πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Secrets Exposed: Why Your CISO Should Worry About Slack πŸ–‹οΈ

In the digital realm, secrets API keys, private keys, username and password combos, etc. are the keys to the kingdom. But what if those keys were accidentally left out in the open in the very tools we use to collaborate every day? A Single Secret Can Wreak Havoc Imagine this It's a typical Tuesday in June 2024. Your dev team is kneedeep in sprints, Jira tickets are flying, and Slack is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access πŸ–‹οΈ

Eight vulnerabilities have been uncovered in Microsoft applications for macOS that an adversary could exploit to gain elevated privileges or access sensitive data by circumventing the operating system's permissionsbased model, which revolves around the Transparency, Consent, and Control TCC framework. "If successful, the adversary could gain any privileges already granted to the affected.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Three Plead Guilty to Running MFA Bypass Site πŸ“”

Three British men are facing jail after pleading guilty to running an MFA bypass site dubbed OTP Agency.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Three Plead Guilty to Running MFA Bypass Site πŸ“”

Three British men are facing jail after pleading guilty to running an MFA bypass site dubbed OTP Agency.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” TfL Claims Cyber-Incident is Not Impacting Services πŸ“”

Londons transport body, TfL, is playing down the impact of a cybersecurity incident on its services.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Improved Software Supply Chain Resilience Equals Increased Security πŸ•΅οΈβ€β™‚οΈ

Understanding through visibility, managing through governance, and anticipating through continuous deployment will better prepare organizations for the next supply chain attack.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 Cost of a data breach: Cost savings with law enforcement involvement 🧠

For those working in the information security and cybersecurity industries, the technical impacts of a data breach are generally understood. But for those outside of these technical functions, such as executives, operators and business support functions, explaining the real impact of a breach can be difficult. Therefore, explaining impacts in terms of quantifiable financial figures The post Cost of a data breach Cost savings with law enforcement involvement appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus πŸ–‹οΈ

A hacktivist group known as Head Mare has been linked to cyber attacks that exclusively target organizations located in Russia and Belarus. "Head Mare uses more uptodate methods for obtaining initial access," Kaspersky said in a Monday analysis of the group's tactics and tools. "For instance, the attackers took advantage of the relatively recent CVE202338831 vulnerability in WinRAR, which.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Rust-Based Ransomware Cicada3301 Targets Windows and Linux Systems πŸ–‹οΈ

Cybersecurity researchers have unpacked the inner workings of a new ransomware variant called Cicada3301 that shares similarities with the nowdefunct BlackCat aka ALPHV operation. "It appears that Cicada3301 ransomware primarily targets small to mediumsized businesses SMBs, likely through opportunistic attacks that exploit vulnerabilities as the initial access vector," cybersecurity.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Palo Alto's GlobalProtect VPN Spoofed to Deliver New Malware Variant πŸ“”

A variant of the WikiLoader malware was observed being delivered via SEO poisoning and spoofing Palo Alto Networks GlobalProtect VPN software.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 VMware ESXi Servers Targeted by New Ransomware Variant from Cicada3301 Group 🦿

A number of similarities between Cicada3301 and ALPHVBlackCat indicates that it could represent a rebrand or offshoot group.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google Removing Poor-Quality Android Apps From Play Store to Boost Engagement 🦿

Included in the purge are static apps, those with limited functionality and content, and apps that crash, freeze, and dont offer an engaging user experience, the company said.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Sextortion Scams Now Include Photos of Your Home β™ŸοΈ

An old but persistent email scam known as "sextortion" has a new personalized touch The missives, which claim that malware has captured webcam footage of recipients pleasuring themselves, now include a photo of the target's home in a bid to make threats about publishing the videos more frightening and convincing.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
😱1
πŸ“” Civil Rights Groups Call For Spyware Controls πŸ“”

Civil society and journalists organizations in Europe ask the EU to take steps to regulate spyware technologies.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Rapid Growth of Password Reset Attacks Boosts Fraud and Account Takeovers πŸ“”

Researchers say password reset attacks have grown fourfold in the last year and one in four password reset attempts are fraudulent.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Active Ransomware Groups Surge by 56% in 2024 πŸ“”

Searchlight Cyber observed a 56 rise in active ransomware groups in H1 2024, demonstrating the growing fragmentation of the ransomware landscape.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 SOC Automation: Streamlining Security Operations (+CISO’s Checklist) 🌊

Are you sure your SOC is invincible armor? How often do you hear about the burnout of inhouse SOC analysts? I will not bore you with dry statistics proving that security operation centers SOCs are swamped with tasks, most of which do not require any actions yet missed out on critical.  The solution is clear The post SOC Automation Streamlining Security Operations CISOs Checklist appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Product Manager 🌊

The post Product Manager appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… CERT-In Advisory and WikiLoader Campaign: Comprehensive Overview of Recent Security Threats πŸ¦…

CERTIn's advisory on Palo Alto Networks vulnerabilities and WikiLoaders fake GlobalProtect installers highlight major security risks. Key Takeaways CERTIn has issued a critical advisory highlighting vulnerabilities in multiple Palo Alto Networks applications, including GlobalProtect, Cloud NGFW, PANOS, and Cortex XSOAR. Concurrently, new malware distribution methods involving WikiLoader have been detected, leveraging spoofed GlobalProtect installers. The vulnerabilities identified include privilege escalation CVE20245915, information disclosure CVE20245916, and command injection CVE20245914. WikiLoader, a sophisticated loader, uses advanced evasion techniques such as SEO poisoning to distribute its payload. Specific versions of affected software and newly observed malware t...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ City of Columbus Sues Researcher After Ransomware Attack πŸ•΅οΈβ€β™‚οΈ

The city filed for a restraining order, claiming the researcher was working in tandem with the ransomware attackers.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cyberattackers Spoof Palo Alto VPNs to Spread WikiLoader Variant πŸ•΅οΈβ€β™‚οΈ

The malware, first discovered two years ago, has returned in campaigns using SEO poisoning.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity