πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Three Reasons Why the Browser is Best for Stopping Phishing Attacks πŸ–‹οΈ

Phishing attacks remain a huge challenge for organizations in 2025. In fact, with attackers increasingly leveraging identitybased techniques over software exploits, phishing arguably poses a bigger threat than ever before.  Attackers are increasingly leveraging identitybased techniques over software exploits, with phishing and stolen credentials a byproduct of phishing now the primary.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp πŸ–‹οΈ

Multiple suspected Russialinked threat actors are "aggressively" targeting individuals and organizations with ties to Ukraine and human rights with an aim to gain unauthorized access to Microsoft 365 accounts since early March 2025. The highly targeted social engineering operations, per Volexity, are a shift from previously documented attacks that leveraged a technique known as device code.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
😱1
πŸ–‹οΈ Ripple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack πŸ–‹οΈ

The Ripple cryptocurrency npm JavaScript library named xrpl.js has been compromised by unknown threat actors as part of a software supply chain attack designed to harvest and exfiltrate users' private keys. The malicious activity has been found to affect five different versions of the package 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2. The issue has been addressed in versions 4.2.5 and 2.14.3.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Drops Cookie Prompt in Chrome, Adds IP Protection to Incognito πŸ–‹οΈ

Google on Tuesday revealed that it will no longer offer a standalone prompt for thirdparty cookies in its Chrome browser as part of its Privacy Sandbox initiative. "We've made the decision to maintain our current approach to offering users thirdparty cookie choice in Chrome, and will not be rolling out a new standalone prompt for thirdparty cookies," Anthony Chavez, vice president of Privacy.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“” Verizon's DBIR Reveals 34% Jump in Vulnerability Exploitation πŸ“”

After a 180 rise in last years report, the exploitation of vulnerabilities continues to grow, now accounting for 20 of all breaches.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” FBI Reveals β€œStaggering” $16.6bn Lost to Cybercrime in 2024 πŸ“”

The FBI found that cybercrime losses climbed by 33 compared to 2023, driven by tactics like investment fraud and BEC.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Vulnerability Exploitation and Credential Theft Now Top Initial Access Vectors πŸ“”

Mandiants MTrends report found that credential theft rose significantly in 2024, driven by the growing use of infostealers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Data Breach Victim Count Surges 26% Annually πŸ“”

The latest ITRC data finds breach volumes remained flat in Q1 but victim numbers increased 26 annually.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” M&S Grapples with Cyber Incident Affecting In-Store Services πŸ“”

Marks and Spencer has confirmed that it has been managing a cyber incident for the past few days which affected its contactless payments and click and collect services.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Dutch Warn of β€œWhole of Society” Russian Cyber-Threat πŸ“”

Dutch intelligence report warns of growing Russian aggression with hybrid warfare.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Romance Scams Spike 20% as Online Dating Grows πŸ“”

Barclays found that romance scam victims lost 8000 on average in 2024, a significant increase from the previous year.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Industrial-Scale' Asian Scam Centers Expand Globally πŸ•΅οΈβ€β™‚οΈ

The convergence of cybercrime, financial fraud, and organized crime poses a significant threat, especially where these syndicates excel at operating under the radar.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
πŸ–‹οΈ WhatsApp Adds Advanced Chat Privacy to Blocks Chat Exports and Auto-Downloads πŸ–‹οΈ

WhatsApp has introduced an extra layer of privacy called Advanced Chat Privacy that allows users to block participants from sharing the contents of a conversation in traditional chats and groups. "This new setting available in both chats and groups helps prevent others from taking content outside of WhatsApp for when you may want extra privacy," WhatsApp said in a statement. The optional feature.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2πŸ€”1
πŸ“’ Hackers are using Zoom’s remote control feature to infect devices with malware πŸ“’

Security experts have issued an alert over a new social engineering campaign using Zooms remote control features to take over victim devices.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🦿 Google Chrome Keeps Third-Party Cookies Settings, Lets Users β€˜Make an Informed Choice’ 🦿

Privacy Sandbox, originally pitched as an alternative to crosssite ad tracking, will not show a standalone prompt. Instead, Chrome is readying a different informed choice.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ–‹οΈ Automating Zero Trust in Healthcare: From Risk Scoring to Dynamic Policy Enforcement Without Network Redesign πŸ–‹οΈ

The Evolving Healthcare Cybersecurity Landscape  Healthcare organizations face unprecedented cybersecurity challenges in 2025. With operational technology OT environments increasingly targeted and the convergence of IT and medical systems creating an expanded attack surface, traditional security approaches are proving inadequate. According to recent statistics, the healthcare sector.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
πŸ–‹οΈ Critical Commvault Command Center Flaw Enables Attackers to Execute Code Remotely πŸ–‹οΈ

A critical security flaw has been disclosed in the Commvault Command Center that could allow arbitrary code execution on affected installations. The vulnerability, tracked as CVE202534028, carries a CVSS score of 9.0 out of a maximum of 10.0. "A critical security vulnerability has been identified in the Command Center installation, allowing remote attackers to execute arbitrary code without.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” Verizon DBIR: Small Businesses Bearing the Brunt of Ransomware Attacks πŸ“”

While the Verizon annual report showed that ransomware is rising, it also found that ransom payments are in decline.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” Ransomware Attacks Fall Sharply in March πŸ“”

NCC Group found that ransomware attacks fell by 32 in March compared to February, but described this finding as a red herring.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” ETSI Unveils New Baseline Requirements for Securing AI πŸ“”

ETSIs says new technical specification for securing AI models and systems sets international benchmark.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” Ofcom Lays Down the Law with Child Safety Rules for Tech Giants πŸ“”

Ofcoms Protection of Children Codes and Guidance lists 40 new child safety measures for tech firms.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘Ž1