πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet πŸ–‹οΈ

Threat actors have been observed actively exploiting security flaws in GeoVision endoflife EoL Internet of Things IoT devices to corral them into a Mirai botnet for conducting distributed denialofservice DDoS attacks. The activity, first observed by the Akamai Security Intelligence and Response Team SIRT in early April 2025, involves the exploitation of two operating system command.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Texas School District Notifies Over 47,000 People of Major Data Breach πŸ“”

The Alvin Independent School District in Texas has notified over 47,000 individuals affected by a data breach exposing sensitive personal information.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Russian hackers tried to lure diplomats with wine tasting – sound familiar? It’s an update to a previous campaign by the notorious Midnight Blizzard group πŸ“’

The Midnight Blizzard threat group has been targeting European diplomats with malicious emails offering an invite to wine tasting events, according to Check Point.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Researcher Says Patched Commvault Bug Still Exploitable πŸ•΅οΈβ€β™‚οΈ

CISA added CVE202534028 to its Known Exploited Vulnerabilities catalog, citing active attacks in the wild.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Easily Exploitable' Langflow Vulnerability Requires Immediate Patching πŸ•΅οΈβ€β™‚οΈ

The vulnerability, which has a CVSS score of 9.8, is under attack and allows threat actors to remotely execute arbitrary commands on servers running the agentic AI builder.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Almost a third of workers are covertly using AI at work – here’s why that’s a terrible idea πŸ“’

Employers need to get wise to the use of unauthorized AI tools and tighten up policies.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“’ Cyber attacks are costing UK firms billions every year – ransom payments, staff overtime, and lost business are crippling victims πŸ“’

New research from ESET shows the cost of cyber attacks against UK businesses is surging, with many victims struggling to remediate breaches.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ 96% of businesses have low cyber-readiness, claims Cisco πŸ“’

The 2025 Cisco Cybersecurity Readiness Index shows a concerning number of businesses globally are unprepared for rising AIrelated threats.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Infrastructure as Code: An IaC Guide to Cloud Security πŸ•΅οΈβ€β™‚οΈ

IaC is powerful. It brings speed, scale, and structure to cloud infrastructure. But none of that matters if your security can't keep up.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks πŸ–‹οΈ

Europol has announced the takedown of distributed denial of service DDoSforhire services that were used to launch thousands of cyberattacks across the world. In connection with the operation, Polish authorities have arrested four individuals and the United States has seized nine domains that are associated with the nowdefunct platforms. "The suspects are believed to be behind six separate.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws πŸ–‹οΈ

A second security flaw impacting the OttoKit formerly SureTriggers WordPress plugin has come under active exploitation in the wild. The vulnerability, tracked as CVE202527007 CVSS score 9.8, is a privilege escalation bug impacting all versions of the plugin prior to and including version 1.0.82.  "This is due to the createwpconnection function missing a capability check and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version πŸ–‹οΈ

Cybersecurity researchers have disclosed multiple security flaw in the onpremise version of SysAid IT support software that could be exploited to achieve preauthenticated remote code execution with elevated privileges. The vulnerabilities, tracked as CVE20252775, CVE20252776, and CVE20252777, have all been described as XML External Entity XXE injections, which occur when an attacker is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Reevaluating SSEs: A Technical Gap Analysis of Last-Mile Protection πŸ–‹οΈ

Security Service Edge SSE platforms have become the goto architecture for securing hybrid work and SaaS access. They promise centralized enforcement, simplified connectivity, and consistent policy control across users and devices. But there's a problem they stop short of where the most sensitive user activity actually happensthe browser. This isnt a small omission. Its a structural.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization πŸ–‹οΈ

Threat actors with links to the Play ransomware family exploited a recently patched security flaw in Microsoft Windows as a zeroday as part of an attack targeting an unnamed organization in the United States. The attack, per the Symantec Threat Hunter Team, part of Broadcom, leveraged CVE202529824, a privilege escalation flaw in the Common Log File System CLFS driver. It was patched by.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Uncover Malware in Fake Discord PyPI Package Downloaded 11,500+ Times πŸ–‹οΈ

Cybersecurity researchers have discovered a malicious package on the Python Package Index PyPI repository that masquerades as a seemingly harmless Discordrelated utility but incorporates a remote access trojan. The package in question is discordpydebug, which was uploaded to PyPI on March 21, 2022. It has been downloaded 11,574 times and continues to be available on the opensource registry.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ NSO Group Fined $168M for Targeting 1,400 WhatsApp Users With Pegasus Spyware πŸ–‹οΈ

A federal jury on Tuesday decided that NSO Group must pay Metaowned WhatsApp WhatsApp approximately 168 million in monetary damages, more than four months after a federal judge ruled that the Israeli company violated U.S. laws by exploiting WhatsApp servers to deploy Pegasus spyware, targeting over 1,400 individuals globally. WhatsApp originally filed the lawsuit against NSO Group in 2019,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🚨 UK pioneering global move away from passwords 🚨

Government to roll out passkey technology across digital services as an alternative to SMSbased verification.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 UK critical systems at increased risk from 'digital divide' created by AI threats 🚨

New report warns that organisations unable to defend AIenabled threats are exposed to greater cyber risk.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Toll road scams are in overdrive: Here’s how to protect yourself πŸš€

Have you received a text message about an unpaid road toll? Make sure youre not the next victim of a smishing scam.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Passkeys Set to Protect GOV.UK Accounts Against Cyber-Attacks πŸ“”

The UK government has announced that it will be replace its current SMS verification system with passkeys by the end of 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“” NSO Group Hit with $168m Fine for WhatsApp Pegasus Spyware Abuse πŸ“”

The Israeli spyware maker must pay 444,719 in compensatory damages to Meta and 167.25m in punitive damages.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1