πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” RansomHub Overtakes LockBit as Most Prolific Ransomware Group πŸ“”

Symantec data reveals RansomHub claimed more attacks than any other group in Q3 2024.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Two-thirds of Attributable Malware Linked to Nation States πŸ“”

Netskope claims 66 of malware attacks last year were backed by nation states.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Is a CPO Still a CPO? The Evolving Role of Privacy Leadership πŸ•΅οΈβ€β™‚οΈ

Has the role of chief privacy officer become something more than it was? And is it still a role that just one person can handle?.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1πŸ‘1
🦿 NIS 2 Compliance Deadline Arrives: What You Need to Know 🦿

The NIS 2 compliance deadline is Oct. 17. Discover essential insights on requirements, impacts, and what organisations must do now.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Fortify your future with HPE ProLiant Servers powered by Intel πŸ“’

Enhance your security and manage your servers more effectively.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ 4 Ways to Address Zero-Days in AI/ML Security πŸ•΅οΈβ€β™‚οΈ

As the unique challenges of AI zerodays emerge, the approach to managing the accompanying risks needs to follow traditional security best practices but be adapted for AI.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Anonymous Sudan Unmasked as Leaders Face Life in Prison πŸ•΅οΈβ€β™‚οΈ

US officials disrupted the group's DDoS operation and arrested two individuals behind it, who turned out to be far less intimidating than they were made out to be in the media.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Number of Active Ransomware Groups Highest on Record, Cyberint’s Report Finds 🦿

This indicates that the most prominent ransomware groups are succumbing to law enforcement takedowns, according to researchers from Cyberint.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Sudanese Brothers Arrested in β€˜AnonSudan’ Takedown β™ŸοΈ

The U.S. government on Wednesday announced the arrest and charging of two Sudanese brothers accused of running Anonymous Sudan a.k.a. AnonSudan, a cybercrime business known for launching powerful distributed denialofservice DDoS attacks against a range of targets, including dozens of hospitals, news websites and cloud providers. One of the brothers is facing life in prison for allegedly seeking to kill people with his attacks.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 The cybersecurity skills gap contributed to a $1.76 million increase in average breach costs 🧠

Understaffing in cybersecurity the skills gap is driving up the cost of data breaches in recent years, according to a decade of reports by IBM. The 2024 IBM Data Breach Report found that more than half of breached organizations experienced severe security staffing shortages, a 26.2 increase from the previous year. They found The post The cybersecurity skills gap contributed to a 1.76 million increase in average breach costs appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant πŸ–‹οΈ

The Russian threat actor known as RomCom has been linked to a new wave of cyber attacks aimed at Ukrainian government agencies and unknown Polish entities since at least late 2023. The intrusions are characterized by the use of a variant of the RomCom RAT dubbed SingleCamper aka SnipBot or RomCom 5.0, said Cisco Talos, which is monitoring the activity cluster under the moniker UAT5647. "This.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Uncover Cicada3301 Ransomware Operations and Its Affiliate Program πŸ–‹οΈ

Cybersecurity researchers have gleaned additional insights into a nascent ransomwareasaservice RaaS called Cicada3301 after successfully gaining access to the group's affiliate panel on the dark web. Singaporeheadquartered GroupIB said it contacted the threat actor behind the Cicada3301 persona on the RAMP cybercrime forum via the Tox messaging service after the latter put out an.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 5 Ways to Reduce SaaS Security Risks πŸ–‹οΈ

As technology adoption has shifted to be employeeled, just in time, and from any location or device, IT and security teams have found themselves contending with an eversprawling SaaS attack surface, much of which is often unknown or unmanaged. This greatly increases the risk of identitybased threats, and according to a recent report from CrowdStrike, 80 of breaches today use compromised.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SideWinder APT Strikes Middle East and Africa With Stealthy Multi-Stage Attack πŸ–‹οΈ

An advanced persistent threat APT actor with suspected ties to India has sprung forth with a flurry of attacks against highprofile entities and strategic infrastructures in the Middle East and Africa. The activity has been attributed to a group tracked as SideWinder, which is also known as APTC17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor Tiger, and TAPT04. ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cicada3301 Ransomware Targets Critical Sectors in US and UK πŸ“”

Cicada3301 ransomware has targeted critical sectors in USUK, leaking data from 30 firms in three months.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Charges Anonymous Sudan Members in DDoS Cybercrime Case πŸ“”

US authorities have charged two Sudanese linked to DDoS cybercrime group, Anonymous Sudan, which caused 10m in damages.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Iranian Hackers Target Critical Infrastructure with Brute Force Attacks πŸ“”

The ongoing campaign targets multiple critical infrastructure sectors, including healthcare, government, information technology, engineering, and energy.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” North Korea Escalates Fake IT Worker Schemes to Extort Employers πŸ“”

Secureworks said it had observed a case where a fake North Korean IT contractor exfiltrated proprietary data before issuing a ransom demand to their former employer.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… SolarWinds Releases Patches for High-Severity Vulnerabilities πŸ¦…

Overview SolarWinds has issued an important security update advisory outlining the latest vulnerability patches released for its products. This advisory provides insights into recently disclosed vulnerabilities affecting the SolarWinds range and emphasizes the need for organizations to take immediate action to protect their IT infrastructure. The advisory details various vulnerabilities and their associated risk scores, categorized by severity levels. High vulnerabilities, classified with a CVSS base score of 7.0 to 10.0, include three identified issues, specifically CVE202445714, CVE202445711, CVE202445710, and CVE202445715. These vulnerabilities carry a highrisk score and are marked with a Green TLP rating. In addition, there is one medium vulnerability, which falls within a...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… GitHub Releases Security Advisory on Critical Vulnerability in Self-Hosted Environments πŸ¦…

Overview GitHub has issued a security advisory regarding critical vulnerabilities that require immediate attention from users of the GitHub Enterprise Server GHES. This advisory highlights a specific vulnerability that could severely compromise organizations' security relying on this selfhosted version of GitHub, which is tailored for those needing to manage their infrastructure, security, and compliance. GitHub Enterprise Server is a platform that enables organizations to host their repositories while maintaining control over security protocols. However, vulnerabilities identified under the Common Vulnerabilities and Exposures CVE system and classified by the Common Vulnerability Scoring System CVSS indicate potential risks that must be addressed promptly. CVE20249487 is a ...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Internet Archive Slowly Revives After DDoS Barrage πŸ•΅οΈβ€β™‚οΈ

Days after facing a major breach, the site is still struggling to get fully back on its feet.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity