πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Cross-Domain Attacks: A Growing Threat to Modern Security and How to Combat Them πŸ–‹οΈ

In the past year, crossdomain attacks have gained prominence as an emerging tactic among adversaries. These operations exploit weak points across multiple domains including endpoints, identity systems and cloud environments so the adversary can infiltrate organizations, move laterally and evade detection. eCrime groups like SCATTERED SPIDER and North Koreanexus adversaries such as FAMOUS.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Hackers Leak Rhode Island Citizens' Data on Dark Web πŸ“”

The State of Rhode Island has confirmed that cybercriminals have begun publishing data stolen from its social services portal, the RIBridges system.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ¦… CISA Adds CVE-2024-3393 to Vulnerabilities Catalog: Palo Alto Networks PAN-OS DNS Packet Flaw Threatens Firewalls πŸ¦…

Overview  The Cybersecurity and Infrastructure Security Agency CISA has added CVE20243393, a Palo Alto Networks PANOS Malformed DNS Packet vulnerability, to its Known Exploited Vulnerabilities KEV catalog. This vulnerability impacts the DNS Security feature of PANOS, which powers firewalls and security solutions. The vulnerability allows attackers to exploit the system through specially crafted DNS packets, leading to a denialofservice DoS condition, affecting the availability of essential firewall services.  On December 27, 2024, Palo Alto Networks reported a Denial of Service DoS vulnerability in the DNS Security feature of PANOS, specifically linked to the malformed DNS packet handling process. This issue, now documented as CVE20243393, has been added to the CISAs Known Exploit...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ•΅οΈβ€β™‚οΈ 'Bad Likert Judge' Jailbreak Bypasses Guardrails of OpenAI, Other Top LLMs πŸ•΅οΈβ€β™‚οΈ

A novel technique to stump artificial intelligence AI textbased systems increases the likelihood of a successful cyberattack by 60.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 Preparing for the future of data privacy 🧠

The focus on data privacy started to quickly shift beyond compliance in recent years and is expected to move even faster in the near future. Not surprisingly, the Thomson Reuters Risk Compliance Survey Report found that 82 of respondents cited data and cybersecurity concerns as their organizations greatest risk. However, the majority of organizations The post Preparing for the future of data privacy appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API πŸ–‹οΈ

Details have emerged about three nowpatched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure. The flaws, discovered by Melbournebased cybersecurity company Stratus Security, have been addressed as of May 2024. Two of the three shortcomings reside in Power Platform's OData Web API Filter, while the third vulnerability is rooted in the FetchXML.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” HIPAA Rules Update Proposed to Combat Healthcare Data Breaches πŸ“”

The US government has set out proposals to increase security obligations on healthcare providers to protect patient data amid surging cyberattacks in the sector.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Ukraine Takes Steps to Strengthen its Cybersecurity Framework with Policy Advancements and Strategic Initiatives πŸ¦…

Overview  Ukraine has taken significant steps to enhance its cybersecurity posture, introducing key updates to its Organizational and Technical Model OTM of Cybersecurity and implementing new standards for safeguarding critical infrastructure facilities CIF. These developments are part of the countrys broader Cybersecurity Strategy, aligning with global best practices and addressing evolving cyber threats.  Unified Cybersecurity Framework Inspired by NIST  The Cabinet of Ministers of Ukraine has approved amendments to the OTM of Cybersecurity, adopting a unified approach based on NIST's Cybersecurity Framework 2.0. The updated framework provides state bodies and critical infrastructure operators with a structured methodology for identifying, mitigating, and recovering from cyber...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Global Campaign Targets PlugX Malware with Innovative Portal πŸ“”

Sekoias innovative PlugX malware disinfection campaign removed active threats across ten countries.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New DoubleClickjacking Attack Bypasses Protections πŸ“”

DoubleClickjacking bypasses XFrameOptions and SameSite cookies in doubleclick sequences, exposing UI authentication flaws.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Volkswagen Breach Exposes Data of 800K EV Customers πŸ•΅οΈβ€β™‚οΈ

Ethical hacking group Chaos Computer Club uncovered exposed data of electrical vehicle owners across the company's VW, Audi, Seat, and Skoda brands.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Unpatched Active Directory Flaw Can Crash Any Microsoft Server πŸ•΅οΈβ€β™‚οΈ

Windows servers are vulnerable to a dangerous LDAP vulnerability that could be used to crash multiple servers at once and should be patched immediately.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ US Soldier Arrested in Verizon, AT&T Hacks πŸ•΅οΈβ€β™‚οΈ

Wagenius posted about hacking more than 15 telecom providers on the Telegram messaging service.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 China-Linked Cyber Threat Group Hacks US Treasury Department 🦿

Threat actors entered Treasury Department systems through BeyondTrust. The breach may be related to the Salt Typhoon attacks reported throughout the year.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ₯°1
πŸ•΅οΈβ€β™‚οΈ Proposed HIPAA Amendments Will Close Healthcare Security Gaps πŸ•΅οΈβ€β™‚οΈ

The changes to the healthcare privacy regulation with technical controls such as network segmentation, multifactor authentication, and encryption. The changes would strengthen cybersecurity protections for electronic health information and address evolving threats against healthcare entities.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations πŸ–‹οΈ

Apple has agreed to pay 95 million to settle a proposed class action lawsuit that accused the iPhone maker of invading users' privacy using its voiceactivated Siri assistant. The development was first reported by Reuters. The settlement applies to U.S.based individuals current or former owners or purchasers of a Sirienabled device who had their confidential voice communications with the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🦿 TotalAV VPN vs Surfshark: Which VPN Should You Choose? 🦿

TotalAV combines a simple VPN with antivirus software, while Surfshark offers a standalone VPN with better features and faster speeds.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers πŸ–‹οΈ

A proofofconcept PoC exploit has been released for a nowpatched security flaw impacting Windows Lightweight Directory Access Protocol LDAP that could trigger a denialofservice DoS condition. The outofbounds reads vulnerability is tracked as CVE202449113 CVSS score 7.5. It was addressed by Microsoft as part of Patch Tuesday updates for December 2024, alongside CVE202449112 .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption πŸ–‹οΈ

Microsoft has announced that it's making an "unexpected change" to the way .NET installers and archives are distributed, requiring developers to update their production and DevOps infrastructure. "We expect that most users will not be directly affected, however, it is critical that you validate if you are affected and to watch for downtime or other kinds of breakage," Richard Lander, a program.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Confirms Russian GenAI Disinformation Op Targeted Election πŸ“”

The US government has sanctioned Russian stateaffiliated entity CGE, which used a vast GenAI infrastructure to spread disinformation during the US Presidential election.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 SentinelOne Pricing 2025: Core, Control, Complete, & Commercial Packages Comparison 🌊

SentinelOne is a wellknown player in the cybersecurity market offering a cuttingedge cybersecurity platform developed to safeguard endpoints, cloud environments, and workloads from various cyber threats. Using the capabilities of artificial intelligence AI and automation, the solution offers an integrated approach to endpoint security to prevent, detect, and respond to known and unknown threats.  Here The post SentinelOne Pricing 2025 Core, Control, Complete, Commercial Packages Comparison appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity