πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🧠 Skills shortage directly tied to financial loss in data breaches 🧠

The cybersecurity skills gap continues to widen, with serious consequences for organizations worldwide. According to IBMs 2024 Cost Of A Data Breach Report, more than half of breached organizations now face severe security staffing shortages, a whopping 26.2 increase from the previous year. And thats expensive. This skills deficit adds an average of 1.76 million in The post Skills shortage directly tied to financial loss in data breaches appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers πŸ–‹οΈ

Over 1,500 Android devices have been infected by a new strain of Android banking malware called ToxicPanda that allows threat actors to conduct fraudulent banking transactions. "ToxicPanda's main goal is to initiate money transfers from compromised devices via account takeover ATO using a wellknown technique called ondevice fraud ODF," Cleafy researchers Michele Roviello, Alessandro Strino.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Leveraging Wazuh for Zero Trust security πŸ–‹οΈ

Zero Trust security changes how organizations handle security by doing away with implicit trust while continuously analyzing and validating access requests. Contrary to perimeterbased security, users within an environment are not automatically trusted upon gaining access. Zero Trust security encourages continuous monitoring of every device and user, which ensures sustained protection after.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” ToxicPanda Malware Targets Banking Apps on Android Devices πŸ“”

ToxicPanda malware targets banking apps on Android, spreading through Italy, Portugal and Spain.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Voters Urged to Use Official Sources for Election Information πŸ“”

A joint US government advisory warned about increasing foreign influence efforts designed to undermine the legitimacy of the Presidential Election.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Pakistani Hackers Targeted High-Profile Indian Entities using Custom RAT πŸ“”

APT36 evolved its remote access trojan, ElizaRAT, along with introducing a new stealer payload called ApoloStealer.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Oasis Fans Losing Up to Β£1000 Each to Ticket Scammers πŸ“”

Lloyds Bank has revealed that Oasis fans comprise the vast majority of ticket scam victims it deals with.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Cybersecurity and Influence Operations Threaten Integrity of U.S. Elections, Warns FBI, CISA, and ODNI πŸ¦…

As the U.S. Elections nears, Russia and Iran intensify influence operations, spreading disinformation to undermine trust in the election process, particularly in swing states.

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Critical Vulnerabilities in PTZ Cameras: CISA Adds New Exploits to Its Catalog πŸ¦…

CISA added two critical vulnerabilities CVE20248956 CVE20248957 in PTZ cameras to its KEV Catalog, exposing systems to OS command injections and authentication bypass.

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1πŸ‘1
β™ŸοΈ Canadian Man Arrested in Snowflake Data Extortions β™ŸοΈ

A 26yearold man in Ontario, Canada has been arrested for allegedly stealing data from and extorting more than 160 companies that used the cloud data service Snowflake. On October 30, Canadian authorities arrested Alexander Moucka, a.k.a. Connor Riley Moucka of Kitchener, Ontario, on a provisional arrest warrant from the United States. Bloomberg first reported Moucka's alleged ties to the Snowflake hacks on Monday. At the end of 2023, malicious hackers learned that many large companies had uploaded huge volumes of sensitive customer data to Snowflake accounts that were protected with little more than a username and password no multifactor authentication required. After scouring darknet markets for stolen Snowflake account credentials, the hackers began raiding the data storage reposito...

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions πŸ–‹οΈ

The U.S. Federal Bureau of Investigation FBI has sought assistance from the public in connection with an investigation involving the breach of edge devices and computer networks belonging to companies and government entities. "An Advanced Persistent Threat group allegedly created and deployed malware CVE202012271 as part of a widespread series of indiscriminate computer intrusions designed.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” ClickFix Exploits Users with Fake Errors and Malicious Code πŸ“”

ClickFix exploits fake error messages across multiple platforms, such as Google Meet and Zoom.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Canadian Authorities Arrest Attacker Who Stole Snowflake Data πŸ•΅οΈβ€β™‚οΈ

The suspect, tracked as UNC5537, allegedly bragged about hacking several Snowflake victims on Telegram, drawing attention to himself.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Attacker Hides Malicious Activity in Emulated Linux Environment πŸ•΅οΈβ€β™‚οΈ

The CRONTRAP campaign involves a novel technique for executing malicious commands on a compromised system.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Android Botnet 'ToxicPanda' Bashes Banks Across Europe, Latin America πŸ•΅οΈβ€β™‚οΈ

Chinesespeaking adversaries are using a fresh Android banking Trojan to take over devices and initiate fraudulent money transfers from financial institutions across Latin America, Italy, Portugal, and Spain.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Schneider Electric Clawed by 'Hellcat' Ransomware Gang πŸ•΅οΈβ€β™‚οΈ

The cybercriminal group holding the stolen information is demanding the vendor admit to the breach and pay up.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 How to Become a Chief Information Officer: CIO Cheat Sheet 🦿

If you want to pursue a path toward becoming a CIO, here's your guide to salaries, job markets, skills and common interview questions.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 HR Manager 🌊

The post HR Manager appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ South Korea Fines Meta $15.67M for Illegally Sharing Sensitive User Data with Advertisers πŸ–‹οΈ

Meta has been fined 21.62 billion won 15.67 million by South Korea's data privacy watchdog for illegally collecting sensitive personal information from Facebook users, including data about their political views and sexual orientation, and sharing it with advertisers without their consent. The country's Personal Information Protection Commission PIPC said Meta gathered information such as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users πŸ–‹οΈ

Google's cloud division has announced that it will enforce mandatory multifactor authentication MFA for all users by the end of 2025 as part of its efforts to improve account security. "We will be implementing mandatory MFA for Google Cloud in a phased approach that will roll out to all users worldwide during 2025," Mayank Upadhyay, vice president of engineering and distinguished engineer at.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘½ Singtel Hack Highlights Rising Threat of Chinese Cyber Attacks on Global Telecoms πŸ‘½

In a stark warning for global telecommunications infrastructure, Singtel, Singapores largest mobile carrier, was reportedly targeted by Chinese statesponsored hackers this past summer. The breach, which involved a group known as Volt Typhoon, was detected in June and aligns with a broader pattern of Chinese attacks on telecommunications and critical.

πŸ“– Read more.

πŸ”— Via "BE3SEC"

----------
πŸ‘οΈ Seen on @cibsecurity