πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🧠 Are attackers already embedded in U.S. critical infrastructure networks? 🧠

The threat of cyberattacks against critical infrastructure in the United States has evolved beyond data theft and espionage. Intruders are already entrenched in the nations most vital systems, waiting to unleash attacks. For instance, CISA has raised alarms about Volt Typhoon, a statesponsored hacking group that has infiltrated critical infrastructure networks. Their goal? To establish The post Are attackers already embedded in U.S. critical infrastructure networks? appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Mirai Variant Murdoc_Botnet Exploits AVTECH IP Cameras and Huawei Routers πŸ–‹οΈ

Cybersecurity researchers have warned of a new largescale campaign that exploits security flaws in AVTECH IP cameras and Huawei HG532 routers to rope the devices into a Mirai botnet variant dubbed MurdocBotnet. The ongoing activity "demonstrates enhanced capabilities, exploiting vulnerabilities to compromise devices and establish expansive botnet networks," Qualys security researcher Shilpesh.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacks πŸ–‹οΈ

A global network of about 13,000 hijacked Mikrotik routers has been employed as a botnet to propagate malware via spam campaigns, the latest addition to a list of botnets powered by MikroTik devices. The activity "takes advantage of misconfigured DNS records to pass email protection techniques," Infoblox security researcher David Brunsdon said in a technical report published last week. "This.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” GDPR Fines Total €1.2bn in 2024 πŸ“”

Data from DLA Piper showed a 33 yearonyear fall in GDPR fines issued in Europe in 2024, with total penalties reaching 1.2bn.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Oracle To Address 320 Vulnerabilities in January Patch Update πŸ“”

Critical flaws include those in Oracle Supply Chain products.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Why CISOs Must Think Clearly Amid Regulatory Chaos πŸ•΅οΈβ€β™‚οΈ

Even as the rule book changes, the profession of the CISO remains unchanged protecting their organization in a world of constant, continually evolving threats.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Phishing Risks Rise as Zendesk Subdomains Facilitate Attacks πŸ“”

A CloudSEK report revealed Zendesk's platform can be exploited for phishing and investment scams.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK’s New Digital IDs Raise Security and Privacy Fears πŸ“”

Security experts have outlined security and privacy concerns around the UK governments GOV.UK Wallet, which will allow citizens to store all their ID documents in a single place.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Trump Fires Cyber Safety Board Investigating Salt Typhoon Hackers πŸ•΅οΈβ€β™‚οΈ

In a letter sent today, the acting DHS secretary terminated membership to all advisory boards, including the Cyber Safety Review Board CSRB tasked with investigating statesponsored cyber threats against the US.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Email Bombing, 'Vishing' Tactics Abound in Microsoft 365 Attacks πŸ•΅οΈβ€β™‚οΈ

Sophos noted more than 15 attacks have been reported during the past three months.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ DONOT Group Deploys Malicious Android Apps in India πŸ•΅οΈβ€β™‚οΈ

The advanced persistent threat APT group is likely Indiabased and targeting individuals with connections to the country's intelligence community.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ HPE Investigates After Alleged Data Breach πŸ•΅οΈβ€β™‚οΈ

The company reports that it is not experiencing any operational issues within its business, so far.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Mirai Botnet Spinoffs Unleash Global Wave of DDoS Attacks πŸ•΅οΈβ€β™‚οΈ

Two separate campaigns are targeting flaws in various IoT devices globally, with the goal of compromising them and propagating malware worldwide.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 β€˜Sneaky Log’ Microsoft Spoofing Scheme Sidesteps Two-Factor Security 🦿

The phishingasaservice kit from Sneaky Log creates fake authentication pages to farm account information, including twofactor security codes.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 Why maintaining data cleanliness is essential to cybersecurity 🧠

Data, in all its shapes and forms, is one of the most critical assets a business possesses. Not only does it provide organizations with critical information regarding their systems and processes, but it also fuels growth and enables better decisionmaking on all levels. However, like any other piece of company equipment, data can degrade over The post Why maintaining data cleanliness is essential to cybersecurity appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New Mirai Malware Variant Targets AVTECH Cameras, Huawei Routers πŸ“”

MurdocBotnet used Mirai malware to exploit IoT vulnerabilities, targeting devices globally.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13,000+ IoT Device πŸ–‹οΈ

Web infrastructure and security company Cloudflare on Tuesday said it detected and blocked a 5.6 Terabit per second Tbps distributed denialofservice DDoS attack, the largest ever attack to be reported to date. The UDP protocolbased attack took place on October 29, 2024, targeting one of its customers, an unnamed internet service provider ISP from Eastern Asia. The activity originated.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Mandatory MFA, Biometrics Make Headway in Middle East, Africa πŸ•΅οΈβ€β™‚οΈ

Despite lagging in technology adoption, African and Middle Eastern organizations are catching up, driven by smartphone acceptance and national identity systems.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack πŸ–‹οΈ

A previously undocumented Chinaaligned advanced persistent threat APT group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network VPN provider in 2023, according to new findings from ESET. "The attackers replaced the legitimate installer with one that also deployed the group's signature implant that we have named SlowStepper a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Oracle Releases January 2025 Patch to Address 318 Flaws Across Major Products πŸ–‹οΈ

Oracle is urging customers to apply its January 2025 Critical Patch Update CPU to address 318 new security vulnerabilities spanning its products and services. The most severe of the flaws is a bug in the Oracle Agile Product Lifecycle Management PLM Framework CVE202521556, CVSS score 9.9 that could allow an attacker to seize control of susceptible instances. "Easily exploitable.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Cyble Finds Thousands of Security Vendor Credentials on Dark Web πŸ¦…

Overview Account credentials from some of the largest cybersecurity vendors can be found on the dark web, a result of the growing problem of infostealers, according to an analysis of Cyble threat intelligence data. The credentials available for as little as 10 in cybercrime marketplaces span internal accounts and customer access across web and cloud environments, including internal security company enterprise and development environments that could pose substantial risks. The accounts ideally would have been protected by multifactor authentication MFA, which would have made any attack more difficult. However, the leaked credentials underscore the importance of dark web monitoring as an early warning system for keeping such leaks from becoming much bigger cyberattacks. Leak...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity