πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Agentic AI’s Role in the Future of AppSec 🦿

Overwhelmed AppSec teams are turning to agentic AI to handle the tedious manual work of security reporting, threat modeling, and code reviews, but successful implementation requires careful human oversight.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Leaked Black Basta Chats Suggest Russian Officials Aided Leader's Escape from Armenia πŸ–‹οΈ

The recently leaked trove of internal chat logs among members of the Black Basta ransomware operation has revealed possible connections between the ecrime gang and Russian authorities. The leak, containing over 200,000 messages from September 2023 to September 2024, was published by a Telegram user ExploitWhispers last month. According to an analysis of the messages by cybersecurity company.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Keeper Security launches revamped partner program for 2025 πŸ“’

Keeper Security has announced an update to its partner program designed to help partners expand their cybersecurity offerings and drive new revenue.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Keeper Security launches revamped partner program for 2025 πŸ“’

Keeper Security has announced an update to its partner program designed to help partners expand their cybersecurity offerings and drive new revenue.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig Miners πŸ–‹οΈ

Threat actors are exploiting a severe security flaw in PHP to deliver cryptocurrency miners and remote access trojans RATs like Quasar RAT. The vulnerability, assigned the CVE identifier CVE20244577, refers to an argument injection vulnerability in PHP affecting Windowsbased systems running in CGI mode that could allow remote attackers to run arbitrary code. Cybersecurity company.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters: Are You at Risk? 🦿

By simply sending HTTP requests, attackers can trigger the deserialisation of malicious data in Tomcat's session storage and gain control.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Windows Shortcut Flaw Exploited by 11 State-Sponsored Groups πŸ“”

Newly discovered vulnerability ZDICAN25373 takes advantage of Windows shortcuts has been exploited by 11 statesponsored groups since 2017.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🀯1
πŸ•΅οΈβ€β™‚οΈ AI Cloud Adoption Is Rife With Cyber Mistakes πŸ•΅οΈβ€β™‚οΈ

Research finds that organizations are granting root access by default and making other big missteps, including a Jengalike building concept, in deploying and configuring AI services in cloud deployments.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Critical Fortinet Vulnerability Draws Fresh Attention πŸ•΅οΈβ€β™‚οΈ

CISA this week added CVE202524472 to its catalog of known exploited vulnerabilities, citing ransomware activity targeting the authentication bypass flaw.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Nation-State Groups Abuse Microsoft Windows Shortcut Exploit πŸ•΅οΈβ€β™‚οΈ

Trend Micro uncovered a method that nationstate threat actors are using to target victims via the Windows .Ink shortcut file extension.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Infosys Settles $17.5M Class Action Lawsuit After Sprawling Third-Party Breach πŸ•΅οΈβ€β™‚οΈ

Several major companies in the finance sector were impacted by the thirdparty breach, prompting them to notify thousands of customers of their compromised data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 TechRepublic Exclusive: New Ransomware Attacks are Getting More Personal as Hackers β€˜Apply Psychological Pressure’ 🦿

Ransomware attackers know where your kids go to school and they want you to know it, according to professional negotiators at Sygnia.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Scam Alert: FBI β€˜Increasingly Seeing’ Malware Distributed In Document Converters 🦿

FBI warns computer users to keep an eye out for malware, including ransomware, distributed through working document converters.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 Cyber chiefs unveil new roadmap for post-quantum cryptography migration 🚨

New guidance from the NCSC outlines a threephase timeline for organisations to transition to quantumresistant encryption methods by 2035.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ DOGE to Fired CISA Staff: Email Us Your Personal Data β™ŸοΈ

A message posted on Monday to the homepage of the U.S. Cybersecurity Infrastructure Security Agency CISA is the latest exhibit in the Trump administration's continued disregard for basic cybersecurity protections. The message instructed recentlyfired CISA employees to get in touch so they can be rehired and then immediately placed on leave, asking employees to send their Social Security number or date of birth in a passwordprotected email attachment presumably with the password needed to view the file included in the body of the email.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ India Is Top Global Target for Hacktivists, Regional APTs πŸ•΅οΈβ€β™‚οΈ

Global politics and a growing economy draw the wrong kind of attention to India, with denialofservice and application attacks both on the rise.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Get started on post-quantum encryption, organizations warned πŸ“’

The UK's national cybersecurity agency is urging companies to begin preparing themselves for quantum threats by 2035.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Western Alliance Bank admits cyber attack exposed 22,000 customers πŸ“’

An American bank has admitted nearly 22,000 customers had their accounts compromised following an attack that targeted a zeroday flaw in a thirdparty filetransfer tool.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Hackers are turning to AI tools to reverse engineer millions of apps – and it’s causing havoc for security professionals πŸ“’

A marked surge in attacks on clientside apps could be due to the growing use of AI tools among cyber criminals, according to new research.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯2
πŸ“’ Forget MFA fatigue, attackers are exploiting β€˜click tolerance’ to trick users into infecting themselves with malware πŸ“’

Threat actors are exploiting users familiarity with verification tests to trick them into loading malware onto their systems, new research has warned.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Mobile Jailbreaks Exponentially Increase Corporate Risk πŸ•΅οΈβ€β™‚οΈ

Both Android devices and iPhones are 3.5 times more likely to be infected with malware once "broken" and 250 times more likely to be totally compromised, recent research shows.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity