πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸš€ Mandatory reporting for ransomware attacks? – Week in security with Tony Anscombe πŸš€

As the UK mulls new rules for ransomware disclosure, what would be the wider implications of such a move, how would cyberinsurance come into play, and how might cybercriminals respond?.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
πŸ–‹οΈ Experts Find Flaw in Replicate AI Service Exposing Customers' Models and Data πŸ–‹οΈ

Cybersecurity researchers have discovered a critical security flaw in an artificial intelligence AIasaservice provider Replicate that could have allowed threat actors to gain access to proprietary AI models and sensitive information. "Exploitation of this vulnerability would have allowed unauthorized access to the AI prompts and results of all Replicate's platform customers,".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 6 Facts About How Interpol Fights Cybercrime πŸ•΅οΈβ€β™‚οΈ

So you think you know Interpol? Here are some key details of how this international law enforcement entity disrupts cybercrime worldwide.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Pakistan-linked Hackers Deploy Python, Golang, and Rust Malware on Indian Targets πŸ–‹οΈ

The Pakistannexus Transparent Tribe actor has been linked to a new set of attacks targeting Indian government, defense, and aerospace sectors using crossplatform malware written in Python, Golang, and Rust. "This cluster of activity spanned from late 2023 to April 2024 and is anticipated to persist," the BlackBerry Research and Intelligence Team said in a technical report.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Learn how to Protect your Business with this $30 Cybersecurity Training 🦿

This extensive bundle includes eight courses from leading instructors covering certification exams from CompTIA and Cisco to set you up for success.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Tricks in the Phishing Playbook: Cloudflare Workers, HTML Smuggling, GenAI πŸ–‹οΈ

Cybersecurity researchers are alerting of phishing campaigns that abuse Cloudflare Workers to serve phishing sites that are used to harvest users' credentials associated with Microsoft, Gmail, Yahoo!, and cPanel Webmail. The attack method, called transparent phishing or adversaryinthemiddle AitM phishing, "uses Cloudflare Workers to act as a reverse proxy server for a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Moroccan Cybercrime Group Steals Up to $100K Daily Through Gift Card Fraud πŸ–‹οΈ

Microsoft is calling attention to a Moroccobased cybercrime group dubbed Storm0539 that's behind gift card fraud and theft through highly sophisticated email and SMS phishing attacks. "Their primary motivation is to steal gift cards and profit by selling them online at a discounted rate," the company said in its latest Cyber Signals report. "We've seen some examples where.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Report: The Dark Side of Phishing Protection πŸ–‹οΈ

The transition to the cloud, poor password hygiene and the evolution in webpage technologies have all enabled the rise in phishing attacks. But despite sincere efforts by security stakeholders to mitigate them through email protection, firewall rules and employee education phishing attacks are still a very risky attack vector. A new report by LayerX explores the state of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 SentinelOne vs Palo Alto: Compare EDR software 🦿

Compare the key features of two EDR tools SentinelOne's Singularity XDR and Palo Alto's Cortex XDR.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Get 9 Courses on Ethical Hacking for Just $50 🦿

Kickstart a lucrative career in pentesting and ethical hacking with this ninecourse bundle from IDUNOVA, now on sale for just 49.99 for a limited time.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ WithSecure Sphere 2024 live: All the news and updates as they happen πŸ“’

ITPro is live on the ground in Helsinki for WithSecure SPHERE 2024 follow all the news, updates, and announcements as they happen.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
πŸ–‹οΈ WordPress Plugin Exploited to Steal Credit Card Data from E-commerce Sites πŸ–‹οΈ

Unknown threat actors are abusing lesserknown code snippet plugins for WordPress to insert malicious PHP code in victim sites that are capable of harvesting credit card data. The campaign, observed by Sucuri on May 11, 2024, entails the abuse of a WordPress plugin called Dessky Snippets, which allows users to add custom PHP code. It has over 200 active installations.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ TP-Link Gaming Router Vulnerability Exposes Users to Remote Code Attacks πŸ–‹οΈ

A maximumseverity security flaw has been disclosed in the TPLink Archer C5400X gaming router that could lead to remote code execution on susceptible devices by sending specially crafted requests. The vulnerability, tracked as CVE20245035, carries a CVSS score of 10.0. It impacts all versions of the router firmware including and prior to 11.1.6. It has .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2024: Why Human Risk Management is Cybersecurity's Next Step for Awareness πŸ“”

With most cyberattacks still involving a nonmalicious human element, it is clear that awareness training alone is insufficient, this is where human risk management comes into play.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2024: Charity Bridges Digital Divide and Fuels New Cyber Talent πŸ“”

Every Child Online, a UK charity, tackles the digital divide and potential cybersecurity skills gap by offering free refurbished IT equipment to underprivileged children.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ How identity theft makes a mockery of traditional antivirus – and exposes your business to unnecessary risk πŸ“’

Pinning your businesss cyber resilience on traditional antivirus software is no longer a viable security strategy, heres how identitybased attacks are rewriting cyber security.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Why embracing Endpoint Security and Identity Protection could be the most important security decision you take in 2024 and beyond πŸ“’

Leaders can use EPP and IDP to combine disparate security solutions in the cloud and shore up the most common routes for attack.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Christie’s given Friday ransom deadline after threat group claims responsibility for cyber attack πŸ“’

Christie's has been handed an ultimatum by RansomHub.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 6 Best VPNs for Canada in 2024 (Free & Paid VPNs) 🦿

What is the best VPN provider in Canada? Use our guide to compare the pricing and features of our recommended VPNs for Canada.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 4-Step Approach to Mapping and Securing Your Organization's Most Critical Assets πŸ–‹οΈ

Youre probably familiar with the term critical assets. These are the technology assets within your company's IT infrastructure that are essential to the functioning of your organization. If anything happens to these assets, such as application servers, databases, or privileged identities, the ramifications to your security posture can be severe.  But is every technology asset considered.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Warn of CatDDoS Botnet and DNSBomb DDoS Attack Technique πŸ–‹οΈ

The threat actors behind the CatDDoS malware botnet have exploited over 80 known security flaws in various software over the past three months to infiltrate vulnerable devices and coopt them into a botnet for conducting distributed denialofservice DDoS attacks. "CatDDoSrelated gangs' samples have used a large number of known vulnerabilities to deliver samples," the QiAnXin XLab team .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity