πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims πŸ–‹οΈ

Cybersecurity researchers have lifted the lid on two threat actors that orchestrate investment scams through spoofed celebrity endorsements and conceal their activity through traffic distribution systems TDSes. The activity clusters have been codenamed Reckless Rabbit and Ruthless Rabbit by DNS threat intelligence firm Infoblox. The attacks have been observed to lure victims with bogus.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Third Parties and Machine Credentials: The Silent Drivers Behind 2025's Worst Breaches πŸ–‹οΈ

It wasn't ransomware headlines or zeroday exploits that stood out most in this year's Verizon 2025 Data Breach Investigations Report DBIR it was what fueled them. Quietly, yet consistently, two underlying factors played a role in some of the worst breaches thirdparty exposure and machine credential abuse. According to the 2025 DBIR, thirdparty involvement in breaches doubled.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Warns Default Helm Charts Could Leave Kubernetes Apps Exposed to Data Leaks πŸ–‹οΈ

Microsoft has warned that using premade templates, such as outofthebox Helm charts, during Kubernetes deployments could open the door to misconfigurations and leak valuable data. "While these 'plugandplay' options greatly simplify the setup process, they often prioritize ease of use over security," Michael Katchinskiy and Yossi Weizman from the Microsoft Defender for Cloud Research team.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
😱1
πŸ–‹οΈ Entra ID Data Protection: Essential or Overkill? πŸ–‹οΈ

Microsoft Entra ID formerly Azure Active Directory is the backbone of modern identity management, enabling secure access to the applications, data, and services your business relies on. As hybrid work and cloud adoption accelerate, Entra ID plays an even more central role managing authentication, enforcing policy, and connecting users across distributed environments. That prominence also.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Update ASAP: Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers πŸ–‹οΈ

Google has released its monthly security updates for Android with fixes for 46 security flaws, including one vulnerability that it said has been exploited in the wild. The vulnerability in question is CVE202527363 CVSS score 8.1, a highseverity flaw in the System component that could lead to local code execution without requiring any additional execution privileges. "The most severe of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Inside DragonForce, the Group Tied to M&S, Co-op and Harrods Hacks πŸ“”

Individuals allegedly linked to the DragonForce cybercriminal syndicate have claimed the attack on the three UK retailers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Darcula Phishing as a Service Operation Snares 800,000+ Victims πŸ“”

Prolific PhaaS operation Darcula uses Magic Cat software to steal over 800,000 cards in a sevenmonth period.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK’s NCSC Offers Security Tips as Co-op Confirms Data Loss πŸ“”

The National Cyber Security Centre has published advice for retailers while the Coop admits customer data was stolen.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 What Are Managed Cybersecurity Services? 🌊

Managed cybersecurity services are delivered by a thirdparty cybersecurity service provider who monitors, detects, and responds to cyber threats across an organizations systems, networks, and applications.  Managed security services MSS include a full spectrum of cybersecurity as a service offerings, from realtime system monitoring and threat detection to incident response, vulnerability management, and compliance support. The post What Are Managed Cybersecurity Services? appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Addressing the Top Cyber-Risks in Higher Education πŸ•΅οΈβ€β™‚οΈ

As attacks accelerate, security leaders must act to gain visibility across their entire institution's network and systems and continuously educate their users on best practices.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Ransomware Attacks April 2025: Qilin Emerges from Chaos πŸ¦…

Ransomware Attacks April 2025 Qilin Emerges from Chaos " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202505RansomwareAttacksApril2025QilinEmergesfromChaos300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202505RansomwareAttacksApril2025QilinEmergesfromChaos.jpg" title"Ransomware Attacks April 2025 Qilin Emerges from Chaos  1" Global ransomware attacks in April 2025 declined to 450 from 564 in March the lowest level since November 2024 as major changes among the leading RansomwareasaService RaaS groups caused many affiliates to align with new groups. Still, the longterm trend for ransomware attacks remains decidedly upward chart below so Aprils decline could be reversed as soon as new RaaS leaders are established.  Rasomware attacks by month 20212025 Fo...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 App Used by Trump Adviser Suspends Services After Hack Taking ’15-20 Minutes’ 🦿

TeleMessage, a messaging app used by Trump adviser Mike Waltz, has suspended services after a hacker accessed sensitive government and corporate data.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation πŸ•΅οΈβ€β™‚οΈ

The vulnerabilities affect SonicWall's SMA devices for secure remote access, which have been heavily targeted by threat actors in the past.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Smishing Triad Upgrades Tools and Tactics for Global Attacks πŸ“”

Global smishing campaigns linked to Chinese cybercriminals escalate with Smishing Triads new tools and techniques.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet πŸ–‹οΈ

Threat actors have been observed actively exploiting security flaws in GeoVision endoflife EoL Internet of Things IoT devices to corral them into a Mirai botnet for conducting distributed denialofservice DDoS attacks. The activity, first observed by the Akamai Security Intelligence and Response Team SIRT in early April 2025, involves the exploitation of two operating system command.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Texas School District Notifies Over 47,000 People of Major Data Breach πŸ“”

The Alvin Independent School District in Texas has notified over 47,000 individuals affected by a data breach exposing sensitive personal information.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Russian hackers tried to lure diplomats with wine tasting – sound familiar? It’s an update to a previous campaign by the notorious Midnight Blizzard group πŸ“’

The Midnight Blizzard threat group has been targeting European diplomats with malicious emails offering an invite to wine tasting events, according to Check Point.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Researcher Says Patched Commvault Bug Still Exploitable πŸ•΅οΈβ€β™‚οΈ

CISA added CVE202534028 to its Known Exploited Vulnerabilities catalog, citing active attacks in the wild.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Easily Exploitable' Langflow Vulnerability Requires Immediate Patching πŸ•΅οΈβ€β™‚οΈ

The vulnerability, which has a CVSS score of 9.8, is under attack and allows threat actors to remotely execute arbitrary commands on servers running the agentic AI builder.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Almost a third of workers are covertly using AI at work – here’s why that’s a terrible idea πŸ“’

Employers need to get wise to the use of unauthorized AI tools and tighten up policies.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“’ Cyber attacks are costing UK firms billions every year – ransom payments, staff overtime, and lost business are crippling victims πŸ“’

New research from ESET shows the cost of cyber attacks against UK businesses is surging, with many victims struggling to remediate breaches.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity