πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” New Linux Vulnerabilities Expose Password Hashes via Core Dumps πŸ“”

Two local information disclosure flaws in Linux crashreporting tools have been identified exposing system data to attackers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU πŸ–‹οΈ

Qualcomm has shipped security updates to address three zeroday vulnerabilities that it said have been exploited in limited, targeted attacks in the wild. The flaws in question, which were responsibly disclosed to the company by the Google Android Security team, are listed below CVE202521479 and CVE202521480 CVSS score 8.6 Two incorrect authorization vulnerabilities in the Graphics.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Critical Bugs Could Spark Takeover of Widely Used Fire Safety OT/ICS Platform πŸ•΅οΈβ€β™‚οΈ

The unpatched security vulnerabilities in Consilium Safety's CS5000 Fire Panel could create "serious safety issues" in environments where fire suppression and safety are paramount, according to a CISA advisory.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Australia Begins New Ransomware Payment Disclosure Rules πŸ•΅οΈβ€β™‚οΈ

The country will require certain organizations to report ransomware payments and communications within 72 hours after they're made or face potential civil penalties.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub πŸ–‹οΈ

Cybersecurity researchers have discovered a new cryptojacking campaign that's targeting publicly accessible DevOps web servers such as those associated with Docker, Gitea, and HashiCorp Consul and Nomad to illicitly mine cryptocurrencies. Cloud security firm Wiz, which is tracking the activity under the name JINX0132, said the attackers are exploiting a wide range of known misconfigurations and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Preinstalled Apps on Ulefone, KrΓΌger&Matz Phones Let Any App Reset Device, Steal PIN πŸ–‹οΈ

Three security vulnerabilities have been disclosed in preloaded Android applications on smartphones from Ulefone and KrgerMatz that could enable any app installed on the device to perform a factory reset and encrypt an application. A brief description of the three flaws is as follows CVE202413915 CVSS score 6.9 A preinstalled "com.pri.factorytest" application on Ulefone and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ EMR-ISAC Shuts Down: What Happens Now? πŸ•΅οΈβ€β™‚οΈ

The Emergency Management and Response Information Sharing and Analysis Center provided essential information to the emergency services sector on physical and cyber threats and its closure leaves an information vacuum for these organizations.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Exploitation Risk Grows for Critical Cisco Bug πŸ•΅οΈβ€β™‚οΈ

New details on the Cisco IOS XE vulnerability could help attackers develop a working exploit soon, researchers say.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Trickbot, Conti Ransomware Operator Unmasked Amid Huge Ops Leak πŸ•΅οΈβ€β™‚οΈ

An anonymous whistleblower has leaked large amounts of data tied to the alleged operator behind Trickbot and Conti ransomware.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch πŸ–‹οΈ

Google on Monday released outofband fixes to address three security issues in its Chrome browser, including one that it said has come under active exploitation in the wild. The highseverity flaw is being tracked as CVE20255419, and has been flagged as an outofbounds read and write vulnerability in the V8 JavaScript and WebAssembly engine. "Out of bounds read and write in V8 in Google.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: Half of Firms Suffer Two Supply Chain Incidents in Past Year πŸ“”

Risk Ledger found that 90 of UK professionals view supply chain cyber incidents as a top concern for 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… APRA Compliance, Simplified by Cyble πŸ¦…

Cyble APRA Compliance, Simplified by Cyble " dataimagecaption"Cyble APRA Compliance, Simplified by Cyble " datamediumfile"httpscyble.comwpcontentuploads202506CybleBlogsAPRA300x150.png" datalargefile"httpscyble.comwpcontentuploads202506CybleBlogsAPRA1024x512.png" title"APRA Compliance, Simplified by Cyble 1" Australias fintech sector is undergoing rapid evolution. With a booming A45 billion fintech industry and a 10 trillion financial services market, the nation has become a global hub for digital finance innovation. However, this progress comes with heightened scrutiny and regulatory pressure. The Australian Prudential Regulation Authority APRA and the Australian Cyber Security Centre ACSC are urging organizations to implement strong cyber hygiene measuresespecially the Essential 8as...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues πŸ–‹οΈ

Google has revealed that it will no longer trust digital certificates issued by Chunghwa Telecom and Netlock citing "patterns of concerning behavior observed over the past year." The changes are expected to be introduced in Chrome 139, which is scheduled for public release in early August 2025. The current major version is 137.  The update will affect all Transport Layer Security TLS.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft and CrowdStrike Launch Shared Threat Actor Glossary to Cut Attribution Confusion πŸ–‹οΈ

Microsoft and CrowdStrike have announced that they are teaming up to align their individual threat actor taxonomies by publishing a new joint threat actor mapping. "By mapping where our knowledge of these actors align, we will provide security professionals with the ability to connect insights faster and make decisions with greater confidence," Vasu Jakkal, corporate vice president at Microsoft.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Open-Weight Chinese AI Models Drive Privacy Innovation in LLMs πŸ•΅οΈβ€β™‚οΈ

Edge computing and stricter regulations may usher in a new era of AI privacy.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Silence, Security, Speed β€” This Antivirus Checks Every Box 🦿

ESET NOD32 2025's AI and cloudpowered scanning detect threats faster and more accurately than legacy tools.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 6 Best Open Source Password Managers for Windows in 2025 🦿

Discover the top opensource password managers for Windows. Learn about the features and benefits of each to determine which one is the best fit for your needs.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Scattered Spider: Understanding Help Desk Scams and How to Defend Your Organization πŸ–‹οΈ

In the wake of highprofile attacks on UK retailers Marks Spencer and Coop, Scattered Spider has been all over the media, with coverage spilling over into the mainstream news due to the severity of the disruption caused currently looking like hundreds of millions in lost profits for MS alone.  This coverage is extremely valuable for the cybersecurity community as it raises.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets πŸ–‹οΈ

A growing number of malicious campaigns have leveraged a recently discovered Android banking trojan called Crocodilus to target users in Europe and South America. The malware, according to a new report published by ThreatFabric, has also adopted improved obfuscation techniques to hinder analysis and detection, and includes the ability to create new contacts in the victim's contacts list. "Recent.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘½ Victoria’s Secret Website Offline Amidst β€œSecurity Incident” πŸ‘½

Lingerie giant Victorias Secret has confirmed that its U.S. website was taken offline as a precautionary measure following a security incident that began impacting operations earlier this week. While the company has been tightlipped on the exact nature of the disruption, the widespread outages and the engagement of thirdparty experts suggest a significant cybersecurity event. .

πŸ“– Read more.

πŸ”— Via "BE3SEC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Trump Budget Plan to Cut Nearly 1000 Jobs at Cyber Agency CISA πŸ“”

CISA is facing 495m budget cut, losing 1000 employees and reducing staff to 2324.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity