Australian airline Qantas alerted customers and authorities about a data breach at a contact center. The industry remains on edge after cyberattacks on airlines elsewhere.
Cybercriminals are extorting the German humanitarian aid group Welthungerhilfe (WHH) for 20 bitcoin. The charity said it will not pay.
Following the disclosure of two local privilege escalation (LPE) vulnerabilities, CVE-2025-6018 and CVE-2025-6019, less than a month ago, that impact major Linux distributions, a new wave of...
Citrix warns that patching recently disclosed vulnerabilities that can be exploited to bypass authentication and launch denial-of-service attacks may also break login pages on NetScaler ADC and...
As U.S. federal agencies sharpen their focus on cyber defense and resilience, new leadership is taking shape across... The post Federal cyber posts see fresh faces amid push to boost national...
Qantas, the largest airline in Australia, confirmed the theft of 6 million customers' personal information.
The Forminator plugin for WordPress is vulnerable to an unauthenticated arbitrary file deletion flaw that could enable full site takeover attacks. [...]
2025-07-01 • ANSSI • ANSSI • elf.goreshell Open article on Malpedia
Unknown threat actors have been observed weaponizing v0, a generative artificial intelligence (AI) tool from Vercel, to design fake sign-in pages that impersonate their legitimate counterparts....
User claims to sell stolen Verizon and T-Mobile data for millions of users (online Verizon says data is old T-Mobile denies any breach and links to it.
The French cybersecurity agency identified Houken, a new Chinese intrusion campaign targeting various industries in France
The Federal Energy Regulatory Commission (FERC) has withdrawn its notice of inquiry and terminated the related rulemaking proceeding... The post FERC ends rulemaking on a CIP reliability standard,...
The Federal Bureau of Investigation (FBI) said that it has recently observed the cybercriminal group Scattered Spider expanding... The post FBI raises alarm over Scattered Spider targeting airline...
SSH Communications Security, a defensive cybersecurity company for humans, systems, and networks, announced on Tuesday its intention to... The post SSH enters into partnership agreement with...
Cybersecurity vendor Forescout Technologies announced Tuesday the appointment of Robert J. Skinner, USAF, retired, and cybersecurity and risk... The post Forescout strengthens advisory board, adds...
Our telemetry shows a surge in Windows shortcut (LNK) malware use. We explain how attackers exploit LNK files for malware delivery. The post Windows Shortcut (LNK) Malware Strategies appeared...
A popular social engineering technique returns: callback phishing, or TOAD attacks, which leverage PDFs, VoIP anonymity and even QR code tricks.
The Treasury said that Aeza Group has provided infrastructure services for notorious infostealer and ransomware operators
NimDoor shows how threat actors are continuing to explore cross-platform languages that introduce new levels of complexity for analysts.
Microsoft has fixed a known bug that breaks the 'Print to PDF' feature on Windows 11 24H2 systems after installing the April 2025 preview update. [...]
More than 40 fake extensions in Firefox's official add-ons store are impersonating popular cryptocurrency wallets from trusted providers to steal wallet credentials and sensitive data. [...]
Benefits admin specialist Kelly Benefits has revealed a breach impacting over 500,000 individuals across 45 client organizations
There are various approaches to managing vulnerabilities on cloud workloads, and knowing which vulnerability scan method to use is critical to your success. However, there isn’t a universally...
ESET Research analyzes Gamaredon’s updated cyberespionage toolset, new stealth-focused techniques, and aggressive spearphishing operations observed throughout 2024
Qantas admits that a “significant” volume of customer data may have been stolen from a contact center
Elon Musk-funded xAI is skipping Grok 3.5 and releasing Grok 4 after Independence Day in the United States. [...]
Microsoft is working to fix a DNS misconfiguration that is causing one-time passcode (OTP) message delivery failures in Exchange Online for some users. [...]
U.S. security agencies on Monday urged critical infrastructure operators to stay alert for possible cyberattacks by Iranian state-sponsored... The post Critical infrastructure warned of rising...
This story was produced in partnership with Agence France-Presse (AFP). In a field near the small town of Bezymenne in southern Ukraine, Viktoria Shynkar carefully picks out a narrow path through...
By Salleh Kodri, SE Regional Manager, Cyble ASEAN is going full throttle on digital growth. From cross-border e-commerce and AI deployments to digital identity and smart cities, the region is...