πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Cyber-Attack on Microlise Disrupts DHL and Serco Tracking Services πŸ“”

A cyberattack targeting telematics provider Microlise has disrupted tracking services for key clients like DHL and Serco.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Chinese Gamers Targeted in Winos4.0 Framework Scam πŸ•΅οΈβ€β™‚οΈ

Campaigns like Silver Fox and Void Arachne are deploying the framework, using social media and messaging platforms to lure in victims.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ•΅οΈβ€β™‚οΈ German Law Could Protect Researchers Reporting Vulns πŸ•΅οΈβ€β™‚οΈ

The draft amendment also includes prison time for those who access systems to maliciously spy or intercept data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 AI-Assisted Attacks Top Cyber Threat For Third Consecutive Quarter, Gartner Finds 🦿

AIenhanced malicious attacks are a top concern for 80 of executives, and for good reason, as there is a lot of evidence that bad actors are exploiting the technology.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Increasing Awareness of DNS Hijacking: A Growing Cyber Threat 🦿

Read more about DNS hijacking and how organizations can prevent it.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware πŸ–‹οΈ

An ongoing threat campaign dubbed VEILDrive has been observed taking advantage of legitimate services from Microsoft, including Teams, SharePoint, Quick Assist, and OneDrive, as part of its modus operandi. "Leveraging Microsoft SaaS services including Teams, SharePoint, Quick Assist, and OneDrive the attacker exploited the trusted infrastructures of previously compromised organizations to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Fake Copyright Infringement Emails Spread Rhadamanthys πŸ•΅οΈβ€β™‚οΈ

Attackers are triggering victims' deepseated fear of getting in trouble in order to spread the sophisticated stealer across continents.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Canada Orders TikTok to Shut Down Canadian Operations Over Security Concerns πŸ–‹οΈ

The Canadian government on Wednesday ordered ByteDanceowned TikTok to dissolve its operations in the country, citing national security risks, but stopped short of instituting a ban on the popular videosharing platform. "The decision was based on the information and evidence collected over the course of the review and on the advice of Canada's security and intelligence community and other.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Jane Goodall: Reasons for hope | Starmus highlights πŸš€

The trailblazing scientist shares her reasons for hope in the fight against climate change and how we can tackle seemingly impossible problems and keep going in the face of adversity.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Suspect in Snowflake hack arrested in Canada πŸ“’

Alexander 'Connor' Moucka is believed to be a prominent figure in the hacking group behind breaches at 165 companies.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems πŸ–‹οΈ

Cisco has released security updates to address a maximum severity security flaw impacting UltraReliable Wireless Backhaul URWB Access Points that could permit unauthenticated, remote attackers to run commands with elevated privileges. Tracked as CVE202420418 CVS score 10.0, the vulnerability has been described as stemming from a lack of input validation to the webbased management.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Defenders Outpace Attackers in AI Adoption πŸ“”

Trend Micros Robert McArdle says cybercriminals use of AI is far more limited than many realize, and pales in comparison to defenders' use of the technology.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Serco, DHL among firms affected by Microlise cyber attack πŸ“’

The incident affected vehicle tracking for two major customers.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ The Power of Process in Creating a Successful Security Posture πŸ•΅οΈβ€β™‚οΈ

Establishing realistic, practitionerdriven processes prevents employee burnout, standardizes experiences, and closes many of the gaps exposed by repeated oneoffs.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Symbiotic Security Launches Scanning Tool to Help Fix Flaws in Code πŸ•΅οΈβ€β™‚οΈ

The company comes out of stealth with a tool that integrates directly into the developer's IDE to find flaws, offer remediation advice, and training materials to write secure code.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 Exploring DORA: How to manage ICT incidents and minimize cyber threat risks 🧠

As cybersecurity breaches continue to rise globally, institutions handling sensitive information are particularly vulnerable. In 2024, the average cost of a data breach in the financial sector reached 6.08 million, making it the second hardest hit after healthcare, according to IBMs 2024 Cost of a Data Breach report. This underscores the need for robust IT The post Exploring DORA How to manage ICT incidents and minimize cyber threat risks appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Critical Zero-Click Vulnerability in Synology NAS Devices Needs Urgent Patching πŸ¦…

Overview A recently discovered highseverity vulnerability, tracked as CVE202410443 and dubbed "RISKSTATION," poses a significant threat to Synology NAS users worldwide. The vulnerability, affecting Synology DiskStation and BeeStation models, allows remote code execution without user interaction, heightening the potential for malicious exploitation. CERTIn has released an advisory urging Synology users to apply critical security patches immediately to secure their devices and prevent unauthorized access. Affected Systems and Risk Assessment The flaw specifically impacts Synology Photos and BeePhotos components, which come preinstalled on many Synology NAS products. Vulnerable versions include BeePhotos for BeeStation OS 1.1 versions below 1.1.010053 BeePhotos for Be...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Critical Bug in Cisco’s URWB Exposes Systems to Root Privilege Command Injection πŸ¦…

Overview Cisco has disclosed a severe vulnerability, tracked as CVE202420418, in its Unified Industrial Wireless Software for UltraReliable Wireless Backhaul URWB Access Points. The flaw, rated with a maximum CVSS score of 10.0, affects multiple Cisco Catalyst Access Point models. Attackers exploiting this vulnerability can gain rootlevel control, enabling unauthorized command execution on vulnerable devices. Vulnerability Details This critical CVE202420418 vulnerability stems from improper input validation within Cisco's webbased management interface, which controls URWB Access Points. A remote attacker without authentication can exploit this flaw by sending specially crafted HTTP requests to vulnerable devices, thereby injecting commands with root privileges on the devic...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS πŸ–‹οΈ

A threat actor with ties to the Democratic People's Republic of Korea DPRK has been observed targeting cryptocurrencyrelated businesses with a multistage malware capable of infecting Apple macOS devices. Cybersecurity company SentinelOne, which dubbed the campaign Hidden Risk, attributed it with high confidence to BlueNoroff, which has been previously linked to malware families such as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ A Hacker's Guide to Password Cracking πŸ–‹οΈ

Defending your organizations security is like fortifying a castleyou need to understand where attackers will strike and how theyll try to breach your walls. And hackers are always searching for weaknesses, whether its a lax password policy or a forgotten backdoor. To build a stronger defense, you must think like a hacker and anticipate their moves. Read on to learn more about hackers'.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 5 Most Common Malware Techniques in 2024 πŸ–‹οΈ

Tactics, techniques, and procedures TTPs form the foundation of modern defense strategies. Unlike indicators of compromise IOCs, TTPs are more stable, making them a reliable way to identify specific cyber threats. Here are some of the most commonly used techniques, according to ANY.RUN's Q3 2024 report on malware trends, complete with realworld examples. Disabling of Windows Event Logging.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity