πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ Black Kite Unveils Monthly Ransomware Dashboards πŸ•΅οΈβ€β™‚οΈ



πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Wyden Releases Documents Confirming the NSA Buys Americans' Internet Browsing Records πŸ•΅οΈβ€β™‚οΈ



πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ NRC Issues Recommendations for Better Network, Software Security πŸ•΅οΈβ€β™‚οΈ

The Network Resilience Coalition pushes adoption of standards like SSDF, OpenEoX and CISA's Secure By Design and Default framework.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ AllaKore RAT Malware Targeting Mexican Firms with Financial Fraud Tricks πŸ–‹οΈ

Mexican financial institutions are under the radar of a new spearphishing campaign that delivers a modified version of an opensource remote access trojan called AllaKore RAT. The BlackBerry Research and Intelligence Team attributed the activity to an unknown Latin Americanbased financially motivated threat actor. The campaign has been active since at least 2021. "Lures use Mexican Social.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Midnight Blizzard claims another big tech scalp with HPE hack just days after Microsoft breach - and more victims could be coming πŸ“’

Microsoft has warned Midnight Blizzard may have hacked a raft of other organizations in addition to itself and HPE, and has begun warning potential victims.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 PixPirate: The Brazilian financial malware you can’t see 🧠

Malicious software always aims to stay hidden, making itself invisible so the victims cant detect it. The constantly mutating PixPirate malware has taken that strategy to a new extreme. PixPirate is a sophisticated financial remote access trojan RAT malware that heavily utilizes antiresearch techniques. This malwares infection vector is based on two malicious apps a The post PixPirate The Brazilian financial malware you cant see appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Data privacy will be a critical enterprise focus in 2024 - and generative AI has torn up the rulebook πŸ“’

Ahead of Data Privacy Day, industry experts told ITPro that firm must prioritize security, staff awareness, and the responsible use of emerging technologies to prevent major data protection blunders.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
πŸ–‹οΈ Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines πŸ–‹οΈ

Cybersecurity researchers have identified malicious packages on the opensource Python Package Index PyPI repository that deliver an information stealing malware called WhiteSnake Stealer on Windows systems. The malwarelaced packages are named nigpal, figflix, telerer, seGMM, fbdebug, sGMM, myGens, NewGends, and TestLibs111. They have been uploaded by a threat actor named "WS." "These.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
πŸ–‹οΈ NSA Admits Secretly Buying Your Internet Browsing Data without Warrants πŸ–‹οΈ

The U.S. National Security Agency NSA has admitted to buying internet browsing records from data brokers to identify the websites and apps Americans use that would otherwise require a court order, U.S. Senator Ron Wyden said last week. "The U.S. government should not be funding and legitimizing a shady industry whose flagrant violations of Americans' privacy are not just unethical, but illegal.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” CI/CD at Risk as Exploits Released For Critical Jenkins Bug πŸ“”

Customers are urged to patch now after exploits are released for critical vulnerability in Jenkins.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Dark Web Drugs Vendor Forfeits $150m After Guilty Plea πŸ“”

Drug trafficker Banmeet Singh made 150m in cryptocurrency from dark web sales.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ’» Russia hacks Microsoft: It’s worse than you think πŸ’»

Another day, another hack of Microsoft technology. Hohum, you might think, this has happened before and will happen again as surely as the sun rises in the morning and sets at night.This time is different. Because this time the targets werent Microsoft customers, but rather the top echelons of Microsoft itself. And the hacker group, called Midnight Blizzard, or sometimes Cozy Bear, the Dukes, or A.P.T. 29, is sponsored by Russias Foreign Intelligence Service and has been since at least 2008.To read this article in full, please click here.

πŸ“– Read more.

πŸ”— Via "COMPUTERWORLD"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1πŸ‘1
πŸ“’ Lush cyber attack claimed by Akira ransomware gang πŸ“’

The group says it has accessed and will release data including passports, tax information, and client data.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 493 Companies Share Their SaaS Security Battles – Get Insights in this Webinar πŸ–‹οΈ

In today's digital world, security risks are more prevalent than ever, especially when it comes to Software as a Service SaaS applications. Did you know that an alarming 97 of companies face serious risks from unsecured SaaS applications?Moreover, about 20 of these organizations are struggling with internal data threats. These statistics aren't just numbers they're a wakeup call. We're.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Riding the AI Waves: The Rise of Artificial Intelligence to Combat Cyber Threats πŸ–‹οΈ

In nearly every segment of our lives, AI artificial intelligence now makes a significant impact It can deliver better healthcare diagnoses and treatments detect and reduce the risk of financial fraud improve inventory management and serve up the right recommendation for a streaming movie on Friday night. However, one can also make a strong case that some of AIs most significant impacts.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Albabat, Kasseika, Kuiper: New Ransomware Gangs Rise with Rust and Golang πŸ–‹οΈ

Cybersecurity researchers have detected in the wild yet another variant of the Phobos ransomware family known as Faust. Fortinet FortiGuard Labs, which detailed the latest iteration of the ransomware, said it's being propagated by means of an infection that delivers a Microsoft Excel document .XLAM containing a VBA script. "The attackers utilized the Gitea service to store several files.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft Provides Defense Guidance After Nation-State Compromise πŸ“”

Microsoft said the Russian nationstate group Midnight Blizzard obfuscated its attack through the use of an OAuth application.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ PoC exploits for Jenkins vulnerability are being targeted in the wild, researchers reveal πŸ“’

Hackers are already sniffing around a number of proofofconcept exploits for a critical vulnerability in the Jenkins open source automation software, experts warn.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
😱1
πŸ“” Nigerian 'Yahoo Boys' Behind Social Media Sextortion Surge in the US πŸ“”

Nigeriabased cybercriminals known as Yahoo Boys are the main drivers of a financial sextortion increase on TikTok, Instagram and Snapchat, targeting Englishspeaking teenagers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Uncover How Outlook Vulnerability Could Leak Your NTLM Passwords πŸ–‹οΈ

A nowpatched security flaw in Microsoft Outlook could be exploited by threat actors to access NT LAN Manager NTLM v2 hashed passwords when opening a specially crafted file. The issue, tracked as CVE202335636 CVSS score 6.5, was addressed by the tech giant as part of its Patch Tuesday updates for December 2023. "In an email attack scenario, an attacker could exploit the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Take your business further with a dedicated internet connection πŸ“’

Achieve internet speed and reliability to match your business ambitions.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity