Cloud Security Alliance Marks a New Chapter in AI Governance | CSA

Latest CyberSec News by @thecyberpicker
Microsoft creates separate Windows 11 24H2 update for incompatible PCs
Microsoft confirmed on Tuesday that it's pushing a revised security update targeting some Windows 11 24H2 systems incompatible with the initial update released during this month's Patch Tuesday.
Global law-enforcement operation targets infostealer malware
Authorities in three countries arrested 32 people and seized dozens of servers.
Hackers exploited Windows WebDav zero-day to drop malware
An APT hacking group known as 'Stealth Falcon' exploited a Windows WebDav RCE vulnerability in zero-day attacks since March 2025 against defense and government organizations in Turkey, Qatar, Egypt, and Yemen.
295 Malicious IPs Launch Coordinated Brute-Force Attacks on Apache Tomcat Manager
Coordinated brute-force attacks target Tomcat Manager; exposed cameras leak sensitive data globally.
Brute-force attacks target Apache Tomcat management panels
A coordinated campaign of brute-force attacks using hundreds of unique IP addresses targets Apache Tomcat Manager interfaces exposed online.
Congress Introduces Bill to Strengthen Healthcare Cybersecurity
The legislation aims to expand the federal government’s role in helping healthcare providers protect and respond to cyber-attacks
Operation Secure disrupts global infostealer malware operations
An international law enforcement action codenamed "Operation Secure" targeted infostealer malware infrastructure in a massive crackdown across 26 countries, resulting in 32 arrests, data seizures, and server takedowns.
How AI agents could revolutionize the SOC — with human help
AI agents aren’t foolproof, but they could soon replace some of the most common tasks for cyber defenders.
https://www.nist.gov/news-events/news/2025/06/nist-offers-19-ways-build-zero-trust-architectures
Microsoft fixes unreachable Windows Server domain controllers
Microsoft has resolved a known issue that caused some Windows Server 2025 domain controllers to become unreachable after a restart and triggered app or service failures.
Orange Business et Toshiba lancent un réseau ultra-sécurisé pour anticiper les menaces quantiques
Orange Business et Toshiba Europe s'allient pour lancer "un réseau quantique". Ce service, baptisé Orange Quantum Defender, vise à répondre à...-Cybersécurité
FIN6 cybercriminals pose as job seekers on LinkedIn to hack recruiters
FIN6, a financially motivated group tracked for years by cybersecurity researchers, is now lurking on sites such as LinkedIn and Indeed to spread malware, a new report says.
Young Western Hackers Collaborate with Russians Increasing Ransomware Threats
This week in cybersecurity from the editors at Cybercrime Magazine
20,000 Asian IPs and Domains Dismantled in Infostealer Crackdown
Interpol-coordinated Operation Secure led to 32 arrests, including the suspected ringleader of a cybercriminal organization
Valid-AI-ted: A Step Towards Real-Time Cloud Assurance | CSA
The Cloud Security Alliance has launched Valid-AI-ted, an AI-assisted quality check for STAR assessments. CEO Jim Reavis shares the background of this new tool.
Microsoft fixes Windows Server auth issues caused by April updates
Microsoft has fixed a known issue causing authentication problems on Windows Server domain controllers after installing the April 2025 security updates.
Cloud Security Alliance Brings AI-Assisted Auditing to Cloud | CSA
Hands-On Skills Now Key to Landing Your First Cyber Role
An ISC2 study found that 90% of security hiring managers would consider entry-level candidates with only previous IT work experience
https://www.nist.gov/news-events/events/2025/05/nist-nccoe-cybersecurity-and-privacy-genomic-data-workshop
Why DNS Security Is Your First Defense Against Cyber Attacks?
DNS attacks threaten every online interaction; securing DNS with ClouDNS protects businesses and prevents costly disruptions.
INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure
INTERPOL and 26 countries dismantled 20,000+ malicious IPs tied to info-stealing malware, disrupting global cybercrime networks.
Boost Cloud Security Without Bugging Your Developers | CSA
Security teams struggle to maintain a secure cloud environment while also facilitating developer access and productivity.
Toxic trend: Another malware threat targets DeepSeek
Kaspersky GReAT experts discovered a new malicious implant: BrowserVenom. It enables a proxy in browsers like Chrome and Mozilla and spreads through a DeepSeek-mimicking phishing website.
Researcher Finds Five Zero-Days and 20+ Misconfigurations in Salesforce Cloud
The products affected by the issues are part of the Salesforce OmniStudio suite, including FlexCards and Data Mappers
How to Build a Lean Security Model: 5 Lessons from River Island
Lean security with automated exposure and threat detection helps River Island protect 200+ stores and e-commerce without growing the team.
SinoTrack GPS Devices Vulnerable to Remote Vehicle Control via Default Passwords
SinoTrack GPS flaws let attackers remotely control vehicles and track locations, affecting all platform versions. Change passwords now.
Cybersécurité : Forte satisfaction au travail, mais disparités dans l’accès à la formation
la quatrième édition de l'Observatoire des métiers mené par l'Anssi et...-Cybersécurité
Half of Mobile Users Now Face Daily Scams
Malwarebytes claims 44% of mobile users are exposed to scams every day
Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild
Microsoft patches 67 vulnerabilities, including a WEBDAV zero-day actively exploited by Stealth Falcon. Critical for enterprise security.