[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (4 articles)

|

// AI-powered summary generated at 04:00

> DPA - autorité grecque
L'Autorité de protection des données personnelles a publié une décision de sanction à l'encontre de Vodafone (comprenant le prononcé d'une amende de 20 000 €) et d'une personne physique (amende de 2 000 €) pour des manquements en lien avec l'obligation d'information et le droit d'accès. Cette affair...
> GPDP - autorité italienne
L'autorité italienne, le Garant pour la protection des données personnelles (GPDP), a publié une décision de sanction à l'encontre du Ministère de la Justice, comprenant le prononcé d'une amende de 12 000 €, pour des manquements en lien avec la communication illicite de données de santé d'un employé...
> Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub acc...
> AZOP - autorité croate
L'autorité croate de protection des données (AZOP) a publié des recommandations détaillant les conditions d'application de l'intérêt légitime comme base juridique pour le traitement des données personnelles.S'appuyant sur les lignes directrices 1/2024 du Comité européen de la protection des données...
> Conseil d'Etat
Le Conseil d'État a partiellement annulé et réformé une sanction de la Commission nationale de l'informatique et des libertés (CNIL) à l'encontre de la société Tagadamedia concernant ses pratiques de recueil du consentement pour la prospection commerciale.La société Tagadamedia, qui collecte des don...
> Kash Patel’s clothing brand website shut down after reports it was hacked
According to users on X, the website was hijacked by hackers in an attempt to trick visitors into installing malware.
> Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Compute...
> Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations
How Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth. The post Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations appeared first on Microsoft Securit...
> Dans les coulisses d’un lookup
Vidéo exclusive ZATAZ : plongée dans un lookup, outil lié aux fuites de données et au darkweb.
> LookUp : un suspect arrêté pour trafic de données
Un suspect interpellé après un trafic de données lié à Telegram, crypto-actifs et 79 millions d’entrées.
> Microsoft says it’s making AI ‘safe for work’ in your browser
Microsoft is testing the addition of agentic AI to its corporate browser, Edge for Business. A new version, currently available in a limited preview, will help perform routine tasks more efficiently, according to Microsoft’s partner product manager for Edge, Lindsay Kubasik....
> Former US execs plead guilty to aiding tech support scammers
Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]
> Ubuntu 24.04 Path-to-Regexp Significant Denial-of-Service Flaw USN-8290-1
Path-to-Regexp could be made to crash if it received specially crafted network traffic.
> Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict
Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operations. These activities included targeting internet-connected cameras, conducting destructive attacks agains...
> The Good, the Bad and the Ugly in Cybersecurity – Week 21
Cops seize First VPN and share intel on users, Reaper spoofs multiple brands to infect Macs, and two Microsoft Defender zero-days exploited in the wild.
> Why the Supreme Court's Chatrie case could change the meaning of privacy in America
Lawyer Adam Unikowsky spoke with Recorded Future News about why he believes geofence searches are problematic and why the way the court rules could have a dramatic impact on Americans’ right to privacy.
> Canadian man arrested, charged for running KimWolf DDos botnet
In court documents unsealed on Thursday, the Justice Department said Jacob Butler ran KimWolf as a DDoS-for-hire service that infected over a million devices worldwide.
> RemotePE: The Lazarus RAT that lives in memory
Authors: Yun Zheng Hu and Mick Koomen Summary Last year, we published research about a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations, encountered during multiple incident response engagements. This Lazarus subgroup overlaps with activity linked to AppleJeus, Citr...
> Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses
President Trump’s branded cell phone maker and cell provider said the exposure was linked to a third-party platform, and was evaluating whether it needs to notify customers.
> Ubuntu Evince Critical Command Injection Vulnerability USN-8295-1
Evince could be made to run programs as your login if it opened a specially crafted file.