πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Eliminating AI Deepfake Threats: Is Your Identity Security AI-Proof? πŸ–‹οΈ

Artificial Intelligence AI has rapidly evolved from a futuristic concept to a potent weapon in the hands of bad actors. Today, AIbased attacks are not just theoretical threatsthey're happening across industries and outpacing traditional defense mechanisms.  The solution, however, is not futuristic. It turns out a properly designed identity security platform is able to deliver defenses.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SEC Charges 4 Companies Over Misleading SolarWinds Cyberattack Disclosures πŸ–‹οΈ

The U.S. Securities and Exchange Commission SEC has charged four current and former public companies for making "materially misleading disclosures" related to the largescale cyber attack that stemmed from the hack of SolarWinds in 2020. The SEC said the companies Avaya, Check Point, Mimecast, and Unisys are being penalized for how they handled the disclosure process in the aftermath of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” Ukraine Warns of Mass Phishing Campaign Targeting Citizens Data πŸ“”

CERTUA said the phishing campaign lures victims into downloading malware used to exfiltrate files containing sensitive personal data.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Irish Data Protection Watchdog Fines LinkedIn $336m πŸ“”

LinkedIn violated the EUs GDPR in how it processes its users personal data for behavioral purposes.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Inequity Challenges Women in Digital Trust, But Progress is Being Made πŸ“”

A new ISACA study reveals that pay inequity and a lack of female leadership are significant issues noted by women in the digital trust sector.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2πŸ‘Ž1πŸ”₯1
🧠 Addressing growing concerns about cybersecurity in manufacturing 🧠

Manufacturing has become increasingly reliant on modern technology, including industrial control systems ICS, Internet of Things IoT devices and operational technology OT. While these innovations boost productivity and streamline operations, theyve vastly expanded the cyberattack surface. According to the 2024 IBM Cost of a Data Breach report, the average total cost of a data breach in The post Addressing growing concerns about cybersecurity in manufacturing appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Living off the land attacks πŸ“’

How adversaries are using native system files against you and what you can do to block it.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ Understanding least privileges πŸ“’

Protect your company from ransomware attacks.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ•΅οΈβ€β™‚οΈ My Journey From the Air Force to Cybersecurity πŸ•΅οΈβ€β™‚οΈ

Cybersecurity is missiondriven, meaningful work that coincides with the service branches' goals to protect, defend, and create a safer world.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cybersecurity Isn't Easy When You're Trying to Be Green πŸ•΅οΈβ€β™‚οΈ

Renewable energy firms deal with a large cyberattack surface area, given the distributed nature of power generation and more pervasive connectivity.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Open Source LLM Tool Sniffs Out Python Zero-Days πŸ•΅οΈβ€β™‚οΈ

Vulnhuntr is a Python static code analyzer that uses Claude AI to find and explain complex, multistep vulnerabilities.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Enter the World of Ethical Hacking with Confidence 🦿

This 44.99 bundle gives you 92 hours of training in penetration testing, network security, and much more.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ›  Faraday 5.8.0 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated PenetrationTest Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to reuse the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ›  Adversary3 3.32 πŸ› 

Adversary3 malware vulnerability intel tool for thirdparty attackers living off malware LOM, updated with 700 malware and C2 panel vulnerabilities.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Researchers Discover Command Injection Flaw in Wi-Fi Alliance's Test Suite πŸ–‹οΈ

A security flaw impacting the WiFi Test Suite could enable unauthenticated local attackers to execute arbitrary code with elevated privileges. The CERT Coordination Center CERTCC said the vulnerability, tracked as CVE202441992, said the susceptible code from the WiFi Alliance has been found deployed on Arcadyan FMIMG51AX000J routers. "This flaw allows an unauthenticated local attacker to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Apple Opens PCC Source Code for Researchers to Identify Bugs in Cloud AI Security πŸ–‹οΈ

Apple has publicly made available its Private Cloud Compute PCC Virtual Research Environment VRE, allowing the research community to inspect and verify the privacy and security guarantees of its offering. PCC, which Apple unveiled earlier this June, has been marketed as the "most advanced security architecture ever deployed for cloud AI compute at scale." With the new technology, the idea is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Change Healthcare Breach Affects 100 Million Americans πŸ“”

Updated figures from the HHS revealed that 100 million patients have been notified that their data was breached in the Change Healthcare ransomware attack.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Head of Talent Acquisition 🌊

The post Head of Talent Acquisition appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… HeptaX: Unauthorized RDP Connections for Cyberespionage Operations πŸ¦…

Key takeaways Cyble Research and Intelligence Labs CRIL came across an ongoing cyberattack campaign originating from malicious LNK files. The sophisticated multistage attack chain relies heavily on PowerShell and BAT scripts to streamline the download and execution of additional payloads, demonstrating the Threat Actors TA preference for scriptbased methods to evade detection by traditional security solutions. The attack involves the creation of an administrative account on the victims system and altering Remote Desktop settings to lower authentication requirements, simplifying unauthorized RDP access for the attacker. The campaign deploys an additional wellknown password recovery tool, ChromePass, which collects saved passwords from Chromiumbased browsers, increasing the ris...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1πŸ”₯1
πŸ¦… Cyble Unveils Four Groundbreaking Capabilities for Enhanced Threat Intelligence πŸ¦…

With rapid digital advancement, organizations face unprecedented challenges in safeguarding their assets and reputation. Recognizing this need, Cyble Inc. has launched four revolutionary capabilities tailored specifically for Cybersecurity for Executives. These innovations significantly advance Executive Protection and digital risk management, ensuring executives are equipped to navigate the complexities of modern threats. From safeguarding executive travels to countering deepfake threats and providing realtime Azure Security Monitoring, these capabilities highlight Cybles unwavering commitment to comprehensive security. Heres a closer look at each innovation and the unique benefits they bring to todays threat landscape.  Physical Threat Intelligence for Executive Travel Ensuring Sa...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… CISA Warns of Critical Vulnerabilities: CVE-2024-20481 and CVE-2024-37383 Require Immediate Attention πŸ¦…

Overview The Cybersecurity and Infrastructure Security Agency CISA has issued urgent advisories regarding two vulnerabilities that pose substantial risks to organizations CVE202420481, a denialofservice DoS vulnerability affecting Cisco Adaptive Security Appliance ASA and Firepower Threat Defense FTD, and CVE202437383, a crosssite scripting XSS vulnerability in RoundCube Webmail. Both vulnerabilities highlight the necessity for immediate action to safeguard against potential exploitation. The relevant CVE IDs for these vulnerabilities are CVE202437383 and CVE202420481. The first vulnerability, CVE202437383, affects Roundcube Webmail versions prior to 1.5.7 and 1.6.x before 1.6.7, while CVE202420481 impacts Cisco products running a vulnerable release of Cisco ASA or FTD Software wi...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity