> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several key threats and trends. The suspected member of the ShinyHunters group, known as "Rey," has been detained in Jordan, aiding the FBI in identifying other group members involved in digital extortion. Meanwhile, a new China-aligned cyber espionage group, TA419, has been targeting U.S. AI policy experts through credential phishing campaigns tied to Microsoft. This indicates a rising trend in nation-state actors focusing on critical technology sectors. Additionally, ongoing analysis of User Agent Strings in honeypot logs reveals continued interest in understanding attacker behaviors. These developments underscore the persistent threats from both cybercriminal groups and state-sponsored actors in the evolving cybersecurity landscape.
|
// AI-powered summary generated at 08:00
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands. [...]
Several security issues were fixed in the Linux kernel.
Stonejiajia, Shir Tamari and Sagi Tzadik discovered that the OverlayFS
implementation in the Ubuntu Linux kernel did not properly perform
permission checks in certain situations. A local attacker could possibly
use this to gain elevated privileges. (CVE-2023-2640)
Shir Tamari and Sagi Tzadik discov...
iRhythm disclosed a cyberattack via third-party apps where patient and proprietary data was stolen, followed by a ransom demand. iRhythm Technologies is a U.S.-based digital healthcare company specializing in remote cardiac monitoring and arrhythmia detection. Its best-known product is the Zio, a we...
It was discovered that missing input sanitising in the NTLM client of the GNU SASL library could result in memory disclosure For the stable distribution (trixie), this problem has been fixed in version 2.2.2-1.1+deb13u2. We recommend that you upgrade your gsasl packages.
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure.
Palo Alto Networks Unit 42, which found and reported the bug through Google's bug bounty pr...
After 26 years, today is my last day at EFF. It's been a terrific and wild ride â the organization has grown from a tiny band of fighty people trying to plant a flag for freedom and justice in the coming digital world into a large, established band of fighty people doing, well, much the same. The wo...
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. [...]
All have patches, so make sure you upgrade to a fixed version
A security researcher said a flaw in FIFAâs online platforms allowed her to access several internal systems, including one that could have allowed her to take control of the TV stream of every World Cup match.
During a recent incident response engagement, our team uncovered a multi-stage WordPress infection that goes beyond the usual file-based malware. The attacker combined a fake plugin, a remote command-and-control server, and two PHP web shells stored directly inside the WordPress database.
The campai...
A supply chain attack can affect businesses of any size. Find out how to reduce exposure from vendors and SaaS tools.
In this blog post youâll learn how to detect and prevent subdomain takeover â a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. Weâll explain the issue, how the situation arises, and how you can use various AWS features and services to he...
The US government crackdown on Anthropicâs Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will soon be the norm.
Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively.
Attacks involving BabaDeda Loader, observed in April 2026,...
The Wordfence Threat Intelligence Team was notified on June 11th, 2026 of a potential supply chain compromise affecting ShapedPlugin, a WordPress plugin vendor with over 400,000 active free plugin installations. Fortunately, Wordfence customers have already had malware signature detection for the pa...
Le non-respect du droit d'opposition à la prospection commerciale directe entraßne une violation de l'obligation de licéité du traitement.Faits et contexteL'Autorité Nationale de Surveillance du Traitement des Données à CaractÚre Personnel (ANSPDCP) roumaine a publié une décision de sanction à l'enc...
L'Autorité suédoise de protection de la vie privée (IMY) a aujourd'hui publié une décision prononçant une réprimande à l'encontre de Securitas Sverige AB pour des manquements en lien avec la vidéosurveillance de ses salariés conducteurs de véhicules.Faits et contexteL'affaire trouve son origine dans...
Several security issues were fixed in rabbitmq-c.
La Commission Nationale de l'Informatique et des LibertĂ©s (CNIL) a annoncĂ© la nomination de son nouveau directeur administratif et financier.Ă compter du 15 juin 2026, un administrateur de l'Ătat est nommĂ© directeur administratif et financier de la CNIL, succĂ©dant Ă son prĂ©dĂ©cesseur qui occupait cet...