Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29804 bookmarks
Custom sorting
SHARED INTEL Q&A: A sharper lens on rising API logic abuse — and a framework to fight back
SHARED INTEL Q&A: A sharper lens on rising API logic abuse — and a framework to fight back
In today’s digital enterprise, API-driven infrastructure is the connective tissue holding everything together. Related: The DocuSign API-abuse hack From mobile apps to backend workflows, APIs are what keep digital services talking—and scaling. But this essential layer of connectivity is also where attackers are gaining traction, often quietly and with alarming precision. Jamison Utter, a cybersecurity
·lastwatchdog.com·
SHARED INTEL Q&A: A sharper lens on rising API logic abuse — and a framework to fight back
NIST Publishes New Zero Trust Implementation Guidance
NIST Publishes New Zero Trust Implementation Guidance
The new NIST guidance sets out 19 example implementations of zero trust using commercial, off-the-shelf technologies
·infosecurity-magazine.com·
NIST Publishes New Zero Trust Implementation Guidance
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
Microsoft has released an emergency Windows 11 24H2 update to address an incompatibility issue triggering restarts with blue screen of death (BSOD) errors on systems with Easy Anti-Cheat.
·bleepingcomputer.com·
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
Montres connectĂ©es et ultrasons : le danger invisible qui menace mĂȘme les ordinateurs les plus protĂ©gĂ©s
Montres connectĂ©es et ultrasons : le danger invisible qui menace mĂȘme les ordinateurs les plus protĂ©gĂ©s
Des chercheurs israĂ©liens ont prouvĂ© que les montres connectĂ©es, objets du quotidien, peuvent servir Ă  dĂ©rober des donnĂ©es sensibles depuis des ordinateurs pourtant totalement coupĂ©s d’Internet. Leur mĂ©thode, baptisĂ©e SmartAttack, repose sur la transmission de donnĂ©es par ultrasons et rĂ©vĂšle une faille insoupçonnĂ©e
·numerama.com·
Montres connectĂ©es et ultrasons : le danger invisible qui menace mĂȘme les ordinateurs les plus protĂ©gĂ©s
En passant par Amazon, il est possible d’acheter des VPN en promotion
En passant par Amazon, il est possible d’acheter des VPN en promotion
Vous ne le savez peut-ĂȘtre pas, mais Amazon vend des abonnements VPN, dont ceux du leader sur le marchĂ©. NordVPN ou Surfshark proposent plusieurs offres, avec parfois quelques promotions. Les VPN sont de plus en plus utilisĂ©s pour surfer sur Internet l'esprit tranquille, et ce, sur la plupart de vos appareils
·numerama.com·
En passant par Amazon, il est possible d’acheter des VPN en promotion
Digital rights groups sound alarm on Stop CSAM Act | CyberScoop
Digital rights groups sound alarm on Stop CSAM Act | CyberScoop
The organizations say a reintroduced version of the bill would “break” encryption for most Americans and make it impossible for end-to-end encrypted service providers to avoid lawsuits.
·cyberscoop.com·
Digital rights groups sound alarm on Stop CSAM Act | CyberScoop
Erie Insurance confirms cyberattack behind business disruptions
Erie Insurance confirms cyberattack behind business disruptions
Erie Insurance and Erie Indemnity Company have disclosed that a weekend cyberattack is behind the recent business disruptions and platform outages on its website.
·bleepingcomputer.com·
Erie Insurance confirms cyberattack behind business disruptions
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
A new attack dubbed 'EchoLeak' is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive data from Microsoft 365 Copilot from a user's context without interaction.
·bleepingcomputer.com·
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
RSAC Fireside Chat: Operationalizing diverse security to assure customers, partners–and insurers
RSAC Fireside Chat: Operationalizing diverse security to assure customers, partners–and insurers
Catastrophic outages don’t just crash systems — they expose assumptions. Related: Getting the most from cyber insurance At RSAC 2025, I met with ESET Chief Security Evangelist Tony Anscombe to trace a quiet but growing convergence: endpoint defense, cyber insurance, and monoculture risk are no longer separate concerns. They’re overlapping — and reshaping how security
·lastwatchdog.com·
RSAC Fireside Chat: Operationalizing diverse security to assure customers, partners–and insurers
catdoc zero-day, NVIDIA, High-Logic FontCreator and Parallel vulnerabilities
catdoc zero-day, NVIDIA, High-Logic FontCreator and Parallel vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three zero-day vulnerabilities in catdoc, as well as vulnerabilities in Parallel, NVIDIA and High-Logic FontCreator 15.
·blog.talosintelligence.com·
catdoc zero-day, NVIDIA, High-Logic FontCreator and Parallel vulnerabilities
Ce groupe cybercriminel dupe les recruteurs sur LinkedIn
Ce groupe cybercriminel dupe les recruteurs sur LinkedIn
Un nouveau type d'arnaque vise actuellement les professionnels du recrutement sur LinkedIn et Indeed. DerriĂšre des profils de candidats qui semblent tout Ă  fait ordinaires se cache le groupe cybercriminel FIN6. Son but : gagner la confiance des recruteurs, infiltrer les systĂšmes informatiques des entreprises et
·numerama.com·
Ce groupe cybercriminel dupe les recruteurs sur LinkedIn
Dozens arrested across Asia in global infostealer malware crackdown
Dozens arrested across Asia in global infostealer malware crackdown
A global law enforcement crackdown on information-stealing malware led to the arrest of 32 suspects and the dismantling of more than 20,000 malicious IP addresses and domains linked to cybercrime.
·therecord.media·
Dozens arrested across Asia in global infostealer malware crackdown
UNFI’s operations remain hobbled following cyberattack
UNFI’s operations remain hobbled following cyberattack
The grocery company had to entirely shut down its network following the intrusion and is serving customers on only a “limited basis” as it works to recover, CEO Sandy Douglas said.
·cybersecuritydive.com·
UNFI’s operations remain hobbled following cyberattack