πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β™ŸοΈ Arrests in $400M SIM-Swap Tied to Heist at FTX? β™ŸοΈ

Three Americans were charged this week with stealing more than 400 million in a November 2022 SIMswapping attack. The U.S. government did not name the victim organization, but there is every indication that the money was stolen from the nowdefunct cryptocurrency exchange FTX, which had just filed for bankruptcy on that same day.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ FritzFrog Botnet Exploits Log4Shell on Overlooked Internal Hosts πŸ•΅οΈβ€β™‚οΈ

Everyone knows to patch vulnerabilities for Internetfacing assets, but what about internal ones? One botnet is counting on your complacency.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ China Infiltrates US Critical Infrastructure in Ramp-up to Conflict πŸ•΅οΈβ€β™‚οΈ

Threat actors linked to the People's Republic of China, such as Volt Typhoon, continue to "preposition" themselves in the critical infrastructure of the United States, according to military and law enforcement officials.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Ukraine Military Targeted With Russian APT PowerShell Attack πŸ•΅οΈβ€β™‚οΈ

The attack, associated with Shuckworm, employs TTPs observed in prior campaigns against the Ukrainian military, predominantly using PowerShell.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Delinea Research Reveals that Ransomware Is Back on the Rise As Cybercriminals' Motivation Shifts to Data Exfiltration πŸ•΅οΈβ€β™‚οΈ



πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Feds Confirm Remote Killing of Volt Typhoon's SOHO Botnet πŸ•΅οΈβ€β™‚οΈ

The Chinabacked APT was using the botnet, made up of mostly endoflife, patchless routers from Cisco and Netgear, to set up shop inside US critical infrastructure.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Commando Cat' Is Second Campaign of the Year Targeting Docker πŸ•΅οΈβ€β™‚οΈ

The threat actor behind the campaign is still unknown, but it shares some similarities with other cyptojacking groups.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ ProcessUnity Introduces Industry's All-In-One Third-Party Risk Management Platform πŸ•΅οΈβ€β™‚οΈ



πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cloudflare Breach: Nation-State Hackers Access Source Code and Internal Docs πŸ–‹οΈ

Cloudflare has revealed that it was the target of a likely nationstate attack in which the threat actor leveraged stolen credentials to gain unauthorized access to its Atlassian server and ultimately access some documentation and a limited amount of source code. The intrusion, which took place between November 14 and 24, 2023, and detected on November 23, was carried out "with the goal of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ VajraSpy: A Patchwork of espionage apps πŸš€

ESET researchers discovered several Android apps carrying VajraSpy, a RAT used by the Patchwork APT group.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 Charities offered latest insight into key cyber threats to help keep out attackers 🚨

Latest report published by the NCSC outlines key threats facing the UK charity sector.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” LockBit Reigns Supreme in Soaring Ransomware Landscape πŸ“”

The last quarter of 2023 saw an 80 yearonyear increase in ransomware victim claims, according to ReliaQuest.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ INTERPOL Arrests 31 in Global Operation, Identifies 1,900+ Ransomware-Linked IPs πŸ–‹οΈ

An INTERPOLled collaborative operation targeting phishing, banking malware, and ransomware attacks has led to the identification of 1,300 suspicious IP addresses and URLs. The law enforcement effort, codenamed Synergia, took place between September and November 2023 in an attempt to blunt the "growth, escalation and professionalization of transnational cybercrime." Involving 60 law.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cloudflare Suffers Breach After Failing to Rotate Stolen Okta Credentials πŸ“”

Cloudflare revealed suspected nationstate attackers compromised its systems and accessed source code using credentials stolen in the Okta breach.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Researchers at UC San Diego reveal the most effective way to get stubborn employees to change their passwords πŸ“’

The study involved monitoring email reminders and login prompts sent to almost 10,000 faculty and staff members.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Former CIA Engineer Sentenced to 40 Years for Leaking Classified Documents πŸ–‹οΈ

A former software engineer with the U.S. Central Intelligence Agency CIA has been sentenced to 40 years in prison by the Southern District of New York SDNY for transmitting classified documents to WikiLeaks and for possessing child pornographic material. Joshua Adam Schulte, 35, was originally charged in June 2018. He was found guilty in July 2022. On September 13, 2023, he was.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cloudzy Elevates Cybersecurity: Integrating Insights from Recorded Future to Revolutionize Cloud Security πŸ–‹οΈ

Cloudzy, a prominent cloud infrastructure provider, proudly announces a significant enhancement in its cybersecurity landscape. This breakthrough has been achieved through a recent consultation with Recorded Future, a leader in providing realtime threat intelligence and cybersecurity analytics. This initiative, coupled with an overhaul of Cloudzy's cybersecurity strategies, represents a major.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The end of passwords – and how businesses will embrace it πŸ“’

What will the end of passwords look like in practice and what can businesses do to prepare?.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cloudflare Falls Victim to Okta Breach, Atlassian Systems Cracked πŸ•΅οΈβ€β™‚οΈ

The cyberattackers, believed to be state sponsored, didn't get far into Cloudflare's global network, but not for lack of trying.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ DirtyMoe Malware Infects 2,000+ Ukrainian Computers for DDoS and Cryptojacking πŸ–‹οΈ

The Computer Emergency Response Team of Ukraine CERTUA has warned that more than 2,000 computers in the country have been infected by a strain of malware called DirtyMoe. The agency attributed the campaign to a threat actor it calls UAC0027. DirtyMoe, active since at least 2016, is capable of carrying out cryptojacking and distributed denialofservice DDoS attacks. In March.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The 'Big Three’ ransomware groups are losing their grip on the industry as gangs begin to fracture, study shows πŸ“’

The ransomware landscape has become more diversified, with major players like LockBit losing ground to smaller, more dynamic collectives.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1