[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 12:00

> Google exposes China espionage group that’s been lurking in networks undetected since 2023
The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to intercept research and steal data with national security implications. The post Google exposes China espionage group that’s been lurking in networks undetected since 2023 appeare...
> SimpleHelp bug lets hackers create rogue remote support accounts
A vulnerability in the SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on servers using the OpenID Connect (OIDC) authentication protocol. [...]
> Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the u...
> North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the threat actor has b...
> June 2026 Stealer Logs - 56,278,397 breached accounts
In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searc...
> Le VPN intégré de Firefox devient illimité cet été : profitez-en dès maintenant
Jusqu'au 31 août 2026, le VPN intégré et gratuit de Firefox passe en données illimitées et propose 28 localisations de serveurs. Voici comment en profiter. Le post Le VPN intégré de Firefox devient illimité cet été : profitez-en dès maintenant a été publié sur IT-Connect.
> Building an autonomous SOC: core challenges and solutions
How AI is being introduced in security operations centers, and whether AI agents can successfully function without a human SOC analyst.
> Australian Sugar Producer Mackay Sugar Reports Cyber Incident
Mackay Sugar, Australia’s second-largest sugar producer, disclosed a cyberattack on June 10, potentially affecting key processing operations. Mackay Sugar is one of Australia’s largest sugar producers and the country’s second-largest sugar manufacturer. The company is based in the Mackay region of t...
> Chinese hackers breached North American research institutions via REDCap servers
A China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. UNC6508 exploits vulnerabl...
> Maine closes data breach portal to the public after fake reports
Maine is still allowing companies to report breaches, but won’t make the portal easily available to the public until after it completes an audit of its procedures to stop such incidents, according to a press release from the Maine attorney general’s office.
> BfDI - autorité allemande
Le Préposé fédéral à la protection des données et à la liberté d'information (BfDI) organise un atelier de réflexion sur le Règlement sur les données (DA).Le troisième atelier de réflexion se tiendra le 7 juillet 2026 à Berlin, à destination des représentants experts du monde économique et de la soc...
> PIPC - autorité sud-coréenne
La Commission de Protection des Informations Personnelles (PIPC) sud-coréenne a initié une série d'inspections sur site pour évaluer la gestion des données dans le secteur public.Le 12 juin, l'autorité a mené une première inspection auprès de l'Institut Coréen de Recherche et de Développement de l'I...
> Council of Europe hacked in ShinyHunters' PeopleSoft heist
Joins the ranks of Nottingham Uni and 100 other unnamed victims
> AEPD - autorité espagnole
Le Réseau Ibéro-américain de Protection des Données (RIPD), sous l'impulsion de l'autorité espagnole (AEPD), a approuvé une nouvelle version de ses Standards Ibéro-américains pour répondre aux défis des technologies émergentes.Approuvée à l'unanimité lors de la rencontre de Carthagène des Indes, cet...
> IMY - autorité suédoise
L'Autorité suédoise de protection de la vie privée (IMY) a été désignée par le gouvernement comme autorité de contrôle du marché pour le Règlement sur l'IA.Cette décision confère à l'IMY un rôle central dans la surveillance de la conformité au Règlement sur l'IA, adopté par le Parlement européen en...
> OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]
> DPC - autorité irlandaise
La Commission de protection des données irlandaise sanctionne le service de santé public pour de multiples manquements à la sécurité des données, révélés par une attaque par rançongiciel ayant affecté les données de santé de 84 000 patients. Faits et contexteL'autorité irlandaise de protection de...
> EDPS
Le Contrôleur européen de la protection des données a publié un article de blog sur les risques liés à l'utilisation d'outils d'intelligence artificielle non autorisés.Cet article aborde le concept d'"IA de l'ombre" (Shadow AI), soulignant comment l'emploi de tels outils peut exposer des données à c...
> USN-8431-1: Ruby vulnerabilities
It was discovered that Ruby's Net::IMAP library did not properly verify that Transport Layer Security (TLS) encryption was started after issuing a STARTTLS command. A remote attacker could possibly use this issue to perform a machine-in-the-middle attack and silently bypass TLS encryption. (CVE-2026...
> GPDP - autorité italienne
La publication en ligne de la liste des candidats admis à un concours réservé aux catégories protégées constitue une diffusion illicite de données de santé, même si l'information est indirecte, et engage la responsabilité du recruteur en tant que responsable du traitement. Faits et contexteL'auto...