> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues and emerging threats. A significant privacy battle is brewing in California over updates to wiretapping laws that may limit private lawsuits against internet tracking. At the Pwn2Own Ireland event, hackers successfully exploited 32 zero-day vulnerabilities, showcasing the rapid pace at which security flaws are being targeted. In a concerning data breach, the FBI has removed a contractor linked to the exposure of sensitive employee information due to a missed patch, raising alarms about operational security in federal agencies. Meanwhile, ASOS confirmed a data breach that involved unauthorized push notifications claiming to leak customer data. Additionally, multiple vulnerabilities affecting Atlassian products and a critical flaw in Dell's System Update could allow attackers to gain unauthorized access. Overall, there is an evident rise in exploitation of known vulnerabilities and an increasing trend in data breaches across various sectors.
|
// AI-powered summary generated at 20:00
Cloudflare Radar data confirms early indications of a partial Internet restoration in Iran, nearly three months after the shutdown began. Traffic spikes and DNS queries have risen, but network activity is currently just 40% of pre-shutdown levels.
More than half of orgs in Okta survey faced an AI-related security incident or near miss last year
L'autorité norvégienne de protection des données (Datatilsynet) a publié les conclusions d'un projet mené dans son "bac à sable" réglementaire concernant le développement de robots conversationnels par la Direction de la Santé.La Direction de la Santé envisage de déployer des agents conversationnels...
L'Autorité suédoise de protection de la vie privée (IMY) a publié sa décision de clôturer une enquête menée à l'encontre de la société Analyse Suédoise d'Antécédents AB, concernant le respect des conditions de son autorisation de traiter des données relatives aux infractions pénales. Cette affaire f...
Cybercriminals used the Glassworm botnet to infect open source software projects with malware, and in turn hack the developers and companies that use that software.
La Commission nationale de l'informatique et des libertés (CNIL) et son homologue sud-coréenne, la Commission de protection des informations personnelles (PIPC), ont collaboré pour créer une affiche de sensibilisation sur l'intelligence artificielle générative et la protection des données.Cette init...
Le vice-président du Bureau tchèque pour la protection des données personnelles (ÚOOÚ) s'est exprimé sur le débat concernant l'utilisation de caméras avec reconnaissance faciale dans les stades.Lors d'une intervention le 27 mai 2026 dans l'émission "Débat" sur le portail d'information iDnes.tv, le v...
Cybercriminals still allowed to walk into office blocks and convince staff to let them plug in their own thumb drives
La Commission Nationale de l'Informatique et des Libertés (CNIL) détaille, à travers un cas fictif, les obligations et les bonnes pratiques d'un sous-traitant victime d'une cyberattaque affectant à la fois ses propres données et celles de ses clients.Le scénario décrit une attaque par ingénierie soc...
Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively.
That's according to new findings from WatchGuard and ESET, which have observed the two malware families being used to...
Threat actors are exploiting legitimate Google AppSheet addresses for phishing campaigns, sending emails on behalf of major companies to steal user credentials.
Learn how to block websites on Google Chrome using the Family Life app, Chrome extensions, mobile-specific settings, and router settings.
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities.
According to OX Security, the package, named "mouse5212-super-formatter," is designed to upload files from "/mnt/user-data," a dedicated directory used by Anthrop...
Read the latest DFIR news – cloud attachment collection, Cellebrite’s Spring 2026 release, free vehicle forensics tools, Telegram forensic artifacts, and more.
Army Gen. Joshua Rudd, who took the twin-leadership reins of Cyber Command and the NSA in March, recently tapped MITRE to conduct a potentially wide-ranging review into the organization, according to three people familiar with the matter.
Find out if Facebook Marketplace is safe, learn to spot the most common scams, plus top tips to shop securely.
The Silent Ransom Group (SRG) is targeting law firms using social engineering techniques and an unusual tactic for cybercriminals: showing up at victims’ offices in person while posing as IT staff, the FBI warns. The group, also known as Luna Moth, Chatty Spider, and UNC3753, has been active since a...
It was discovered that tgt incorrectly tried to achieve entropy by calling
rand without srand. An attacker could possibly use this issue to make tgt
generate an identical sequence of challenges, resulting in authentication
bypass.
A single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said.
The flaw, tracked as CVE-2026-48710 could allo...
Get step‑by‑step instructions to change your WiFi password on Windows, macOS, Android, iOS, and popular routers.