πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
24.8K subscribers
88.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ Operation PowerOFF Takes Down 9 DDoS-for-Hire Domains πŸ•΅οΈβ€β™‚οΈ

Four different countries, including the United States and Germany, were included in the latest international operation alongside Europol's support.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Security Tools Alone Don't Protect You β€” Control Effectiveness Does πŸ–‹οΈ

61 of security leaders reported suffering a breach due to failed or misconfigured controls over the past 12 months. This is despite having an average of 43 cybersecurity tools in place. This massive rate of security failure is clearly not a security investment problem. It is a configuration problem. Organizations are beginning to understand that a security control installed or deployed is not.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ SonicWall Issues Patch for Exploit Chain in SMA Devices πŸ•΅οΈβ€β™‚οΈ

Three vulnerabilities in SMA 100 gateways could facilitate root RCE attacks, and one of the vulnerabilities has already been exploited in the wild.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Qilin Ransomware Ranked Highest in April 2025 with Over 45 Data Leak Disclosures πŸ–‹οΈ

Threat actors with ties to the Qilin ransomware family have leveraged malware known as SmokeLoader along with a previously undocumented .NET compiled loader codenamed NETXLOADER as part of a campaign observed in November 2024. "NETXLOADER is a new .NETbased loader that plays a critical role in cyber attacks," Trend Micro researchers Jacob Santos, Raymart Yambot, John Rainier Navato, Sarah Pearl.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ SonicWall Issues Patch for Exploit Chain in SMA Devices πŸ•΅οΈβ€β™‚οΈ

Three vulnerabilities in SMA 100 gateways could facilitate root RCE attacks, and one of the vulnerabilities has already been exploited in the wild.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Email-Based Attacks Top Cyber-Insurance Claims πŸ•΅οΈβ€β™‚οΈ

Cyberinsurance carrier Coalition said business email compromise and funds transfer fraud accounted for 60 of claims in 2024.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Operation PowerOFF Takes Down 9 DDoS-for-Hire Domains πŸ•΅οΈβ€β™‚οΈ

Four different countries, including the United States and Germany, were included in the latest international operation alongside Europol's support.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Life Without CVEs? It's Time to Act πŸ•΅οΈβ€β™‚οΈ

Despite all MITRE has done for cybersecurity, it is clear we should not wait 11 months to discuss the future of the CVE database. It's simply too important for that.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Practical IT & Cybersecurity Training for Just $29.99 🦿

Learn by doing build jobready skills and train for CompTIA exams through realworld IT and coding exercises.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Business Owners: Here’s Why a VPN Isn’t Optional Anymore 🦿

Protect 10 team members browsing, block malware, and secure sensitive data with this easytouse VPN sub.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases πŸ–‹οΈ

Cybersecurity researchers have exposed what they say is an "industrialscale, global cryptocurrency phishing operation" engineered to steal digital assets from cryptocurrency wallets for several years. The campaign has been codenamed FreeDrain by threat intelligence firms SentinelOne and Validin. "FreeDrain uses SEO manipulation, freetier web services like gitbook.io, webflow.io, and github.io.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Security Tools Alone Don't Protect You β€” Control Effectiveness Does πŸ–‹οΈ

61 of security leaders reported suffering a breach due to failed or misconfigured controls over the past 12 months. This is despite having an average of 43 cybersecurity tools in place. This massive rate of security failure is clearly not a security investment problem. It is a configuration problem. Organizations are beginning to understand that a security control installed or deployed is not.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root πŸ–‹οΈ

SonicWall has released patches to address three security flaws affecting SMA 100 Secure Mobile Access SMA appliances that could be fashioned to result in remote code execution. The vulnerabilities are listed below CVE202532819 CVSS score 8.8 A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Qilin Ransomware Ranked Highest in April 2025 with Over 45 Data Leak Disclosures πŸ–‹οΈ

Threat actors with ties to the Qilin ransomware family have leveraged malware known as SmokeLoader along with a previously undocumented .NET compiled loader codenamed NETXLOADER as part of a campaign observed in November 2024. "NETXLOADER is a new .NETbased loader that plays a critical role in cyber attacks," Trend Micro researchers Jacob Santos, Raymart Yambot, John Rainier Navato, Sarah Pearl.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware πŸ–‹οΈ

The nationstate threat actor known as MirrorFace has been observed deploying malware dubbed ROAMINGMOUSE as part of a cyber espionage campaign directed against government agencies and public institutions in Japan and Taiwan. The activity, detected by Trend Micro in March 2025, involved the use of spearphishing lures to deliver an updated version of a backdoor called ANEL. "The ANEL file from.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware πŸ–‹οΈ

The Russialinked threat actor known as COLDRIVER has been observed distributing a new malware called LOSTKEYS as part of an espionagefocused campaign using ClickFixlike social engineering lures. "LOSTKEYS is capable of stealing files from a hardcoded list of extensions and directories, along with sending system information and running processes to the attacker," the Google Threat.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT πŸ–‹οΈ

Cisco has released software fixes to address a maximumseverity security flaw in its IOS XE Wireless Controller that could enable an unauthenticated, remote attacker to upload arbitrary files to a susceptible system. The vulnerability, tracked as CVE202520188, has been rated 10.0 on the CVSS scoring system. "This vulnerability is due to the presence of a hardcoded JSON Web Token JWT on an.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Russian Group Launches LOSTKEYS Malware in Attacks πŸ“”

New LOSTKEYS malware has been identified and linked to COLDRIVER by GTIG, stealing files and system data in targeted attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” LockBit Ransomware Hacked, Insider Secrets Exposed πŸ“”

The data dump will likely shed light on LockBits recent activity and help law enforcement trace cryptocurrency transactions.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Just 5% of Enterprises Have Deployed Quantum-Safe Encryption πŸ“”

DigiCert survey finds only 5 of global businesses are using postquantum cryptography.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Cyber Essentials Certification Numbers Falling Short πŸ“”

The UK government is set to prioritize increasing the number of UK organizations who are Cyber Essentials certified over the coming year.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity