πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Oregon Zoo Warns Over 100,000 Customers of Payment Card Compromise πŸ“”

Oregon Zoo revealed that an unauthorized actor potentially obtained payment card information used in transactions over six months.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 More than 3 in 4 Tech Leaders Worry About SaaS Security Threats, New Survey Reveals 🦿

The average enterprise uses 130 different SaaS applications today, up from 80 in 2020, according to Onymos.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New MoonPeak RAT Linked to North Korean Threat Group UAT-5394 πŸ“”

The MoonPeak RAT as used by UAT5394 showed a possible connection to North Korean threat Kimsuky.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Microsoft Patches Critical Copilot Studio Vulnerability Exposing Sensitive Data πŸ–‹οΈ

Cybersecurity researchers have disclosed a critical security flaw impacting Microsoft's Copilot Studio that could be exploited to access sensitive information. Tracked as CVE202438206 CVSS score 8.5, the vulnerability has been described as an information disclosure bug stemming from a serverside request forgery SSRF attack. "An authenticated attacker can bypass ServerSide Request.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ North Korean Hackers Deploy New MoonPeak Trojan in Cyber Campaign πŸ–‹οΈ

A new remote access trojan called MoonPeak has been discovered as being used by a statesponsored North Korean threat activity cluster as part of a new campaign. Cisco Talos attributed the malicious cyber campaign to a hacking group it tracks as UAT5394, which it said exhibits some level of tactical overlaps with a known nationstate actor codenamed Kimsuky. MoonPeak, under active development.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New MoonPeak RAT Linked to North Korean Threat Group UAT-5394 πŸ“”

The MoonPeak RAT as used by UAT5394 showed a possible connection to North Korean threat Kimsuky.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Critical LiteSpeed Cache Plugin Flaw Exposes WordPress Sites πŸ“”

The LiteSpeed Cache flaw may expose millions of WordPress sites to severe security risks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Malware PG_MEM Targets PostgreSQL Databases for Crypto Mining πŸ–‹οΈ

Cybersecurity researchers have unpacked a new malware strain dubbed PGMEM that's designed to mine cryptocurrency after bruteforcing their way into PostgreSQL database instances. "Bruteforce attacks on Postgres involve repeatedly attempting to guess the database credentials until access is gained, exploiting weak passwords," Aqua security researcher Assaf Morag said in a technical report. ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Fixes High-Severity Chrome Flaw Actively Exploited in the Wild πŸ–‹οΈ

Google has rolled out security fixes to address a highseverity security flaw in its Chrome browser that it said has come under active exploitation in the wild. Tracked as CVE20247971, the vulnerability has been described as a type confusion bug in the V8 JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical Flaw in WordPress LiteSpeed Cache Plugin Allows Hackers Admin Access πŸ–‹οΈ

Cybersecurity researchers have disclosed a critical security flaw in the LiteSpeed Cache plugin for WordPress that could permit unauthenticated users to gain administrator privileges. "The plugin suffers from an unauthenticated privilege escalation vulnerability which allows any unauthenticated visitor to gain Administrator level access after which malicious plugins could be uploaded and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GitHub Patches Critical Security Flaw in Enterprise Server Granting Admin Privileges πŸ–‹οΈ

GitHub has released fixes to address a set of three security flaws impacting its Enterprise Server product, including one critical bug that could be abused to gain site administrator privileges. The most severe of the shortcomings has been assigned the CVE identifier CVE20246800, and carries a CVSS score of 9.5. "On GitHub Enterprise Server instances that use SAML single signon SSO.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ How regulatory standards and cyber insurance inform each other πŸš€

Should the payment of a ransomware demand be illegal? Should it be regulated in some way? These questions are some examples of the legal minefield that cybersecurity teams must deal with.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Backdoor in Mifare Smart Cards Could Open Doors Around the World πŸ“”

Quarklabs researchers claim millions of contactless key cards could be cloned via a backdoor.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Novel Android Malware Steals Card NFC Data For ATM Withdrawals πŸ“”

ESET claims new NGate Android malware relays NFC data to steal card details for ATM cashout.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ British Library issues Β£400,000 tender as rebuild continues after 2023 cyber attack πŸ“’

The British Library's digital transformation project was initially set back by a major cyber attack in October 2023 now its looking to get back on track.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Security Flaws in UK Political Party Donation Platforms Exposed πŸ“”

The donation websites of the UKs seven major political parties are missing critical security features to protect the accounts of donors, according to DataDome.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Facts About Continuous Penetration Testing and Why It’s Important πŸ–‹οΈ

What is Continuous Attack Surface Penetration Testing or CASPT? Continuous Penetration Testing or Continuous Attack Surface Penetration Testing CASPT is an advanced security practice that involves the continuous, automated, and ongoing penetration testing services of an organization's digital assets to identify and mitigate security vulnerabilities. CASPT is designed for enterprises with an.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ AI and data protection: What businesses need to know πŸ“’

Generative AI tools such as ChatGPT pose risks to data protection firms still struggling to put an AI strategy in place will struggle down the line.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Hackers could dupe Slack's AI features to expose private channel messages πŸ“’

The companys internal Slack AI feature can be manipulated into disclosing sensitive data from private channels, new research shows.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Cyber Security and IT Leadership: A Growing Threat to Australia’s Renewable Energy Efforts 🦿

Australia is rapidly embracing renewable energy. But for the nation to successfully leverage green energy, it is imperative to establish strong IT foundations.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Delays Recall Launch for Windows Insider Members Until October 🦿

An upcoming blog post for members of the Windows Insider Program will explain how to get the AIpowered Recall feature.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity