πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues πŸ–‹οΈ

Google has revealed that it will no longer trust digital certificates issued by Chunghwa Telecom and Netlock citing "patterns of concerning behavior observed over the past year." The changes are expected to be introduced in Chrome 139, which is scheduled for public release in early August 2025. The current major version is 137.  The update will affect all Transport Layer Security TLS.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft and CrowdStrike Launch Shared Threat Actor Glossary to Cut Attribution Confusion πŸ–‹οΈ

Microsoft and CrowdStrike have announced that they are teaming up to align their individual threat actor taxonomies by publishing a new joint threat actor mapping. "By mapping where our knowledge of these actors align, we will provide security professionals with the ability to connect insights faster and make decisions with greater confidence," Vasu Jakkal, corporate vice president at Microsoft.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Open-Weight Chinese AI Models Drive Privacy Innovation in LLMs πŸ•΅οΈβ€β™‚οΈ

Edge computing and stricter regulations may usher in a new era of AI privacy.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Silence, Security, Speed β€” This Antivirus Checks Every Box 🦿

ESET NOD32 2025's AI and cloudpowered scanning detect threats faster and more accurately than legacy tools.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 6 Best Open Source Password Managers for Windows in 2025 🦿

Discover the top opensource password managers for Windows. Learn about the features and benefits of each to determine which one is the best fit for your needs.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Scattered Spider: Understanding Help Desk Scams and How to Defend Your Organization πŸ–‹οΈ

In the wake of highprofile attacks on UK retailers Marks Spencer and Coop, Scattered Spider has been all over the media, with coverage spilling over into the mainstream news due to the severity of the disruption caused currently looking like hundreds of millions in lost profits for MS alone.  This coverage is extremely valuable for the cybersecurity community as it raises.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets πŸ–‹οΈ

A growing number of malicious campaigns have leveraged a recently discovered Android banking trojan called Crocodilus to target users in Europe and South America. The malware, according to a new report published by ThreatFabric, has also adopted improved obfuscation techniques to hinder analysis and detection, and includes the ability to create new contacts in the victim's contacts list. "Recent.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘½ Victoria’s Secret Website Offline Amidst β€œSecurity Incident” πŸ‘½

Lingerie giant Victorias Secret has confirmed that its U.S. website was taken offline as a precautionary measure following a security incident that began impacting operations earlier this week. While the company has been tightlipped on the exact nature of the disruption, the widespread outages and the engagement of thirdparty experts suggest a significant cybersecurity event. .

πŸ“– Read more.

πŸ”— Via "BE3SEC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Trump Budget Plan to Cut Nearly 1000 Jobs at Cyber Agency CISA πŸ“”

CISA is facing 495m budget cut, losing 1000 employees and reducing staff to 2324.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: Demand More of Your Vendors to Ease Quantum Transition, Say Experts πŸ“”

CISOs should demand more of their vendors and use regulation as an ally to persuade board members to accelerate the transition to postquantum safety.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fake Docusign Pages Deliver Multi-Stage NetSupport RAT Malware πŸ“”

Malware campaign used fake DocuSign pages to deploy NetSupport RAT through clipboard manipulation.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: VEC Attacks Alarmingly Effective at Driving Engagement πŸ“”

Abnormal AI found that engagement rates with VEC attacks globally is worrisomely high, overtaking BEC in the EMEA region.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Ransomware Landscape May 2025: SafePay, DevMan Emerge as Major Threats πŸ¦…

Cyble Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats " dataimagecaption"Cyble Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats " datamediumfile"httpscyble.comwpcontentuploads202506CybleBlogsRansomwareSafePay300x150.png" datalargefile"httpscyble.comwpcontentuploads202506CybleBlogsRansomwareSafePay1024x512.png" title"Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats 1" SafePay took the top spot among ransomware groups in May 2025, solidifying the groups status as a major threat. Overall, ransomware groups claimed 384 victims in May chart below, the third straight monthly decline, as leadership continues to shift after RansomHub the top group for more than a year went offline at the end of March in what may have been an inf...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious Code πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a critical security flaw in the Roundcube webmail software that has gone unnoticed for a decade and could be exploited to take over susceptible systems and execute arbitrary code. The vulnerability, tracked as CVE202549113, carries a CVSS score of 9.9 out of 10.0. It has been described as a case of postauthenticated remote code execution via.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Is Your CISO Navigating Your Flight Path? πŸ•΅οΈβ€β™‚οΈ

If your CISO isn't wielding influence with the CEO and helping top leaders clearly see the flight path ahead, your company is dangerously exposed.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: Good Cybersecurity Enabled Ukraine’s Surprise Attack on Russia, Says NCSC πŸ“”

Effective cybersecurity played a key role Ukraine drone attack on Russian strategic bombers, a leading government security expert has claimed.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack πŸ–‹οΈ

Threat hunters are alerting to a new campaign that employs deceptive websites to trick unsuspecting users into executing malicious PowerShell scripts on their machines and infect them with the NetSupport RAT malware. The DomainTools Investigations DTI team said it identified "malicious multistage downloader Powershell scripts" hosted on lure websites that masquerade as Gitcode and DocuSign. ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: Channel Bridges Security Skills Gap πŸ“”

Resellers and channel partners can add value, fill gaps in security teams and offer expertise in niche markets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Email spoofing attacks are still a major threat for FTSE 100 companies – despite a simple fix being widely available πŸ“’

Improper configuration of DMARC and other email authentication protocols opens organizations to major threats.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Appeals DMA, Says EU Has β€˜Deeply Flawed Rules’ That β€˜Stifle Innovation’ 🦿

Apple is appealing EU demands to open iOS to thirdparty devices, arguing interoperability threatens privacy, security, and user experience.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Cyber Attacks Are Up 47% in 2025 – AI is One Key Factor 🦿

Another key factor is that ransomware has turned into a business model, Check Point researchers report.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity