πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” UK’s NCSC Offers Security Tips as Co-op Confirms Data Loss πŸ“”

The National Cyber Security Centre has published advice for retailers while the Coop admits customer data was stolen.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 What Are Managed Cybersecurity Services? 🌊

Managed cybersecurity services are delivered by a thirdparty cybersecurity service provider who monitors, detects, and responds to cyber threats across an organizations systems, networks, and applications.  Managed security services MSS include a full spectrum of cybersecurity as a service offerings, from realtime system monitoring and threat detection to incident response, vulnerability management, and compliance support. The post What Are Managed Cybersecurity Services? appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Addressing the Top Cyber-Risks in Higher Education πŸ•΅οΈβ€β™‚οΈ

As attacks accelerate, security leaders must act to gain visibility across their entire institution's network and systems and continuously educate their users on best practices.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Ransomware Attacks April 2025: Qilin Emerges from Chaos πŸ¦…

Ransomware Attacks April 2025 Qilin Emerges from Chaos " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202505RansomwareAttacksApril2025QilinEmergesfromChaos300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202505RansomwareAttacksApril2025QilinEmergesfromChaos.jpg" title"Ransomware Attacks April 2025 Qilin Emerges from Chaos  1" Global ransomware attacks in April 2025 declined to 450 from 564 in March the lowest level since November 2024 as major changes among the leading RansomwareasaService RaaS groups caused many affiliates to align with new groups. Still, the longterm trend for ransomware attacks remains decidedly upward chart below so Aprils decline could be reversed as soon as new RaaS leaders are established.  Rasomware attacks by month 20212025 Fo...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 App Used by Trump Adviser Suspends Services After Hack Taking ’15-20 Minutes’ 🦿

TeleMessage, a messaging app used by Trump adviser Mike Waltz, has suspended services after a hacker accessed sensitive government and corporate data.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation πŸ•΅οΈβ€β™‚οΈ

The vulnerabilities affect SonicWall's SMA devices for secure remote access, which have been heavily targeted by threat actors in the past.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Smishing Triad Upgrades Tools and Tactics for Global Attacks πŸ“”

Global smishing campaigns linked to Chinese cybercriminals escalate with Smishing Triads new tools and techniques.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet πŸ–‹οΈ

Threat actors have been observed actively exploiting security flaws in GeoVision endoflife EoL Internet of Things IoT devices to corral them into a Mirai botnet for conducting distributed denialofservice DDoS attacks. The activity, first observed by the Akamai Security Intelligence and Response Team SIRT in early April 2025, involves the exploitation of two operating system command.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Texas School District Notifies Over 47,000 People of Major Data Breach πŸ“”

The Alvin Independent School District in Texas has notified over 47,000 individuals affected by a data breach exposing sensitive personal information.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Russian hackers tried to lure diplomats with wine tasting – sound familiar? It’s an update to a previous campaign by the notorious Midnight Blizzard group πŸ“’

The Midnight Blizzard threat group has been targeting European diplomats with malicious emails offering an invite to wine tasting events, according to Check Point.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Researcher Says Patched Commvault Bug Still Exploitable πŸ•΅οΈβ€β™‚οΈ

CISA added CVE202534028 to its Known Exploited Vulnerabilities catalog, citing active attacks in the wild.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Easily Exploitable' Langflow Vulnerability Requires Immediate Patching πŸ•΅οΈβ€β™‚οΈ

The vulnerability, which has a CVSS score of 9.8, is under attack and allows threat actors to remotely execute arbitrary commands on servers running the agentic AI builder.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Almost a third of workers are covertly using AI at work – here’s why that’s a terrible idea πŸ“’

Employers need to get wise to the use of unauthorized AI tools and tighten up policies.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“’ Cyber attacks are costing UK firms billions every year – ransom payments, staff overtime, and lost business are crippling victims πŸ“’

New research from ESET shows the cost of cyber attacks against UK businesses is surging, with many victims struggling to remediate breaches.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ 96% of businesses have low cyber-readiness, claims Cisco πŸ“’

The 2025 Cisco Cybersecurity Readiness Index shows a concerning number of businesses globally are unprepared for rising AIrelated threats.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Infrastructure as Code: An IaC Guide to Cloud Security πŸ•΅οΈβ€β™‚οΈ

IaC is powerful. It brings speed, scale, and structure to cloud infrastructure. But none of that matters if your security can't keep up.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks πŸ–‹οΈ

Europol has announced the takedown of distributed denial of service DDoSforhire services that were used to launch thousands of cyberattacks across the world. In connection with the operation, Polish authorities have arrested four individuals and the United States has seized nine domains that are associated with the nowdefunct platforms. "The suspects are believed to be behind six separate.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws πŸ–‹οΈ

A second security flaw impacting the OttoKit formerly SureTriggers WordPress plugin has come under active exploitation in the wild. The vulnerability, tracked as CVE202527007 CVSS score 9.8, is a privilege escalation bug impacting all versions of the plugin prior to and including version 1.0.82.  "This is due to the createwpconnection function missing a capability check and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version πŸ–‹οΈ

Cybersecurity researchers have disclosed multiple security flaw in the onpremise version of SysAid IT support software that could be exploited to achieve preauthenticated remote code execution with elevated privileges. The vulnerabilities, tracked as CVE20252775, CVE20252776, and CVE20252777, have all been described as XML External Entity XXE injections, which occur when an attacker is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Reevaluating SSEs: A Technical Gap Analysis of Last-Mile Protection πŸ–‹οΈ

Security Service Edge SSE platforms have become the goto architecture for securing hybrid work and SaaS access. They promise centralized enforcement, simplified connectivity, and consistent policy control across users and devices. But there's a problem they stop short of where the most sensitive user activity actually happensthe browser. This isnt a small omission. Its a structural.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization πŸ–‹οΈ

Threat actors with links to the Play ransomware family exploited a recently patched security flaw in Microsoft Windows as a zeroday as part of an attack targeting an unnamed organization in the United States. The attack, per the Symantec Threat Hunter Team, part of Broadcom, leveraged CVE202529824, a privilege escalation flaw in the Common Log File System CLFS driver. It was patched by.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity