πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🌊 How to Protect Sensitive Data While Using ChatGPT and Other Generative AI Tools 🌊

Generative AI platforms like ChatGPT have emerged as a new frontier of data breaches, especially in the rise of hybrid work. Equipped with the function to generate various content and troubleshoot software bugs, these applications can leak training data and violate privacy.  In their research, Work From Anywhere, Fortinet found that about 62 of organizations The post How to Protect Sensitive Data While Using ChatGPT and Other Generative AI Tools appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite πŸ–‹οΈ

GitLab once again released fixes to address a critical security flaw in its Community Edition CE and Enterprise Edition EE that could be exploited to write arbitrary files while creating a workspace. Tracked as CVE20240402, the vulnerability has a CVSS score of 9.9 out of a maximum of 10. "An issue has been discovered in GitLab CEEE affecting all versions from 16.0 prior to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Orange EspaΓ±a Breach: Dark Web Flooded With Operator Credentials πŸ“”

Resecurity discovered over 1572 compromised customers from RIPE, APNIC, AFRINIC and LACNIC.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives πŸ–‹οΈ

A Brazilian law enforcement operation has led to the arrest of several Brazilian operators in charge of the Grandoreiro malware. The Federal Police of Brazil said it served five temporary arrest warrants and 13 search and seizure warrants in the states of So Paulo, Santa Catarina, Par, Gois, and Mato Grosso. Slovak cybersecurity firm ESET, which provided additional.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Schneider Electric Confirms Data Accessed in Ransomware Attack πŸ“”

Energy firm Schneider Electric said a ransomware incident, reportedly perpetrated by the Cactus group, has led to data being accessed from its Sustainability Business division.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ’» Apple accuses UK gov't of β€˜unprecedented overreach’ on privacy πŸ’»

In the name of security, the UK government may well have put a cybersecurity target on the nations back, with Apple once again warning that proposed changes to the Investigatory Powers Act 2016 are a serious and direct threat to data security and information privacy.We are deeply concerned about the amendments to the Investigatory Powers Bill currently before Parliament, which will put the privacy and security of users at risk," Apple said in a statement. This is an unprecedented overreach by the government and, if implemented, the UK new user protections could be secretly vetoed globally, preventing us from ever delivering them to customers.To read this article in full, please click here.

πŸ“– Read more.

πŸ”— Via "COMPUTERWORLD"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider β™ŸοΈ

On Jan. 9, 2024, U.S. authorities arrested a 19yearold Florida man charged with wire fraud, aggravated identity theft, and conspiring with others to use SIMswapping to steal cryptocurrency. Sources close to the investigation tell KrebsOnSecurity the accused was a key member of a criminal hacking group blamed for a string of cyber intrusions at major U.S. technology companies during the summer of 2022.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
🧨 Was the Fake Joe Biden Robocall Created with AI? 🧨

As voters in the recent New Hampshire primary have found, a fake robocall of President Joe Biden has been making... The post Was the Fake Joe Biden Robocall Created with AI?  appeared first on McAfee Blog.

πŸ“– Read more.

πŸ”— Via "McAfee"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Feds Reportedly Try to Disrupt 'Volt Typhoon' Attack Infrastructure πŸ•΅οΈβ€β™‚οΈ

The Chinalinked threat actor's attacks on US critical infrastructure organizations have alarmed American intelligence officials, Reuters says.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Forcepoint Federal Rebrands As Everfox to Reflect New Era of Defense-Grade Cybersecurity πŸ•΅οΈβ€β™‚οΈ



πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Apple Warns iPhone Sideloading Changes Will Increase Cyber Threats πŸ•΅οΈβ€β™‚οΈ

The tech giant says that being more open to comply with EU regulations brings risks such as malware, fraud, and scams.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Cactus' Ransomware Strikes Schneider Electric πŸ•΅οΈβ€β™‚οΈ

Schneider's Sustainability division, which provides software and consulting services to enterprises, was felled by cybercriminals in midJanuary.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Ivanti Zero-Day Patches Delayed as 'KrustyLoader' Attacks Mount πŸ•΅οΈβ€β™‚οΈ

The RCEauth bypass bugs in Connect Secure VPNs have gone unpatched for 20 days as statesponsored groups continue to backdoor Ivanti gear.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“’ From complexity to clarity: The channel opportunity in streamlining cyber security πŸ“’

Upcoming legislation and a rapidly evolving threat landscape means organizations can't afford to lose track of security transformation plans and the channel can play a key role in bolstering defenses.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Glibc Flaw Grants Attackers Root Access on Major Linux Distros πŸ–‹οΈ

Malicious local attackers can obtain full root access on Linux machines by taking advantage of a newly disclosed security flaw in the GNU C library aka glibc. Tracked as CVE20236246, the heapbased buffer overflow vulnerability is rooted in glibc's vsysloginternal function, which is used by syslog and vsyslog for system logging purposes. It's said to have been accidentally.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Hackers Exploiting VPN Flaws to Deploy KrustyLoader Malware πŸ–‹οΈ

A pair of recently disclosed zeroday flaws in Ivanti Connect Secure ICS virtual private network VPN devices have been exploited to deliver a Rustbased payload called KrustyLoader that's used to drop the opensource Sliver adversary simulation tool. The security vulnerabilities, tracked as CVE202346805 CVSS score 8.2 and CVE202421887 CVSS score 9.1, could be abused.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” City Cyber Taskforce Launches to Secure Corporate Finance πŸ“”

A new initiative led by the ICAEW and NCSC launches today to improve cybersecurity during deals and investments.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Citibank Sued For Failing to Protect Fraud Victims πŸ“”

New York attorney general launches legal case against Citi for failing to reimburse or protect fraud victims.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Gift Yourself a Year of Online Protection for Only $50 Through 2/4 🦿

Requesting the removal of your most confidential data from the internet is a complicated process unless you have Incogni, which can do it in a few clicks.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The SEC Won't Let CISOs Be: Understanding New SaaS Cybersecurity Rules πŸ–‹οΈ

The SEC isnt giving SaaS a free pass. Applicable public companies, known as registrants, are now subject to cyber incident disclosure and cybersecurity readiness requirements for data stored in SaaS systems, along with the 3rd and 4th party apps connected to them.  The new cybersecurity mandates make no distinction between data exposed in a breach that was stored onpremise, in the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking Malware πŸ–‹οΈ

A financially motivated threat actor known as UNC4990 is leveraging weaponized USB devices as an initial infection vector to target organizations in Italy. Googleowned Mandiant said the attacks single out multiple industries, including health, transportation, construction, and logistics. "UNC4990 operations generally involve widespread USB infection followed by the deployment of the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity