πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Fake Docusign Pages Deliver Multi-Stage NetSupport RAT Malware πŸ“”

Malware campaign used fake DocuSign pages to deploy NetSupport RAT through clipboard manipulation.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: VEC Attacks Alarmingly Effective at Driving Engagement πŸ“”

Abnormal AI found that engagement rates with VEC attacks globally is worrisomely high, overtaking BEC in the EMEA region.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Ransomware Landscape May 2025: SafePay, DevMan Emerge as Major Threats πŸ¦…

Cyble Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats " dataimagecaption"Cyble Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats " datamediumfile"httpscyble.comwpcontentuploads202506CybleBlogsRansomwareSafePay300x150.png" datalargefile"httpscyble.comwpcontentuploads202506CybleBlogsRansomwareSafePay1024x512.png" title"Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats 1" SafePay took the top spot among ransomware groups in May 2025, solidifying the groups status as a major threat. Overall, ransomware groups claimed 384 victims in May chart below, the third straight monthly decline, as leadership continues to shift after RansomHub the top group for more than a year went offline at the end of March in what may have been an inf...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious Code πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a critical security flaw in the Roundcube webmail software that has gone unnoticed for a decade and could be exploited to take over susceptible systems and execute arbitrary code. The vulnerability, tracked as CVE202549113, carries a CVSS score of 9.9 out of 10.0. It has been described as a case of postauthenticated remote code execution via.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Is Your CISO Navigating Your Flight Path? πŸ•΅οΈβ€β™‚οΈ

If your CISO isn't wielding influence with the CEO and helping top leaders clearly see the flight path ahead, your company is dangerously exposed.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: Good Cybersecurity Enabled Ukraine’s Surprise Attack on Russia, Says NCSC πŸ“”

Effective cybersecurity played a key role Ukraine drone attack on Russian strategic bombers, a leading government security expert has claimed.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack πŸ–‹οΈ

Threat hunters are alerting to a new campaign that employs deceptive websites to trick unsuspecting users into executing malicious PowerShell scripts on their machines and infect them with the NetSupport RAT malware. The DomainTools Investigations DTI team said it identified "malicious multistage downloader Powershell scripts" hosted on lure websites that masquerade as Gitcode and DocuSign. ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2025: Channel Bridges Security Skills Gap πŸ“”

Resellers and channel partners can add value, fill gaps in security teams and offer expertise in niche markets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Email spoofing attacks are still a major threat for FTSE 100 companies – despite a simple fix being widely available πŸ“’

Improper configuration of DMARC and other email authentication protocols opens organizations to major threats.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Appeals DMA, Says EU Has β€˜Deeply Flawed Rules’ That β€˜Stifle Innovation’ 🦿

Apple is appealing EU demands to open iOS to thirdparty devices, arguing interoperability threatens privacy, security, and user experience.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Cyber Attacks Are Up 47% in 2025 – AI is One Key Factor 🦿

Another key factor is that ransomware has turned into a business model, Check Point researchers report.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ β€˜I take pleasure in thinking I can rid society of at least some of them’: A cyber vigilante is dumping information on notorious ransomware criminals – and security experts say police will be keeping close tabs πŸ“’

An anonymous whistleblower has released large amounts of data allegedly linked to the ransomware gangs.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Crocodilus' Sharpens Its Teeth on Android Users πŸ•΅οΈβ€β™‚οΈ

The datastealing malware initially targeted users in Turkey but has since evolved into a global threat.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ•΅οΈβ€β™‚οΈ Victoria's Secret Delays Earnings Call Due to Cyber Incident πŸ•΅οΈβ€β™‚οΈ

But that didn't stop the clothing retailer from issuing preliminary results for the first quarter of 2025.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Chrome Drops Trust for Chunghwa, Netlock Certificates πŸ•΅οΈβ€β™‚οΈ

Digital certificates authorized by the authorities will no longer have trust by default in the browser starting in August, over what Google said is a loss of integrity in actions by the respective companies.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ LummaC2 Fractures as Acreed Malware Becomes Top Dog πŸ•΅οΈβ€β™‚οΈ

LummaC2 formerly accounted for almost 92 of Russian Market's credential theft log alerts. Now, the Acreed infostealer has replaced its market share.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 This $35 Training Pack May Help You Land a Cybersecurity Job 🦿

Unlock lifetime access to 11 beginnerfriendly cybersecurity and networking courses taught by real experts.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cutting-Edge ClickFix Tactics Snowball, Pushing Phishing Forward πŸ•΅οΈβ€β™‚οΈ

Several widespread ClickFix campaigns are underway, bent on delivering malware to business targets, and they represent a new level of phishing sophistication that defenders need to be prepared for, researchers warn.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ F5 Acquires Agentic AI Security Startup Fletch πŸ•΅οΈβ€β™‚οΈ

Agentic AI technology will be integrated into the recently launched F5 Application Delivery and Security Platform.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Scattered Spider Uses Tech Vendor Impersonation and Phishing Kits to Target Helpdesks πŸ“”

The ransomware group combines IT vendor impersonation and phishing frameworks like Evilginx to breach its targets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🦿 FBI Issues Play Ransomware Security Advisory & Mitigation Steps to Take Now 🦿

The Play ransomware group has hit about 900 organizations globally so far and uses double extortion after data theft.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity