πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 OpenAI, Anthropic Research Reveals More About How LLMs Affect Security and Bias 🦿

Anthropic opened a window into the black box where features steer a large language models output. OpenAI dug into the same concept two weeks later with a deep dive into sparse autoencoders.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ 560 million Ticketmaster customer data for sale? – Week in security with Tony Anscombe πŸš€

Ticketmaster seems to have experienced a data breach, with the ShinyHunters hacker group claiming to have exfiltrated 560 million customer data. Watch as Tony discusses the story and provides useful tips on how to protect people's data.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Microsoft Revamps Controversial AI-Powered Recall Feature Amid Privacy Concerns πŸ–‹οΈ

Microsoft on Friday said it will disable its muchcriticized artificial intelligence AIpowered Recall feature by default and make it an optin. Recall, currently in preview and coming exclusively to Copilot PCs on June 18, 2024, functions as an "explorable visual timeline" by capturing screenshots of what appears on users' screens every five seconds, which are subsequently analyzed and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New PHP Vulnerability Exposes Windows Servers to Remote Code Execution πŸ–‹οΈ

Details have emerged about a new critical security flaw impacting PHP that could be exploited to achieve remote code execution under certain circumstances. The vulnerability, tracked as CVE20244577, has been described as a CGI argument injection vulnerability affecting all versions of PHP installed on the Windows operating system. According to DEVCORE security researcher, the shortcoming makes.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2πŸ₯°1
πŸ•΅οΈβ€β™‚οΈ Governments, Businesses Tighten Cybersecurity Around Hajj Season πŸ•΅οΈβ€β™‚οΈ

While cyberattacks drop slightly during the week of the Islamic pilgrimage, organizations in Saudi Arabia and other countries with large Muslim populations see attacks on the rise.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Sticky Werewolf Expands Cyber Attack Targets in Russia and Belarus πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a threat actor known as Sticky Werewolf that has been linked to cyber attacks targeting entities in Russia and Belarus. The phishing attacks were aimed at a pharmaceutical company, a Russian research institute dealing with microbiology and vaccine development, and the aviation sector, expanding beyond their initial focus of government.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ A lifeline for LockBit victims? The FBI now has 7,000 decryption keys available – and it’s urging affected organizations to come forward πŸ“’

The FBI has has more than 7,000 LockBit decryption keys available and has put out a call for affected organizations to come forward.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 How Your Business Can Benefit from a Network Security Policy 🦿

A companys network must be secured to ensure the safety of its data against the risks of cyberthreats.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NHS Appeals For Blood and Volunteers After Cyber-Attack πŸ“”

London hospitals continue to suffer the aftereffects of a major ransomware attack last week.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Threat Actor Claims to Leak 270GB of New York Times Data πŸ“”

An anonymous 4Chan user is claiming to have shared a trove of source code stolen from the New York Times.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Avast Business Security review: Strong, affordable protection for smaller businesses πŸ“’

With an excellent antivirus engine and easy management, Avast Business Security is a great solution for SMBs wanting to shore up and centralize their protection.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Microsoft backtracks on Windows Recall feature amid industry outcry πŸ“’

Windows Recall has been met with hefty criticism since first being announced, forcing Microsoft to act.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cybersecurity CPEs: Unraveling the What, Why & How πŸ–‹οΈ

Staying Sharp Cybersecurity CPEs Explained Perhaps even more so than in other professional domains, cybersecurity professionals constantly face new threats. To ensure you stay on top of your game, many certification programs require earning Continuing Professional Education CPE credits. CPEs are essentially units of measurement used to quantify the time and effort professionals spend on.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Azure Service Tags Vulnerability: Microsoft Warns of Potential Abuse by Hackers πŸ–‹οΈ

Microsoft is warning about the potential abuse of Azure Service Tags by malicious actors to forge requests from a trusted service and get around firewall rules, thereby allowing them to gain unauthorized access to cloud resources. "This case does highlight an inherent risk in using service tags as a single mechanism for vetting incoming network traffic," the Microsoft Security Response Center .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Takes Down Influence Campaigns Tied to China, Indonesia, and Russia πŸ–‹οΈ

Google has revealed that it took down 1,320 YouTube channels and 1,177 Blogger blogs as part of a coordinated influence operation connected to the Peoples Republic of China PRC. "The coordinated inauthentic network uploaded content in Chinese and English about China and U.S. foreign affairs," Google Threat Analysis Group TAG researcher Billy Leonard said in the company's quarterly bulletin.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” IoT Vulnerabilities Skyrocket, Becoming Key Entry Point for Attackers πŸ“”

A new Forescout report found that IoT devices containing vulnerabilities surged 136 compared to a year ago, becoming a key focus for attackers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Vietnamese Entities Targeted by China-Linked Mustang Panda in Cyber Espionage πŸ¦…

Key Takeaways  Cyble Research and Intelligence Labs CRIL recently came across a campaign employing Windows shortcut LNK files associated with the Mustang Panda APT group.  Mustang Panda, with its Chinese affiliation, suggests potential statesponsored or stateaffiliated cyber espionage activities targeting government organizations, nonprofits, religious institutions, and other NGOs across the U.S., Europe, Mongolia, Myanmar, Pakistan, Vietnam, and various other regions.  The two campaigns we analyzed are aimed at Vietnam, using lures related to Tax Compliance and the education sector.  The campaign employs sophisticated stages, abusing legitimate tools like forfiles.exe to execute malicious HTA files hosted on remote servers. Additionally, it incorporates PowerShell, VBScript,...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Crowdstrike vs Trellix (2024): What Are The Main Differences? 🦿

Endpoint detection and response software protects against a variety of threats and attacks. Learn about two of the most popular EDR options, CrowdStrike and McAfee, and how to protect your network.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ›  American Fuzzy Lop plus plus 4.21c πŸ› 

Google's American Fuzzy Lop is a bruteforce fuzzer coupled with an exceedingly simple but rocksolid instrumentationguided genetic algorithm. afl is a superior fork to Google's afl. It has more speed, more and better mutations, more and better instrumentation, custom module support, etc.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Making Choices for Stronger Vulnerability Management πŸ•΅οΈβ€β™‚οΈ

The threat environment will continue to grow in complexity. Now is the time for organizations to streamline how they manage and mitigate overlooked vulnerabilities.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Is a US Nationwide Privacy Law Really Coming? πŸ•΅οΈβ€β™‚οΈ

If passed, APRA will be a giant leap forward for the rights and freedoms of Americans.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity