πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.2K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ New PEAKLIGHT Dropper Deployed in Attacks Targeting Windows with Malicious Movie Downloads πŸ–‹οΈ

Cybersecurity researchers have uncovered a neverbeforeseen dropper that serves as a conduit to launch nextstage malware with the ultimate goal of infecting Windows systems with information stealers and loaders. "This memoryonly dropper decrypts and executes a PowerShellbased downloader," Googleowned Mandiant said. "This PowerShellbased downloader is being tracked as PEAKLIGHT." Some of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Webinar: Experience the Power of a Must-Have All-in-One Cybersecurity Platform πŸ–‹οΈ

Let's be honest. The world of cybersecurity feels like a constant war zone. You're bombarded by threats, scrambling to keep up with patches, and drowning in an endless flood of alerts. It's exhausting, isnt it? But what if there was a better way? Imagine having every essential cybersecurity tool at your fingertips, all within a single, intuitive platform, backed by expert support 247. This is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Focus on What Matters Most: Exposure Management and Your Attack Surface πŸ–‹οΈ

Read the full article for key points from Intruders VP of Product, Andy Hornegolds recent talk on exposure management. If youd like to hear Andys insights firsthand, watch Intruders ondemand webinar. To learn more about reducing your attack surface, reach out to their team today.  Attack surface management vs exposure management Attack surface management ASM is the ongoing.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Qilin Ransomware Attack Uses VPN Credentials, Steals Chrome Data πŸ–‹οΈ

The threat actors behind a recently observed Qilin ransomware attack have stolen credentials stored in Google Chrome browsers on a small set of compromised endpoints. The use of credential harvesting in connection with a ransomware infection marks an unusual twist, and one that could have cascading consequences, cybersecurity firm Sophos said in a Thursday report. The attack, detected in July.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ NGate Android malware relays NFC traffic to steal cash πŸš€

Android malware discovered by ESET Research relays NFC data from victims payment cards, via victims mobile phones, to the device of a perpetrator waiting at an ATM.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Georgia Tech Sued Over Cybersecurity Violations πŸ“”

The US government has filed a lawsuit against Georgia Tech for alleged cybersecurity violations as a Department of Defense contractor.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Qilin Caught Red-Handed Stealing Credentials in Google Chrome πŸ“”

Browser credential harvesting is an unusual activity for a ransomware group.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” YouTube Launches AI Tool to Recover Hacked Accounts πŸ“”

YouTubes new AI troubleshooting tool is designed to help users recover and secure their accounts after theyve been hacked.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Liverpool Fans Lose Big in Premier League Ticket Scams πŸ“”

Liverpool fans were the most frequent and highestvalue targets for ticket scams last season, losing over 17,000 to fraudsters.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Cybercriminals Deploy New Malware to Steal Data via Android’s Near Field Communication (NFC) 🦿

A new malware called NGate allows cybercriminals to steal near field communication data from Android phones via sophisticated social engineering. The data is relayed to the fraudsters before being used to steal cash.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Constantly Evolving MoonPeak RAT Linked to North Korean Spying πŸ•΅οΈβ€β™‚οΈ

The malware is a customized variant of the powerful open source XenoRAT information stealing malware often deployed by Kimsuky and other DPRK APTs.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ NIST Hands Off Post-Quantum Cryptography Work to Cyber Teams πŸ•΅οΈβ€β™‚οΈ

The release of new NIST quantumproof cryptography standards signals it's time for cybersecurity teams to get serious about preparing for the rise of quantum threats.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Patch Now: Second SolarWinds Critical Bug in Web Help Desk πŸ•΅οΈβ€β™‚οΈ

The disclosure of CVE202428987 means that, in two weeks, there have been two critical bugs and corresponding patches for SolarWinds' lessoftendiscussed IT help desk software.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Liverpool Fans Take English Premier League Title for Ticket Scams πŸ•΅οΈβ€β™‚οΈ

Ticket scams are costing football fans close to 200 a season, on average, according to a report.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ C-Suite Involvement in Cybersecurity Is Little More Than Lip Service πŸ•΅οΈβ€β™‚οΈ

Collaboration with security teams, making cybersecurity a core principle of business strategy, and investing in defenses better position organizations to thwart threats and ensure business continuity.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ NFC Traffic Stealer Targets Android Users & Their Banking Info πŸ•΅οΈβ€β™‚οΈ

The malware builds on a nearfield communication tool in combination with phishing and social engineering to steal cash.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ NSA Issues Tips for Better Logging, Threat Detection in LotL Incidents πŸ•΅οΈβ€β™‚οΈ

The guidance is part of a coordinated, global effort to eradicate livingofftheland techniques used against critical infrastructure.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ PWA phishing on Android and iOS – Week in security with Tony Anscombe πŸš€

Phishing using PWAs? ESET Research's latest discovery might just ruin some users' assumptions about their preferred platform's security.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA has placed a security flaw impacting Versa Director to its Known Exploited Vulnerabilities KEV catalog based on evidence of active exploitation. The mediumseverity vulnerability, tracked as CVE202439717 CVSS score 6.6, is case of file upload bug impacting the "Change Favicon" feature that could allow a threat actor to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Meta Exposes Iranian Hacker Group Targeting Global Political Figures on WhatsApp πŸ–‹οΈ

Meta Platforms on Friday became the latest company after Microsoft, Google, and OpenAI to expose the activities of an Iranian statesponsored threat actor, who it said used a set of WhatsApp accounts that attempted to target individuals in Israel, Palestine, Iran, the U.K., and the U.S. The activity cluster, which originated from Iran, "appeared to have focused on political and diplomatic.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Telegram Founder Pavel Durov Arrested in France for Content Moderation Failures πŸ–‹οΈ

Pavel Durov, founder and chief executive of the popular messaging app Telegram, was arrested in France on Saturday, according to French television network TF1. Durov is believed to have been apprehended pursuant to a warrant issued in connection with a preliminary police investigation. TF1 said the probe was focused on a lack of content moderation on the instant messaging service, which the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity