πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
24.9K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ Following Data Breach, Multiple Stalkerware Apps Go Offline πŸ•΅οΈβ€β™‚οΈ

The same easily exploitable vulnerability was found in three of the apps that led to the compromise of victims' data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Russian Threat Actor TAG-110 Goes Phishing in Tajikistan πŸ•΅οΈβ€β™‚οΈ

While Ukraine remains Russia's major target for cyberattacks, TAG110 is part of a strategy to preserve "a postSoviet sphere of influence" by embedding itself in other countries' infrastructures.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Russian Threat Actor TAG-110 Goes Phishing in Tajikistan πŸ•΅οΈβ€β™‚οΈ

While Ukraine remains Russia's major target for cyberattacks, TAG110 is part of a strategy to preserve "a postSoviet sphere of influence" by embedding itself in other countries' infrastructures.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 3am Ransomware Adopts Email Bombing, Vishing Combo Attack πŸ•΅οΈβ€β™‚οΈ

The emerging threat group is the latest to adopt the combo attack tactic, which Black Basta and other groups already are using to gain initial access for ransomware deployment.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 3am Ransomware Adopts Email Bombing, Vishing Combo Attack πŸ•΅οΈβ€β™‚οΈ

The emerging threat group is the latest to adopt the combo attack tactic, which Black Basta and other groups already are using to gain initial access for ransomware deployment.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ UK Retail Cyberattacks May Drive Up US Insurance Premiums πŸ•΅οΈβ€β™‚οΈ

Insurance experts weigh in how the recent barrage of attacks against UK retailers could affect premium rates and policy requirements, as well as work toward improving risk assessment.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ UK Retail Cyberattacks May Drive Up US Insurance Premiums πŸ•΅οΈβ€β™‚οΈ

Insurance experts weigh in how the recent barrage of attacks against UK retailers could affect premium rates and policy requirements, as well as work toward improving risk assessment.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ CISA: Russia's Fancy Bear Targeting Logistics, IT Firms πŸ•΅οΈβ€β™‚οΈ

The mission is to gather information that could help Russia in its war against Ukraine.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ CISA: Russia's Fancy Bear Targeting Logistics, IT Firms πŸ•΅οΈβ€β™‚οΈ

The mission is to gather information that could help Russia in its war against Ukraine.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Blurring Lines Between Scattered Spider & Russian Cybercrime πŸ•΅οΈβ€β™‚οΈ

The loosely affiliated hacking group has shifted closer to ransomware gangs, raising questions about Scattered Spider's ties to the Russian cybercrime underground.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Blurring Lines Between Scattered Spider & Russian Cybercrime πŸ•΅οΈβ€β™‚οΈ

The loosely affiliated hacking group has shifted closer to ransomware gangs, raising questions about Scattered Spider's ties to the Russian cybercrime underground.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Security Threats of Open Source AI Exposed by DeepSeek πŸ•΅οΈβ€β™‚οΈ

DeepSeek's risks must be carefully considered, and ultimately mitigated, in order to enjoy the many benefits of generative AI in a manner that is safe and secure for all organizations and users.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘Ž1
πŸ•΅οΈβ€β™‚οΈ Security Threats of Open Source AI Exposed by DeepSeek πŸ•΅οΈβ€β™‚οΈ

DeepSeek's risks must be carefully considered, and ultimately mitigated, in order to enjoy the many benefits of generative AI in a manner that is safe and secure for all organizations and users.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘Ž1
πŸ•΅οΈβ€β™‚οΈ Keeping LLMs on the Rails Poses Design, Engineering Challenges πŸ•΅οΈβ€β™‚οΈ

Despite adding alignment training, guardrails, and filters, large language models continue to give up secrets, make unfiltered statements, and provide dangerous information.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘Ž1
πŸ•΅οΈβ€β™‚οΈ Keeping LLMs on the Rails Poses Design, Engineering Challenges πŸ•΅οΈβ€β™‚οΈ

Despite adding alignment training, guardrails, and filters, large language models continue to give up secrets, make unfiltered statements, and provide dangerous information.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘Ž1
πŸ•΅οΈβ€β™‚οΈ GitLab's AI Assistant Opened Devs to Code Theft πŸ•΅οΈβ€β™‚οΈ

Prompt injection risks in GitLab's AI assistant could have allowed attackers to steal source code, or indirectly deliver developers malware, dirty links, and more.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ GitLab's AI Assistant Opened Devs to Code Theft πŸ•΅οΈβ€β™‚οΈ

Prompt injection risks in GitLab's AI assistant could have allowed attackers to steal source code, or indirectly deliver developers malware, dirty links, and more.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ SideWinder APT Caught Spying on India's Neighbor Gov'ts πŸ•΅οΈβ€β™‚οΈ

A recent spearphishing campaign against countries in South Asia aligns with broader political tensions in the region.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ SideWinder APT Caught Spying on India's Neighbor Gov'ts πŸ•΅οΈβ€β™‚οΈ

A recent spearphishing campaign against countries in South Asia aligns with broader political tensions in the region.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Oops: DanaBot Malware Devs Infected Their Own PCs β™ŸοΈ

The U.S. government today unsealed criminal charges against 16 individuals accused of operating and selling DanaBot, a prolific strain of informationstealing malware that has been sold on Russian cybercrime forums since 2018. The FBI says a newer version of DanaBot was used for espionage, and that many of the defendants exposed their reallife identities after accidentally infecting their own systems with the malware.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI-Generated TikTok Videos Used to Distribute Infostealer Malware πŸ“”

Malware campaign exploiting TikToks popularity has been observed using social engineering to spread Vidar and StealC.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
😱1