> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical threats and trends. Anthropic is seeking voice data from Claude users to enhance AI model training, raising privacy concerns. A 16-year-old researcher recently exploited a Microsoft analytics service, gaining access to 17 trillion records, showcasing vulnerabilities in major platforms. Meanwhile, Warlock ransomware continues to target critical infrastructure by exploiting year-old SharePoint flaws. In law enforcement news, a suspect linked to the ShinyHunters extortion group has been detained in Jordan, aiding the FBI in identifying other members. Additionally, the China-aligned group TA419 is actively conducting phishing campaigns against U.S. AI policy experts, emphasizing the increasing focus on cyber espionage in sensitive sectors.
|
// AI-powered summary generated at 12:00
De multiples vulnérabilités ont été découvertes dans les produits Spring. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans les produits Moxa. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
The sheer number of events and alerts can be overwhelming, but multi-layered pipelines can filter out the noise
Une vulnérabilité a été découverte dans Cisco Catalyst. Elle permet à un attaquant de provoquer une atteinte à l'intégrité des données. Cisco indique que la vulnérabilité CVE-2026-20262 est activement exploitée.
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
LGBTQ+ communities are facing an escalating wave of censorship and targeted surveillance, but we can push back through mutual solidarity. Join us live to learn how safer virtual spaces get built, how platform policies and government pressure are reshaping the digital landscape, and what platform acc...
Une vulnérabilité a été découverte dans LibreNMS. Elle permet à un attaquant de provoquer une injection de code indirecte à distance (XSS).
De multiples vulnérabilités ont été découvertes dans Redmine. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Estonia will require additional security screening for emails sent from Russia’s .ru top-level domain before they reach government officials, according to the country's minister of justice and digital affairs.
Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM.
The post Inside the Modern SOC: The 72-Minute Race appeared first on Unit 42.
Comment un faux service d’effacement de données et un abonnement à 49,99 €/mois exploitent peur et IA pour tromper les victimes. Décryptage.
Le post Faux mail « Vos données sont sur le dark web » : décryptage d’une arnaque a été publié sur IT-Connect.
The U.S. Department of Justice announced Friday that it has seized the CFAKE.com and SOCFAKE.com websites, which allegedly hosted nonconsensual AI-generated nude images and videos of women, in what appears to be the first publicly announced domain seizure under the TAKE IT DOWN Act. [...]
The Trump administration's decision that forced Anthropic to pull its latest cybersecurity models could be reactionary, retaliatory, or both, but the message is clear: The AI industry isn't immune from U.S. government interference.
Second Catalyst SD-WAN Manager flaw exploited as an 0-day this month
According to the one person who actually read the research paper
The UK is banning under-16s from social media, following Australia's lead. But the real cost may be privacy.
Multiple security vulnerabilities were discovered in the BIRD internet routing daemon, which could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 2.17.5-0+deb13u1. We recommend that you upgrade your bird2 packages.
Multiple security vulnerabilities were discovered in LibreOffice, which could result in denial of service or potentially the execution of arbitrary code if malformed files are opened. For the stable distribution (trixie), these problems have been fixed in version 4:25.2.3-2+deb13u5.
We found EtherRAT malware being distributed by a website with a strange homepage. Following the trail, we discovered a vast network of malicious infrastructures, distributing malware, malicious documents, remote desktop software, and phishing pages.Â
A flaw was discovered in libgd-perl, a Perl module wrapper for libgd, which may result in the execution of arbitrary shell commands or file overwrite when processing specially crafted file names. For the stable distribution (trixie), this problem has been fixed in version 2.78-1+deb13u1.