πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems πŸ–‹οΈ

Cisco has released security updates to address a maximum severity security flaw impacting UltraReliable Wireless Backhaul URWB Access Points that could permit unauthenticated, remote attackers to run commands with elevated privileges. Tracked as CVE202420418 CVS score 10.0, the vulnerability has been described as stemming from a lack of input validation to the webbased management.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Malicious PyPI Package β€˜Fabrice’ Found Stealing AWS Keys from Thousands of Developers πŸ–‹οΈ

Cybersecurity researchers have discovered a malicious package on the Python Package Index PyPI that has racked up thousands of downloads for over three years while stealthily exfiltrating developers' Amazon Web Services AWS credentials. The package in question is "fabrice," which typosquats a popular Python library known as "fabric," which is designed to execute shell commands remotely over.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Androxgh0st Botnet Adopts Mozi Payloads, Expands IoT Reach πŸ“”

Androxgh0st botnet has expanded, integrating Mozi IoT payloads and targeting web server vulnerabilities.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ“” Interlock Ransomware Targets US Healthcare, IT and Government Sectors πŸ“”

Interlock employs both biggame hunting and double extortion tactics against its victims.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Regulator Urges Stronger Data Protection in AI Recruitment Tools πŸ“”

An ICO audit of AI recruitment tools found numerous data privacy issues that may lead to jobseekers being discriminated against and privacy compromised.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Canada Orders Shutdown of Local TikTok Branch Over Security Concerns πŸ“”

TikTok Technology Canada, Inc, the subsidiary of Chinese group ByteDance, will have to cease its operations in Canada.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCSC Publishes Tips to Tackle Malvertising Threat πŸ“”

The UKs National Cyber Security Centre has released malvertising guidance for brands and their ad partners.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Cybersecurity Wages Soar Above Inflation as Stress Levels Rise πŸ“”

CIISec report reveals the average wage for UK security professionals is now over 87,000.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Canada Closes TikTok Offices, Citing National Security πŸ•΅οΈβ€β™‚οΈ

Questions remain over what a corporate ban will achieve, since Canadians will still be able to use the app.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cisco Bug Could Lead to Command Injection Attacks πŸ•΅οΈβ€β™‚οΈ

Though Cisco reports of no known malicious exploitation attempts, three of its wireless access points are vulnerable to these attacks.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'SteelFox' Malware Blitz Infects 11K Victims With Bundle of Pain πŸ•΅οΈβ€β™‚οΈ

The malware combines a miner and data stealer, and it packs functions that make detection and mitigation a challenge.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New CRON#TRAP Malware Infects Windows by Hiding in Linux VM to Evade Antivirus πŸ–‹οΈ

Cybersecurity researchers have flagged a new malware campaign that infects Windows systems with a Linux virtual instance containing a backdoor capable of establishing remote access to the compromised hosts. The "intriguing" campaign, codenamed CRONTRAP, starts with a malicious Windows shortcut LNK file likely distributed in the form of a ZIP archive via a phishing email. "What makes the CRON.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Thursday added a nowpatched critical security flaw impacting Palo Alto Networks Expedition to its Known Exploited Vulnerabilities KEV catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE20245910 CVSS score 9.3, concerns a case of missing authentication in the Expedition migration tool that.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ ESET APT Activity Report Q2 2024–Q3 2024 πŸš€

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2024 and Q3 2024.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Top Vulnerability Management Tools: Reviews & Comparisons 2024 🦿

There are a great many vulnerability management tools available. But which is best? Here are our top picks for a variety of use cases.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse πŸ“’

The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Nokia waves off IntelBroker breach claims, says leaked source code came from a third party application πŸ“’

Notorious threat actor IntelBroker released a cache of stolen data.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Cybersecurity salaries are rising, but some professionals wonder if the stress and burnout is worth it πŸ“’

Salaries in cybersecurity have increased 7 above inflation in the last few years.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ IcePeony and Transparent Tribe Target Indian Entities with Cloud-Based Tools πŸ–‹οΈ

Highprofile entities in India have become the target of malicious campaigns orchestrated by the Pakistanbased Transparent Tribe threat actor and a previously unknown Chinanexus cyber espionage group dubbed IcePeony. The intrusions linked to Transparent Tribe involve the use of a malware called ElizaRAT and a new stealer payload dubbed ApoloStealer on specific victims of interest, Check Point.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The vCISO Academy: Transforming MSPs and MSSPs into Cybersecurity Powerhouses πŸ–‹οΈ

Weve all heard a million times growing demand for robust cybersecurity in the face of rising cyber threats is undeniable. Globally small and mediumsized businesses SMBs are increasingly targeted by cyberattacks but often lack the resources for fulltime Chief Information Security Officers CISOs. This gap is driving the rise of the virtual CISO vCISO model, offering a costeffective.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Malicious NPM Packages Target Roblox Users with Data-Stealing Malware πŸ–‹οΈ

A new campaign has targeted the npm package repository with malicious JavaScript libraries that are designed to infect Roblox users with opensource stealer malware such as Skuld and BlankGrabber. "This incident highlights the alarming ease with which threat actors can launch supply chain attacks by exploiting trust and human error within the open source ecosystem, and using readily available.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity