πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a previously undocumented threat group called Unfading Sea Haze that's believed to have been active since 2018. The intrusion singled out highlevel organizations in South China Sea countries, particularly military and government targets, Bitdefender said in a report shared with The Hacker News. "The investigation revealed a troubling.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UserPro Plugin Vulnerability Allows Account Takeover πŸ“”

The plugin is used by over 20,000 sites and enables users to create customizable community websites.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Report Reveals 341% Rise in Advanced Phishing Attacks πŸ“”

This data comes from SlashNexts midyear State of Phishing 2024 report.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Trends at the 2024 RSA Startup Competition πŸ•΅οΈβ€β™‚οΈ

Startups at Innovation Sandbox 2024 brought clarity to artificial intelligence, protecting data from AI, and accomplishing novel security solutions with new models.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ US Pumps $50M Into Better Healthcare Cyber Resilience πŸ•΅οΈβ€β™‚οΈ

Upgrade, an ARPAH program, will focus on automating cybersecurity for healthcare institutions so that providers can focus on patient care.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ GitHub Authentication Bypass Opens Enterprise Server to Attackers πŸ•΅οΈβ€β™‚οΈ

The maxseverity bug affects versions using the SAML single signon mechanism.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Build 2024: Copilot AI Will Gain β€˜Personal Assistant’ and Custom Agent Capabilities 🦿

Other announcements included a Snapdragon Dev Kit for Windows, GitHub Copilot Extensions and the general availability of Azure AI Studio.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The End of an Era: Microsoft Phases Out VBScript for JavaScript and PowerShell πŸ–‹οΈ

Microsoft on Wednesday outlined its plans to deprecate Visual Basic Script VBScript in the second half of 2024 in favor of more advanced alternatives such as JavaScript and PowerShell. "Technology has advanced over the years, giving rise to more powerful and versatile scripting languages such as JavaScript and PowerShell," Microsoft Program Manager Naveen Shankar said. "These languages.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ What happens when AI goes rogue (and how to stop it) πŸš€

As AI gets closer to the ability to cause physical harm and impact the real world, its complicated is no longer a satisfying response.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Healthcare cyber attacks have surged in 2024 β€” this new program aims to improve security πŸ“’

With healthcare cyber attacks intensifying over the last year, a new initiative looks to introduce autonomous patching for organizations and reduce cyber risk.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Ransomware Menace Amplifies for Vulnerable Industrial Control Systems: Heightened Threats to Critical Infrastructure πŸ¦…

Ransomhub Targets SCADA of Spanish Bio Energy Plant  The protection of Industrial Control Systems ICS has emerged as a significant concern across all sectors. The security challenges surrounding ICS environments and the essential measures needed to protect vital operations in every industry are undeniable. Since 2022, numerous cyberattacks exploiting loopholes in ICS environments have led to severe repercussions, impacting not just organizations but also critical national infrastructure. These incidents have disrupted public services and governance, underscoring the urgent need for robust security measures to safeguard against such threats.  In a recent disclosure by a recently emerged ransomware group, Ransomhub, claimed an attack on the Spanish Abattoir, Matadero de Gijn. Consid...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” PSNI Faces Β£750,000 Data Breach Fine After Spreadsheet Leak πŸ“”

The Police Service of Northern Ireland has been fined 750K following a serious data breach last year.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” GitHub Fixes Maximum Severity Flaw in Enterprise Server πŸ“”

A newly patched GitHub Enterprise Server bug has a CVSS score of 10.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager πŸ–‹οΈ

Ivanti on Tuesday rolled out fixes to address multiple critical security flaws in Endpoint Manager EPM that could be exploited to achieve remote code execution under certain circumstances. Six of the 10 vulnerabilities from CVE202429822 through CVE202429827 CVSS scores 9.6 relate to SQL injection flaws that allow an unauthenticated attacker within the same network to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ China APT Stole Geopolitical Secrets From Middle East, Africa & Asia πŸ•΅οΈβ€β™‚οΈ

One of China's biggest espionage operations owes its success to longstanding Microsoft Exchange bugs, open source tools, and old malware.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Are Your SaaS Backups as Secure as Your Production Data? πŸ–‹οΈ

Conversations about data security tend to diverge into three main threads How can we protect the data we store on our onpremises or cloud infrastructure? What strategies and tools or platforms can reliably backup and restore data? What would losing all this data cost us, and how quickly could we get it back? All are valid and necessary conversations for technology organizations of all shapes.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Inside Operation Diplomatic Specter: Chinese APT Group's Stealthy Tactics Exposed πŸ–‹οΈ

Governmental entities in the Middle East, Africa, and Asia are the target of a Chinese advanced persistent threat APT group as part of an ongoing cyber espionage campaign dubbed Operation Diplomatic Specter since at least late 2022. "An analysis of this threat actors activity reveals longterm espionage operations against at least seven governmental entities," Palo Alto Networks.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” National Records of Scotland Data Breached in NHS Cyber-Attack πŸ“”

National Records of Scotland said sensitive personal data it holds was part of information stolen and published online by ransomware attackers from NHS Dumfries and Galloway.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Firms have paid out more than $4.8 billion in GDPR fines since 2018 πŸ“’

Tech giants headquartered in Ireland attract the biggest GDPR fines.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Persistent Burnout Is Still a Crisis in Cybersecurity πŸ•΅οΈβ€β™‚οΈ

Burnout has been an oftreported problem among security professionals for years. Are there any new ideas for supporting mental health in the industry?.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NVD Leaves Exploited Vulnerabilities Unchecked πŸ“”

Over half of CISAs known exploited vulnerabilities disclosed since February 2024 have not yet been analyzed by NISTs National Vulnerability Database.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1