> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Ransomware case reveals two parallel threat actors, blending tactics and evasionâshowing why isolated signals can often miss modern, overlapping cyberattacks.
The post One intrusion, two cyberattackers: Uncovering parallel threat activity appeared first on Microsoft Security Blog.
When securing an Amazon Web Services (AWS) environment, teams naturally prioritize inbound controls, firewalls, WAFs, and access policies, because thatâs where the most visible threats originate. Outbound traffic, on the other hand, tends to get less attention. Itâs often left open by default to avo...
Several security issues were fixed in HAProxy.
Several security issues were fixed in MySQL.
The joint warning from Five Eyes countries mirrors what many cybersecurity and AI experts have been saying for the past year.Â
The post Intel agencies: Frontier AI models will reshape cybersecurity faster than expected appeared first on CyberScoop.
Several security issues were fixed in nginx.
Thousands of outdated D-Link routers have been absorbed into the AryStinger botnet, with no future security updates available to protect them.
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.
The bug traces to a 1997 FTP-parsing change and is still live in Squid's default configur...
London Hydro says names, addresses, account details may have been exposed, but much about the intrusion is unknown
Webshells have been popular for a long time. We already covered this topic across multiple diaries[1][2]. I spent some time to track them[3] and slighly paid less attention to them but today I found another one. It seems to be a new player (pushed on Github two months ago).
The incident occurred early Saturday when at least a dozen unauthorized alerts were sent through Brazil's Civil Defense Alert system, a platform designed to warn residents about imminent threats such as floods, landslides and other natural disasters.
Attackers no longer need to sift through massive credential dumps. They can pay others to do it for them. Flare explores how an emerging underground market searches stolen credential databases for specific companies, domains, and accounts. [...]
Apple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devices
Senate testimony claims Anthropicâs Mythos AI breached NSA and Cyber Command systems in hours, prompting a U.S.-ordered shutdown. On June 12, the Trump administration directed Anthropic to restrict access to Fable 5 and Mythos 5, its two most capable models, exclusively to US citizens. Because verif...
Huntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.
Back in 2017, Troy Hunt and I built a little website called whynohttps.com. The idea was simple: take the most popular sites on the internet, check which ones still weren't redirecting visitors to HTTPS, and put the laggards on a list for everyone to see. No lecture,
Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability.Â
The post Decades-Old Squid Proxy Flaw âSquidbleedâ Can Expose User Data appeared first on SecurityWeek.
Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER.
According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware. Evidence...
A seemingly official voicemail turned out to be a scam. Learn how document delivery scams work and what to do if you receive one.