🛡 Cybersecurity & Privacy 🛡 - News
25K subscribers
88.4K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕵️‍♂️ Amateurish 'CosmicBeetle' Ransomware Stings SMBs in Turkey 🕵️‍♂️

With an immature codebase and a "rather chaotic encryption scheme" prone to failure, the group targets small businesses with custom malware.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Dark Reading Expands Its Coverage to the Asia-Pacific Region 🕵️‍♂️

The latest step in a journey to serve cybersecurity professionals in other regions of the world.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🖋️ WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers 🖋️

WordPress.org has announced a new account security measure that will require accounts with capabilities to update plugins and themes to activate twofactor authentication 2FA mandatorily. The enforcement is expected to come into effect starting October 1, 2024. "Accounts with commit access can push updates and changes to plugins and themes used by millions of WordPress sites worldwide," the.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
👎1
📔 Open Source Updates Have 75% Chance of Breaking Apps 📔

Endor Labs claims security patches can break underlying open source software 75 of the time.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
👍1
📔 Business Email Compromise Costs $55bn Over a Decade 📔

New FBI data reveals BEC scams have cost businesses more than 55bn since 2013.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Hackers Proxyjack & Cryptomine Selenium Grid Servers 🕵️‍♂️

A vendor honeypot caught two attacks intended to leverage the tens of thousands of exposed Selenium Grid Web app testing servers.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🦿 The 6 Best Penetration Testing Companies for 2024 🦿

Discover the top six penetration testing companies for businesses of all sizes. Learn the pros and cons of pentesting providers like Astra, BreachLock, and Acunetix.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🖋️ Top 3 Threat Report Insights for Q2 2024 🖋️

Cato CTRL Cyber Threats Research Lab has released its Q2 2024 Cato CTRL SASE Threat Report. The report highlights critical findings based on the analysis of a staggering 1.38 trillion network flows from more than 2,500 of Catos global customers, between April and June 2024. Key Insights from the Q2 2024 Cato CTRL SASE Threat Report The report is packed with unique insights that are based on.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware Attack 🖋️

Iraqi government networks have emerged as the target of an "elaborate" cyber attack campaign orchestrated by an Iran statesponsored threat actor called OilRig. The attacks singled out Iraqi organizations such as the Prime Minister's Office and the Ministry of Foreign Affairs, cybersecurity company Check Point said in a new analysis. OilRig, also called APT34, Crambus, Cobalt Gypsy, GreenBug,.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Ireland's Watchdog Launches Inquiry into Google's AI Data Practices in Europe 🖋️

The Irish Data Protection Commission DPC has announced that it has commenced a "CrossBorder statutory inquiry" into Google's foundational artificial intelligence AI model to determine whether the tech giant has adhered to data protection regulations in the region when processing the personal data of European users. "The statutory inquiry concerns the question of whether Google has complied.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📔 UK Recognizes Data Centers as Critical National Infrastructure 📔

The UK government has classified data centers as critical infrastructure in a move to protect UK data from cyberattacks and prevent major IT blackouts.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📢 The Iran cyber threat: Breaking down attack tactics 📢

Iran has been implicated in multiple recent cyber attacks as statebacked hackers evolve their tactics, businesses must respond by shoring up defenses.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
1
🕵️‍♂️ Rising Tide of Software Supply Chain Attacks: An Urgent Problem 🕵️‍♂️

Understanding a threat is just as important as the steps taken toward prevention.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🦿 How Business Owners Can Evolve with a Changing Technological Landscape 🦿

Check out these five course bundles breaking down the most important IT, development, and cybersecurity skills that a business owner can master.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🧠 How I got started: AI security executive 🧠

Artificial intelligence and machine learning are becoming increasingly crucial to cybersecurity systems. Organizations need professionals with a strong background that mixes AIML knowledge with cybersecurity skills, bringing on board people like Nicole Carignan, Vice President of Strategic Cyber AI at Darktrace, who has a unique blend of technical and soft skills. Carignan was originally a The post How I got started AI security executive appeared first on Security Intelligence.

📖 Read more.

🔗 Via "Security Intelligence"

----------
👁️ Seen on @cibsecurity
📔 TfL Confirms Customer Data Breach, 17-Year-Old Suspect Arrested 📔

TfL has revealed that some customer data was accessed in a recent cyberattack, potentially including the bank details of 5000 people.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Mastercard Acquires Global Threat Intelligence Firm Recorded Future for $2.65bn 📔

Mastercard aims to strengthen its cybersecurity capabilities by acquiring Recorded Future, a leading provider of threat intelligence.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Lazarus Group Targets Developers in Fresh VMConnect Campaign 📔

Lazarus Group has been observed impersonating Capital One staff to lure developers into downloading malware on open source repositories.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🖋️ Beware: New Vo1d Malware Infects 1.3 Million Android TV Boxes Worldwide 🖋️

Nearly 1.3 million Androidbased TV boxes running outdated versions of the operating system and belonging to users spanning 197 countries have been infected by a new malware dubbed Vo1d aka Void. "It is a backdoor that puts its components in the system storage area and, when commanded by attackers, is capable of secretly downloading and installing thirdparty software," Russian antivirus.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Exposed Selenium Grid Servers Targeted for Crypto Mining and Proxyjacking 🖋️

Internetexposed Selenium Grid instances are being targeted by bad actors for illicit cryptocurrency mining and proxyjacking campaigns. "Selenium Grid is a server that facilitates running test cases in parallel across different browsers and versions," Cado Security researchers Tara Gould and Nate Bill said in an analysis published today. "However, Selenium Grid's default configuration lacks.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📢 TfL reveals bank data on 5,000 customers exposed in cyber attack, arrest made following the incident 📢

The TfL cyber incident has taken a turn for the worse, with the travel operator revealing some customer details may have been compromised.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity