πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ Patch Now: CrushFTP Zero-Day Cloud Exploit Targets US Orgs πŸ•΅οΈβ€β™‚οΈ

An exploit for the vulnerability allows unauthenticated attackers to escape a virtual file system sandbox to download system files and potentially achieve RCE.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ U.S. Treasury Sanctions Iranian Firms and Individuals Tied to Cyber Attacks πŸ–‹οΈ

The U.S. Treasury Department's Office of Foreign Assets Control OFAC on Monday sanctioned two firms and four individuals for their involvement in malicious cyber activities on behalf of the Iranian Islamic Revolutionary Guard Corps Cyber Electronic Command IRGCCEC from at least 2016 to April 2021. This includes the front companies Mehrsam Andisheh Saz Nik MASN and Dadeh.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Detail Multistage Attack Hijacking Systems with SSLoad, Cobalt Strike πŸ–‹οΈ

Cybersecurity researchers have discovered an ongoing attack campaign that's leveraging phishing emails to deliver malware called SSLoad. The campaign, codenamed FROZENSHADOW by Securonix, also involves the deployment of Cobalt Strike and the ConnectWise ScreenConnect remote desktop software. "SSLoad is designed to stealthily infiltrate systems, gather sensitive.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Sanctions Iranian "Fronts" for Cyber-Attacks on American Entities πŸ“”

The US Treasury announced sanctions on two companies and four individuals for cyber campaigns conducted on behalf of the Iranian government.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🧨 How to Tell If Your Text Message Is Real 🧨

According to reports from the Federal Trade Commissions Consumer Sentinel database, text message scams swindled 330 million from Americans in... The post How to Tell If Your Text Message Is Real  appeared first on McAfee Blog.

πŸ“– Read more.

πŸ”— Via "McAfee"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 2023: A 'Good' Year for OT Cyberattacks πŸ•΅οΈβ€β™‚οΈ

Attacks increased by "only" 19 last year. But that number is expected to grow significently.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Congress Passes Bill to Ban TikTok πŸ“”

The bill that could see TikTok banned in the US has been approved by the House of Representatives and the Senate.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Iran Dupes US Military Contractors, Gov't Agencies in Years-Long Cyber Campaign πŸ•΅οΈβ€β™‚οΈ

A statesponsored hacking team employed a clever masquerade and elaborate backend infrastructure as part of a fiveyear infostealing campaign that compromised the US State and Treasury Departments, and hundreds of thousands of accounts overall.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ TechSlayer chronicles - Digital defenders: πŸ“’

Securing hybrid cloud infrastructure from alien forces.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The basics and business of trusted security πŸ“’

Deploy technology with confidence.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Trusted security from the edge to the cloud πŸ“’

Counter cyber risks and threats.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Putting Trusted Security to Work πŸ“’

Securely manage servers across their entire lifecycle.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ North Korea APT Triumvirate Spied on South Korean Defense Industry For Years πŸ•΅οΈβ€β™‚οΈ

Lazarus, Kimsuky, and Andariel all got in on the action, stealing "important" data from firms responsible for defending their southern neighbors from them.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Prompt Hacking, Private GPTs, Zero-Day Exploits and Deepfakes: Report Reveals the Impact of AI on Cyber Security Landscape 🦿

A new report by cyber security firm Radware identifies the four main impacts of AI on the threat landscape emerging this year.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Lights On in Leicester: Streetlights in Disarray After Cyberattack πŸ•΅οΈβ€β™‚οΈ

The city is stymied in efforts to pinpoint the issue since its IT systems were shut down in the wake of the cyberattack.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ KnowBe4 to Acquire Egress πŸ•΅οΈβ€β™‚οΈ



πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Black Girls Do Engineer Signs Education Partnership Agreement With NSA πŸ•΅οΈβ€β™‚οΈ



πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Attacker Social-Engineered Backdoor Code Into XZ Utils πŸ•΅οΈβ€β™‚οΈ

Unlike the SolarWinds and CodeCov incidents, all that it took for an adversary to nearly pull off a massive supply chain attack was some slick social engineering and a string of pressure emails.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Postpones Third-Party Cookie Deprecation Amid U.K. Regulatory Scrutiny πŸ–‹οΈ

Google has once again pushed its plans to deprecate thirdparty tracking cookies in its Chrome web browser as it works to address outstanding competition concerns from U.K. regulators over its Privacy Sandbox initiative. The tech giant said it's working closely with the U.K. Competition and Markets Authority CMA and hopes to achieve an agreement by the end of the year. As part of the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ State-Sponsored Hackers Exploit Two Cisco Zero-Day Vulnerabilities for Espionage πŸ–‹οΈ

A new malware campaign leveraged two zeroday flaws in Cisco networking gear to deliver custom malware and facilitate covert data collection on target environments. Cisco Talos, which dubbed the activity ArcaneDoor, attributing it as the handiwork of a previously undocumented sophisticated statesponsored actor it tracks under the name UAT4356 aka Storm1849 by Microsoft. ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” High Performance Podcast Duo to Unveil Secrets of Success at Infosecurity Europe 2024 πŸ“”

Jake Humphrey and Professor Damian Hughes, the minds behind the High Performance Podcast, share their top nonnegotiable behaviours for success in cybersecurity.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1