations légales pour toutes les organisations au Royaume-Uni concernant le traitement des réclamations en matière de protection des données.Depuis le 23 juin 2026, toutes les organisations sont tenues de fou...
Le Bureau du Commissaire à l'information (ICO) du Royaume-Uni a sanctionné la société KRA Consultancy Ltd d'une amende de 300 000 £ (environ 354 000 €) pour l'envoi de 5 575 715 messages textes de marketing direct illégaux entre avril 2022 et mai 2025.Ces messages, qui ont généré plus de 60 000 plai...
Several security issues were fixed in LibVNCServer.
L'autorité italienne de protection des données sanctionne un établissement de la Croix-Rouge pour avoir divulgué le statut VIH d'une patiente sur son plateau-repas, jugeant la mesure non nécessaire au regard de l'obligation d'appliquer des précautions universelles. Une amende distincte a été infligé...
LIBNFS could be made to crash or run programs if it connected to a specially crafted NFS server.
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as...
Multiple security vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For the stable distribution (trixie), these problems h...
We spent 48 hours exploring the dark web and found stolen identities, malware, scams, and a thriving cybercrime economy.
Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs.
The post Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps appeared first on SecurityWeek.
Two members of the 'Scattered Spider' cybercrime group pleaded guilty to hacking the Transport for London (TfL) systems in 2024. [...]
The so-called duty of care provision that was excluded would have mandated that online platforms take reasonable measures to prevent specific harms such as suicidal ideation, eating disorders and cyberbullying by changing algorithm and design features.
President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography.
Key establishment must move by December 31, 2030; digital signatures by December 31, 2031. EO 14409 leaves national securi...
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts.
Every skill security scanner the firm tested it against marked it safe. The payload was harmless by desi...
This is the second data breach to affect LastPass customers in recent years, after one of the password manager's tech partners was recently breached.
JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT
A massive credential-harvesting campaign targeting FortiGate firewalls has exposed thousands of organizations to potential network compromise, and a trove of attacker tools, scripts, and credentials left inadvertently exposed on a server has given researchers an unusually detailed look at how the op...