πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Teen Dating App Wizz Removed from Apple and Google Stores for Sextortion Concerns πŸ“”

The Tinderlike app has countered claims of being a hot spot for sextortion scammers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian APT28 Hackers Targeting High-Value Orgs with NTLM Relay Attacks πŸ–‹οΈ

Russian statesponsored actors have staged NT LAN Manager NTLM v2 hash relay attacks through various methods from April 2022 to November 2023, targeting highvalue targets worldwide. The attacks, attributed to an "aggressive" hacking crew called APT28, have set their eyes on organizations dealing with foreign affairs, energy, defense, and transportation, as well as those involved with.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Google Play Used to Spread 'Patchwork' APT's Espionage Apps πŸ•΅οΈβ€β™‚οΈ

The Indian statesponsored cyberattackers lurked in Google's official app store, distributing a new RAT and spying on Pakistanis.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ South African Railways Lost Over $1M in Phishing Scam πŸ•΅οΈβ€β™‚οΈ

Just over half of the stolen funds have been recovered.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ•΅οΈβ€β™‚οΈ Interpol's 'Synergia' Op Nabs Dozens of Cybercriminals, Zaps Global C2s πŸ•΅οΈβ€β™‚οΈ

The largest number of takedowns in Africa were in South Sudan and Zimbabwe.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ macOS Malware Campaign Showcases Novel Delivery Technique πŸ•΅οΈβ€β™‚οΈ

Threat actor behind the Activator macOS backdoor is using pirated apps to distribute the malware in what could be a botnetbuilding operation.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🦿 Botnet Struck U.S. Routers; Here’s How to Keep Employees Safe 🦿

The FBI spotted this statesponsored attack that highlights how home office setups can be overlooked when it comes to employees cybersecurity.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Financial services should look to processor-level data protections, report suggests πŸ“’

Processors with security functions to secure data no matter where it is in use could help financial institutions with digital transformations.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Myanmar Hands Over Mob Bosses in Cyber-Fraud Bust πŸ•΅οΈβ€β™‚οΈ

Heads of top crime syndicates extradited to China are implicated in pigbutchering "fraud dens," but four individuals on China's mostwanted list still remain at large.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ CISO Corner: Gen Z Challenges, CISO Liability & Cathay Pacific Case Study πŸ•΅οΈβ€β™‚οΈ

Dark Reading's roundup of strategic cyberoperations insights for chief information security officers.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Forget Deepfakes or Phishing: Prompt Injection is GenAI's Biggest Problem πŸ•΅οΈβ€β™‚οΈ

With prompt injection, AI puts new spin on an old security problem.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ AnyDesk Hacked: Popular Remote Desktop Software Mandates Password Reset πŸ–‹οΈ

Remote desktop software maker AnyDesk disclosed on Friday that it suffered a cyber attack that led to a compromise of its production systems. The German company said the incident, which it discovered following a security audit, is not a ransomware attack and that it has notified relevant authorities. "We have revoked all securityrelated certificates and systems have been remediated or replaced.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Grandoreiro banking malware disrupted – Week in security with Tony Anscombe πŸš€

The banking trojan, which targeted mostly Brazil, Mexico and Spain, blocked the victims screen, logged keystrokes, simulated mouse and keyboard activity and displayed fake popup windows.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account πŸ–‹οΈ

The decentralized social network Mastodon has disclosed a critical security flaw that enables malicious actors to impersonate and take over any account. "Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account," the maintainers said in a terse advisory. The vulnerability, tracked as CVE202423832, has a severity rating of 9.4 out of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks πŸ–‹οΈ

The U.S. Treasury Department's Office of Foreign Assets Control OFAC announced sanctions against six officials associated with the Iranian intelligence agency for attacking critical infrastructure entities in the U.S. and other countries. The officials include Hamid Reza Lashgarian, Mahdi Lashgarian, Hamid Homayunfal, Milad Mansuri, Mohammad Bagher Shirinkar, and Reza Mohammad Amin.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw πŸ–‹οΈ

The threat actors behind the Mispadu banking Trojan have become the latest to exploit a nowpatched Windows SmartScreen security bypass flaw to compromise users in Mexico. The attacks entail a new variant of the malware that was first observed in 2019, Palo Alto Networks Unit 42 said in a report published last week. Propagated via phishing mails, Mispadu is a Delphibased information stealer.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Pegasus Spyware Targeted iPhones of Journalists and Activists in Jordan πŸ–‹οΈ

The iPhones belonging to nearly three dozen journalists, activists, human rights lawyers, and civil society members in Jordan have been targeted with NSO Group's Pegasus spyware, according to joint findings from Access Now and the Citizen Lab. Nine of the 35 individuals have been publicly confirmed as targeted, out of whom had their devices compromised with the mercenary.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ“” UK Court Backlog Blocks Attempts to Fight Fraud Epidemic πŸ“”

KPMG research finds a similar number of highvalue UK fraud cases heard in 2023 to previous year.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ“” Clorox and Johnson Controls Reveal $76m Cyber-Attack Bill πŸ“”

SEC filings reveal multimilliondollar costs of two serious 2023 cyberattacks on Clorox and Johnson Controls.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1πŸ”₯1
🦿 Vix Makes Travels Safer and Smoother With Proactive Global Visibility 🦿

Vix Technology is a global leader in intelligent transportation systems, automated fare collection, and transit analytics. Transit agencies and operators including the major transportation systems of major cities like Edmonton and Seattle rely on Vix to help travelers process fare payments and arrive safely and on time at their destination. Previously, Vix relied ...

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Combined Security Practices Changing the Game for Risk Management πŸ–‹οΈ

A significant challenge within cyber security at present is that there are a lot of risk management platforms available in the market, but only some deal with cyber risks in a very good way. The majority will shout alerts at the customer as and when they become apparent and cause great stress in the process. The issue being that by using a reactive, rather than proactive approach, many risks.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity