πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” CISA Urged to Enrich KEV Catalog with More Contextual Data πŸ“”

Security teams should use vulnerability context alongside KEV lists to prioritize patching, OX argued.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 TechRepublic Premium Editorial Calendar: Policies, Hiring Kits, and Glossaries for Download 🦿

TechRepublic Premium content helps you solve your toughest IT issues and jumpstart your career or next project.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Dutch Police Lead Shut Down of Counter AV Service AVCheck πŸ“”

Dutch, US and Finnish investigators have taken cybercrime service AVCheck offline.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Hackers are using fake tool installers to dupe victims – and AI tools like ChatGPT are a key target πŸ“’

Cisco Talos said it has uncovered malware disguised as a lead monetization platform and a ChatGPT installer.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Secret Defense Strategy of Four Critical Industries Combating Advanced Cyber Threats πŸ–‹οΈ

The evolution of cyber threats has forced organizations across all industries to rethink their security strategies. As attackers become more sophisticated leveraging encryption, livingofftheland techniques, and lateral movement to evade traditional defenses security teams are finding more threats wreaking havoc before they can be detected. Even after an attack has been identified, it can.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions πŸ–‹οΈ

Cybersecurity researchers have warned of a new spearphishing campaign that uses a legitimate remote access tool called Netbird to target Chief Financial Officers CFOs and financial executives at banks, energy companies, insurers, and investment firms across Europe, Africa, Canada, the Middle East, and South Asia.  "In what appears to be a multistage phishing operation, the attackers.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Dutch Police Lead Shut Down of Counter AV Service AVCheck πŸ“”

Dutch, US and Finnish investigators have taken cybercrime service AVCheck offline.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Acreed Emerges as Dominant Infostealer Threat Following Lumma Takedown πŸ“”

A report on the dark web marketplace Russian Market showed Acreed has emerged as the leading infostealer.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More πŸ–‹οΈ

If this had been a security drill, someone wouldve said it went too far. But it wasnt a drillit was real. The access? Everything looked normal. The tools? Easy to find. The detection? Came too late. This is how attacks happen nowquiet, convincing, and fast. Defenders arent just chasing hackers anymoretheyre struggling to trust what their systems are telling them. The problem isnt too.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: Ransomware Drill to Spotlight Water Utility Cyber Risks in β€˜Operation 999’ πŸ“”

Semperis will host an immersive ransomware simulation focused on water utilities during Infosecurity Europe 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… CISA Issues Advisories Highlighting Siemens SiPass and Other Critical Vulnerabilities targeting ICS systems πŸ¦…

Cyble CISA Issues Advisories Highlighting Siemens SiPass and Other Critical Vulnerabilities targeting ICS systems " dataimagecaption"Cyble CISA Issues Advisories Highlighting Siemens SiPass and Other Critical Vulnerabilities targeting ICS systems " datamediumfile"httpscyble.comwpcontentuploads202506CybleBlogsSiemens300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202506CybleBlogsSiemens.jpg" title"CISA Issues Advisories Highlighting Siemens SiPass and Other Critical Vulnerabilities targeting ICS systems 1" The U.S. Cybersecurity and Infrastructure Security Agency CISA released five new ICS advisories this week, drawing attention to severe vulnerabilities affecting industrial and medical systems worldwide. Among the most notable disclosures are flaws in Siemens SiPass, Consili...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cryptojacking Campaign Targets DevOps Servers Including Nomad πŸ“”

Wiz finds new threat group running cryptojacking campaign via exploited and misconfigured DevOps assets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ In the AI Race With China, Don't Forget About Security πŸ•΅οΈβ€β™‚οΈ

The US needs to establish a clear framework to provide reasonable guardrails to protect its interests the quicker, the better.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“” Sophisticated Malware Campaign Targets Windows and Linux Systems πŸ“”

A new malware campaign targeting Windows and Linux systems has been identified, deploying tools for evasion and credential theft.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ AVCheck cyber crime service snared in police takedown πŸ“’

Authorities have seized the domains of AVCheck, one of the largest counter antivirus services used by cybercriminals around the world.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New Linux Vulnerabilities Expose Password Hashes via Core Dumps πŸ“”

Two local information disclosure flaws in Linux crashreporting tools have been identified exposing system data to attackers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU πŸ–‹οΈ

Qualcomm has shipped security updates to address three zeroday vulnerabilities that it said have been exploited in limited, targeted attacks in the wild. The flaws in question, which were responsibly disclosed to the company by the Google Android Security team, are listed below CVE202521479 and CVE202521480 CVSS score 8.6 Two incorrect authorization vulnerabilities in the Graphics.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Critical Bugs Could Spark Takeover of Widely Used Fire Safety OT/ICS Platform πŸ•΅οΈβ€β™‚οΈ

The unpatched security vulnerabilities in Consilium Safety's CS5000 Fire Panel could create "serious safety issues" in environments where fire suppression and safety are paramount, according to a CISA advisory.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Australia Begins New Ransomware Payment Disclosure Rules πŸ•΅οΈβ€β™‚οΈ

The country will require certain organizations to report ransomware payments and communications within 72 hours after they're made or face potential civil penalties.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub πŸ–‹οΈ

Cybersecurity researchers have discovered a new cryptojacking campaign that's targeting publicly accessible DevOps web servers such as those associated with Docker, Gitea, and HashiCorp Consul and Nomad to illicitly mine cryptocurrencies. Cloud security firm Wiz, which is tracking the activity under the name JINX0132, said the attackers are exploiting a wide range of known misconfigurations and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Preinstalled Apps on Ulefone, KrΓΌger&Matz Phones Let Any App Reset Device, Steal PIN πŸ–‹οΈ

Three security vulnerabilities have been disclosed in preloaded Android applications on smartphones from Ulefone and KrgerMatz that could enable any app installed on the device to perform a factory reset and encrypt an application. A brief description of the three flaws is as follows CVE202413915 CVSS score 6.9 A preinstalled "com.pri.factorytest" application on Ulefone and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity