πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.7K subscribers
89.8K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Ransomware Groups Prioritize Defense Evasion for Data Exfiltration πŸ“”

A Cisco report highlighted TTPs used by the most prominent ransomware groups to evade detection, establish persistence and exfiltrate sensitive data.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Russian Media Uses AI-Powered Software to Spread Disinformation πŸ“”

RT leverages the Meliorator software to create fake personas on social media, US, Canadian and Dutch agencies have found.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Most Security Pros Admit Shadow SaaS and AI Use πŸ“”

Next DLP study finds majority of security professionals have used unauthorised apps in past year.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft Fixes Four Zero-Days in July Patch Tuesday πŸ“”

Microsoft has addressed two actively exploited and two publicly disclosed zeroday bugs this month.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Privacy & Security Concerns With AI Meeting Tools πŸ•΅οΈβ€β™‚οΈ

Businesses need to find a balance between harnessing the benefits of AI assistants and safeguarding sensitive information maintaining trust with employees and clients.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Ransomware Group Exploiting Veeam Backup Software Vulnerability πŸ–‹οΈ

A nowpatched security flaw in Veeam Backup Replication software is being exploited by a nascent ransomware operation known as EstateRansomware. Singaporeheadquartered GroupIB, which discovered the threat actor in early April 2024, said the modus operandi involved the exploitation of CVE202327532 CVSS score 7.5 to carry out the malicious activities. Initial access to the target.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… NATO’s 75th Anniversary Washington Summit Draws Ire of Hacktivist Groups πŸ¦…

Washington is hosting the NATO 75th Anniversary Summit from July 9 to July 11, 2024. This pivotal meeting includes heads of state, senior military personnel, and experts from 32 NATO members. The summit is crucial for the Alliance to bolster support for Ukraine, enhance NATO's defense capabilities in the wake of Russia and China's increasingly aggressive stance, expand global partnerships, and address key geopolitical challenges.    In keeping with their established patterns, particularly in the aftermath of the conflict in Ukraine, hacktivists have been quick to target the Washington Summit. The ongoing developments among NATO allies to back Ukraine in the ongoing conflict have already drawn multiple attacks on the digital infrastructure of these countries over the last two years. ...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ New Snowflake security policies mean admins can now enforce mandatory MFA πŸ“’

The changes come two months after a major breach affected dozens of Snowflake customers.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Poco RAT Burrows Deep Into Mining Sector πŸ•΅οΈβ€β™‚οΈ

The novel malware targets Spanishspeaking users via malicious Google Drive links, and taps a popular C library to evade detection.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft Outlook Faced Critical Zero-Click RCE Vulnerability πŸ“”

For trusted senders, the flaw is zeroclick, but requires oneclick interactions for untrusted ones.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ The Stark Truth Behind the Resurgence of Russia’s Fin7 β™ŸοΈ

The Russiabased cybercrime group dubbed "Fin7," known for phishing and malware attacks that have cost victim organizations an estimated 3 billion in losses since 2013, was declared dead last year by U.S. authorities. But experts say Fin7 has roared back to life in 2024 setting up thousands of websites mimicking a range of media and technology companies with the help of Stark Industries Solutions, a sprawling hosting provider is a persistent source of cyberattacks against enemies of Russia.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Smishing Triad Targets India with Fraud Surge πŸ“”

Smishing Triad's MO involves registering fraudulent domain names that mimic legitimate organizations.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Microsoft's Partnership With Middle East AI Firm Under Scrutiny πŸ•΅οΈβ€β™‚οΈ

The US government worries that Group 42 Holdings, an AI firm based in the United Arab Emirates, could become a backdoor for technology leaks to China.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Fujitsu Suffers Worm-Like Attack From Something That Wasn't Ransomware πŸ•΅οΈβ€β™‚οΈ

The CE giant released its investigative findings regarding a March cyberattack that resulted in data exfiltration affecting its Japanese operations.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Peloton Takes a Spin Through Court, Thanks to AI Privacy Lawsuit πŸ•΅οΈβ€β™‚οΈ

The case alleges a thirdparty marketer for the exercise giant improperly used customer chat data to train its AI models.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Attackers Have Been Leveraging Microsoft Zero-Day for 18 Months πŸ•΅οΈβ€β™‚οΈ

Likely two separate threat actors are using the justpatched CVE202438112 in targeted, concurrent infostealer campaigns.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Feds Uncover Sprawling, GenAI-Enabled Russian Troll Farm πŸ•΅οΈβ€β™‚οΈ

The bot farm was created using AIenhanced software that was able to create a host of different false personas to spread disinformation in convincing and unsettling ways.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ₯°1
🦿 Cisco Talos: Top Ransomware TTPs Exposed 🦿

Read about the new Cisco Talos report on the top ransomware groups techniques and learn how to mitigate this cybersecurity risk. Cisco Talos observed the TTPs used by 14 of the most prevalent ransomware groups based on their volume of attack, impact to customers and atypical behavior.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 AWS Summit New York 2024: Guardrails for Amazon Bedrock Gains Claude 3 Haiku and Contextual Grounding 🦿

Responsible AI Lead Diya Wynn spoke to TechRepublic about AI hallucinations and upskilling.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks πŸ–‹οΈ

Multiple threat actors have been observed exploiting a recently disclosed security flaw in PHP to deliver remote access trojans, cryptocurrency miners, and distributed denialofservice DDoS botnets. The vulnerability in question is CVE20244577 CVSS score 9.8, which allows an attacker to remotely execute malicious commands on Windows systems using Chinese and Japanese language locales. It.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Jobs πŸ–‹οΈ

GitLab has shipped another round of updates to close out security flaws in its software development platform, including a critical bug that allows an attacker to run pipeline jobs as an arbitrary user. Tracked as CVE20246385, the vulnerability carries a CVSS score of 9.6 out of a maximum of 10.0. "An issue was discovered in GitLab CEEE affecting versions 15.8 prior to 16.11.6, 17.0 prior to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity