πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Hiring Kit: Computer Forensic Analyst 🦿

The increasing emphasis on securing sensitive data by regulatory agencies and governments worldwide has opened job opportunities beyond criminal justice for capable individuals with proficient technical skills, inquisitive analytical mindsets, and the tenacious drive to solve seemingly intractable problems. This customizable hiring kit, written by Mark W. Kaelin for TechRepublic Premium, provides a framework you ...

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ THN Cybersecurity Recap: Top Threats, Tools and News (Oct 21 - Oct 27) πŸ–‹οΈ

Cybersecurity news can sometimes feel like a neverending horror movie, can't it? Just when you think the villains are locked up, a new threat emerges from the shadows. This week is no exception, with tales of exploited flaws, international espionage, and AI shenanigans that could make your head spin. But don't worry, we're here to break it all down in plain English and arm you with the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cybercriminals Use Webflow to Deceive Users into Sharing Sensitive Login Credentials πŸ–‹οΈ

Cybersecurity researchers have warned of a spike in phishing pages created using a website builder tool called Webflow, as threat actors continue to abuse legitimate services like Cloudflare and Microsoft Sway to their advantage. "The campaigns target sensitive information from different crypto wallets, including Coinbase, MetaMask, Phantom, Trezor, and Bitbuy, as well as login credentials for.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Sailing the Seven Seas Securely from Port to Port – OT Access Security for Ships and Cranes πŸ–‹οΈ

Operational Technology OT security has affected marine vessel and port operators, since both ships and industrial cranes are being digitalized and automated at a rapid pace, ushering in new types of security challenges. Ships come to shore every six months on average. Container cranes are mostly automated. Diagnostics, maintenance, upgrade and adjustments to these critical systems are done.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Researchers Discover Over 70 Zero-Day Bugs at Pwn2Own Ireland πŸ“”

Trend Micros Zero Day Initiative hands out over 1m in awards for Pwn2Own competitors, who found more than 70 zeroday flaws.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI-Powered BEC Scams Zero in on Manufacturers πŸ“”

Vipre research reveals that 10 of emails targeting the manufacturing sector are BEC attempts.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Put End-of-Life Software to Rest πŸ•΅οΈβ€β™‚οΈ

Relying on EOL software leaves critical systems exposed making it a problem no business can afford to ignore.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
πŸ“’ The National Public Data breach exposed 270 million users – now the company has filed for bankruptcy πŸ“’

National Public Datas decline after a devastating cyber attack took roughly six months, as it failed to stay afloat amid mounting recovery costs.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ National Public Data breach: Lawsuit claims failed to protect billions of personal records πŸ“’

A breach at background check company National Public Data allegedly left billions of sensitive personal records exposed on the dark web.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Hackers Use CloudScout Toolset to Steal Session Cookies from Cloud Services πŸ–‹οΈ

A government entity and a religious organization in Taiwan were the target of a Chinalinked threat actor known as Evasive Panda that infected them with a previously undocumented postcompromise toolset codenamed CloudScout. "The CloudScout toolset is capable of retrieving data from various cloud services by leveraging stolen web session cookies," ESET security researcher Anh Ho said. "Through.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ THN Cybersecurity Recap: Top Threats, Tools and News (Oct 21 - Oct 27) πŸ–‹οΈ

Cybersecurity news can sometimes feel like a neverending horror movie, can't it? Just when you think the villains are locked up, a new threat emerges from the shadows. This week is no exception, with tales of exploited flaws, international espionage, and AI shenanigans that could make your head spin. But don't worry, we're here to break it all down in plain English and arm you with the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian Espionage Group Targets Ukrainian Military with Malware via Telegram πŸ–‹οΈ

A suspected Russian hybrid espionage and influence operation has been observed delivering a mix of Windows and Android malware to target the Ukrainian military under the Telegram persona Civil Defense. Google's Threat Analysis Group TAG and Mandiant are tracking the activity under the name UNC5812. The threat group, which operates a Telegram channel named civildefensecomua, was created on.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers πŸ–‹οΈ

Three malicious packages published to the npm registry in September 2024 have been found to contain a known malware called BeaverTail, a JavaScript downloader and information stealer linked to an ongoing North Korean campaign tracked as Contagious Interview. The Datadog Security Research team is monitoring the activity under the name Tenacious Pungsan, which is also known by the monikers.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Evasive Panda’s CloudScout Toolset Targets Taiwan πŸ“”

Evasive Pandas CloudScout uses MgBot to steal session cookies, infiltrating cloud data in Taiwan.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” New Type of Job Scam Targets Financially Vulnerable Populations πŸ“”

The surge in job scams targets vulnerable individuals, mirroring pig butchering fraud tactics.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Russian Malware Campaign Targets Ukrainian Recruits Via Telegram πŸ“”

Google researchers have observed Russian threat actor UNC5812 using a malware campaign via Telegram to access the devices of Ukrainian military recruits.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ¦… U.S. Agencies Investigate China-Linked Telecom Hacks Targeting High-Profile Politicians πŸ¦…

The FBI and the Cybersecurity and Infrastructure Security Agency CISA have launched an investigation into a series of cyber intrusions linked to hackers believed to be affiliated with the Chinese statelinked threat actors.  This investigation follows reports that the phone communications of prominent U.S. political figures, including former President Donald Trump, Vice President Kamala Harris campaign team, and vicepresidential candidate JD Vance, have been targeted in a sweeping cyberespionage effort. Allegations of Unauthorized Access by Chinese State Linked Threat Actors The FBI and CISA issued a statement confirming their investigation into unauthorized access to commercial telecommunications infrastructure perpetrated by actors associated with the Peoples Republic of Ch...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… New Vulnerabilities Identified in Philips Smart Lighting and Matrix Door Controller πŸ¦…

Overview The Indian Computer Emergency Response Team CERTIn has issued two critical vulnerability advisories related to Philips Smart Lighting products and the Matrix Door Controller. Both vulnerabilities are classified as high severity, signaling significant risks for users that cannot be ignored. If left unaddressed, these vulnerabilities could lead to serious repercussions, including unauthorized access to sensitive information and potential data breaches. The implications of these vulnerabilities extend beyond mere inconvenience they threaten the security and integrity of users' home networks and connected devices. Affected users must take immediate action to protect their systems and ensure they are not exposed to potential exploitation. By staying informed and implementi...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Sophos-SecureWorks Deal Focuses on Building Advanced MDR, XDR Platform πŸ•΅οΈβ€β™‚οΈ

Sophos CEO Joe Levy says 859 million deal to acquire SecureWorks from majority owner Dell Technologies will put the Taegis platform with network detection and response, vulnerability detection and response, and identity threat detection and response capabilities at the core.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Windows 'Downdate' Attack Reverts Patched PCs to a Vulnerable State πŸ•΅οΈβ€β™‚οΈ

Windows 11 machines remain open to downgrade attacks, where attackers can abuse the Windows Update process to revive a patched driver signature enforcement DSE bypass.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ China's Elite Cyber Corps Hone Skills on Virtual Battlefields πŸ•΅οΈβ€β™‚οΈ

The nation leads in the number of capturetheflag tournaments sponsored by government and industry  a strategy from which Western nations could learn.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity