CTI Digest du 25 juillet 2026
Posté le 25 juillet 2026 • 3 min de lecture • 469 mots
Généré le 25/07/2026 à 02:00 UTC · 50 items analysés · 10 sélectionnés · 22 sources actives
🔴 Vulnérabilités critiques
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
Source : The Hacker News Publié : 24/07/2026 17:15 UTC CVE : CVE-2026-32194
cve vulnerability
Des SVG malicieux soumis à Bing ont permis l’exécution de commandes en SYSTEM sur les serveurs Microsoft et en root sur des machines Linux, provoquant deux CVEs critiques.
🟠 Campagnes & groupes actifs
🏴☠️ Nova has just published a new victim : Center Of Information Technologies In Finance Public Institution
Source : Ransomware.live News Publié : 24/07/2026 22:57 UTC
breach malware
Le CTIF a été victime d’une attaque de phishing par Nova, une menace connue.
🏴☠️ Safepay has just published a new victim : upland.k12.ca.us
Source : Ransomware.live News Publié : 24/07/2026 21:59 UTC
malware
Upland.k12.ca.us est la nouvelle victime de Safepay selon l’annonce.
Friday Squid Blogging: Illex Squid Catch in the Falklands
Source : Schneier on Security Publié : 24/07/2026 21:06 UTC
malware
BlueNoroff utilise un kit de phishing pour cibler des crypto-wallets avant la distribution de malware.
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Source : The Hacker News Publié : 24/07/2026 20:42 UTC
apt breach malware phishing
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
“BlueNoroff has
Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry
Source : The Record Publié : 24/07/2026 17:14 UTC
ransomware
Andy Burnham maintient Liz Lloyd dans son rôle de cyber sécurité, malgré l’élimination du ministère.
🏴☠️ Insomnia has just published a new victim : Brooklyn Defender Services
Source : Ransomware.live News Publié : 24/07/2026 16:56 UTC
malware
Insomnia a été victime d’une attaque par plugin Notepad++ falso et MATCHBOIL.V2.
📖 Top 3 à lire
1. Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Source : The Hacker News Publié : 24/07/2026 12:20 UTC Score : 25
breach vulnerability
CERT-UA alerte sur une campagne utilisant un faux plugin Notepad++ pour délivrer MATCHBOIL.V2 dans des attaques UAC-0099.
2. Chick-fil-A data breach affects more than 13,000 customers
Source : Bleeping Computer Publié : 24/07/2026 10:04 UTC Score : 25
breach
Plus de 13,000 clients Chick-fil-A ont été victimes d’une fuite de données par attaque de stuffinging de credenciaux.
3. 🏴☠️ M3rx has just published a new victim : ausproof.com.au
Source : Ransomware.live News Publié : 24/07/2026 19:28 UTC Score : 20
breach
AusProof a été victime d’un faux plugin Notepad++ pour délivrer MATCHBOIL.V2.
ARGOS CTI Digest · Defence Intelligence ·
defintelligence.fr
Archivé dans /archive/2026-07/digest-2026-07-25.md