Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30073 bookmarks
Custom sorting
Pour piéger les diplomates européens, les hackers russes les invitent « à boire un excellent verre de vin »
Pour piéger les diplomates européens, les hackers russes les invitent « à boire un excellent verre de vin »
Une campagne d'espionnage menée depuis la Russie tente de piéger les politiques européens avec de fausses invitations envoyées par mail. Une fois la pièce jointe ouverte, l'ordinateur de la victime sera infecté et va offrir toutes ses informations aux hackers. Les pirates de Moscou mènent une nouvelle campagne de
·numerama.com·
Pour piéger les diplomates européens, les hackers russes les invitent « à boire un excellent verre de vin »
AI Red Teaming: Insights from the Front Lines | CSA
AI Red Teaming: Insights from the Front Lines | CSA
Uncover key insights from AI red teaming experts on securing generative AI systems against adversarial attacks, harmful outputs, and infrastructure risks.​
·cloudsecurityalliance.org·
AI Red Teaming: Insights from the Front Lines | CSA
Une cyberattaque sur une maquette en LEGO permet d'illustrer l'arrêt d'une usine - Numerama
Une cyberattaque sur une maquette en LEGO permet d'illustrer l'arrêt d'une usine - Numerama
Un expert en cybersécurité démontre aux entreprises, à travers une maquette en LEGO, comment une cyberattaque peut mettre en péril une chaîne de production. Un simple zéro tapé sur un clavier et la machine s’arrête. En quelques secondes, une chaîne de production peut être paralysée et une entreprise mise à l'arrêt
·numerama.com·
Une cyberattaque sur une maquette en LEGO permet d'illustrer l'arrêt d'une usine - Numerama
Widespread Microsoft Entra lockouts tied to new security feature rollout
Widespread Microsoft Entra lockouts tied to new security feature rollout
Windows administrators from numerous organizations report widespread account lockouts triggered by false positives in the rollout of a new Microsoft Entra ID's "leaked credentials" detection app called MACE.
·bleepingcomputer.com·
Widespread Microsoft Entra lockouts tied to new security feature rollout
Critical Erlang/OTP SSH RCE bug now has public exploits, patch now
Critical Erlang/OTP SSH RCE bug now has public exploits, patch now
Public exploits are now available for a critical Erlang/OTP SSH vulnerability tracked as CVE-2025-32433, allowing unauthenticated attackers to remotely execute code on impacted devices.
·bleepingcomputer.com·
Critical Erlang/OTP SSH RCE bug now has public exploits, patch now
New Android malware steals your credit cards for NFC relay attacks
New Android malware steals your credit cards for NFC relay attacks
A new malware-as-a-service (MaaS) platform named 'SuperCard X' has emerged, targeting Android devices via NFC relay attacks that enable point-of-sale and ATM transactions using compromised payment card data.
·bleepingcomputer.com·
New Android malware steals your credit cards for NFC relay attacks
Google Gemini AI is getting ChatGPT-like Scheduled Actions feature
Google Gemini AI is getting ChatGPT-like Scheduled Actions feature
Google Gemini is testing a ChatGPT-like scheduled tasks feature called "Scheduled Actions," which will allow you to create tasks that Gemini will execute later.
·bleepingcomputer.com·
Google Gemini AI is getting ChatGPT-like Scheduled Actions feature
FoxCMS 1.2.5 - Remote Code Execution (RCE)
FoxCMS 1.2.5 - Remote Code Execution (RCE)
FoxCMS 1.2.5 - Remote Code Execution (RCE). CVE-2025-29306 . webapps exploit for Multiple platform
·exploit-db.com·
FoxCMS 1.2.5 - Remote Code Execution (RCE)
Drupal 11.x-dev - Full Path Disclosure
Drupal 11.x-dev - Full Path Disclosure
Drupal 11.x-dev - Full Path Disclosure. CVE-2024-45440 . webapps exploit for PHP platform
·exploit-db.com·
Drupal 11.x-dev - Full Path Disclosure
Friday Squid Blogging: Live Colossal Squid Filmed - Schneier on Security
Friday Squid Blogging: Live Colossal Squid Filmed - Schneier on Security
A live colossal squid was filmed for the first time in the ocean. It’s only a juvenile: a foot long. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
·schneier.com·
Friday Squid Blogging: Live Colossal Squid Filmed - Schneier on Security
Interlock ransomware gang pushes fake IT tools in ClickFix attacks
Interlock ransomware gang pushes fake IT tools in ClickFix attacks
The Interlock ransomware gang now uses ClickFix attacks that impersonate IT tools to breach corporate networks and deploy file-encrypting malware on devices.
·bleepingcomputer.com·
Interlock ransomware gang pushes fake IT tools in ClickFix attacks
OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits
OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits
OpenAI has launched three new reasoning models - o3, o4-mini, and o4-mini-high for Plus and Pro subscribers, but as it turns out, these models do not offer 'unlimited' usage.
·bleepingcomputer.com·
OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits