🛡 Cybersecurity & Privacy 🛡 - News
25.1K subscribers
88.4K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕵️‍♂️ WestJet Airlines App, Website Suffer After Cyber Incident 🕵️‍♂️

Though its operations are running smoothly, the airline warned customers and employees to exercise caution when sharing personal information online.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
📢 23andMe 'failed to take basic steps' to safeguard customer data 📢

The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
😱1
📔 UK ICO Fines 23andMe £2.3m for Data Protection Failings 📔

23andMe has been fined over 2m by the UK ICO for failing to adequately protect genetic data.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
👍1
🖋️ Silver Fox APT Targets Taiwan with Complex Gh0stCringe and HoldingHands RAT Malware 🖋️

Cybersecurity researchers are warning of a new phishing campaign that's targeting users in Taiwan with malware families such as HoldingHands RAT and Gh0stCringe. The activity is part of a broader campaign that delivered the Winos 4.0 malware framework earlier this January by sending phishing messages impersonating Taiwan's National Taxation Bureau, Fortinet FortiGuard Labs said in a report.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
😱1
🕵️‍♂️ Operation Endgame: Do Takedowns and Arrests Matter? 🕵️‍♂️

Cybercrime response needs more aggressive actions from those seeking to protect victims and pursue criminals.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Private 5G: New Possibilities — and Potential Pitfalls 🕵️‍♂️

While ushering in "great operational value" for organizations, private 5G networks add yet another layer to CISOs' responsibilities.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
📔 Hacklink Marketplace Fuels Surge in Covert SEO Poisoning Attacks 📔

New SEO poisoning attacks identified, using Hacklink to hijack search rankings and inject malicious links into sites.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🖋️ LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents 🖋️

Cybersecurity researchers have disclosed a nowpatched security flaw in LangChain's LangSmith platform that could be exploited to capture sensitive data, including API keys and user prompts. The vulnerability, which carries a CVSS score of 8.8 out of a maximum of 10.0, has been codenamed AgentSmith by Noma Security. LangSmith is an observability and evaluation platform that allows users to.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
1
🖋️ LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents 🖋️

Cybersecurity researchers have disclosed a nowpatched security flaw in LangChain's LangSmith platform that could be exploited to capture sensitive data, including API keys and user prompts. The vulnerability, which carries a CVSS score of 8.8 out of a maximum of 10.0, has been codenamed AgentSmith by Noma Security. LangSmith is an observability and evaluation platform that allows users to.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ 'HoldingHands' Acts Like a Pickpocket With Taiwan Orgs 🕵️‍♂️

Since at least January, the threat actor has been employing multiple malware tools to steal information for potential future attacks against Taiwanese businesses and government agencies.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🖋️ Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor 🖋️

A nowpatched security flaw in Google Chrome was exploited as a zeroday by a threat actor known as TaxOff to deploy a backdoor codenamed Trinper. The attack, observed in midMarch 2025 by Positive Technologies, involved the use of a sandbox escape vulnerability tracked as CVE20252783 CVSS score 8.3. Google addressed the flaw later that month after Kaspersky reported inthewild.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Indian Car-Sharing Firm Zoomcar Latest to Suffer Breach 🕵️‍♂️

The company acknowledged that cybercriminals had taken sensitive information on more than 8 million users, including names, phone numbers, car registration numbers, addresses, and emails.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🖋️ Veeam Patches CVE-2025-23121: Critical RCE Bug Rated 9.9 CVSS in Backup & Replication 🖋️

Veeam has rolled out patches to contain a critical security flaw impacting its Backup Replication software that could result in remote code execution under certain conditions. The security defect, tracked as CVE202523121, carries a CVSS score of 9.9 out of a maximum of 10.0. "A vulnerability allowing remote code execution RCE on the Backup Server by an authenticated domain user," the.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict 🖋️

Iran has throttled internet access in the country in a purported attempt to hamper Israel's ability to conduct covert cyber operations, days after the latter launched an unprecedented attack on the country, escalating geopolitical tensions in the region. Fatemeh Mohajerani, the spokesperson of the Iranian Government, and the Iranian Cyber Police, FATA, said the internet slowdown was designed to.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ CISA Warns of Active Exploitation of Linux Kernel Privilege Escalation Vulnerability 🖋️

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Tuesday placed a security flaw impacting the Linux kernel in its Known Exploited Vulnerabilities KEV catalog, stating it has been actively exploited in the wild. The vulnerability, CVE20230386 CVSS score 7.8, is an improper ownership bug in the Linux kernel that could be exploited to escalate privileges on susceptible.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents 🖋️

A former U.S. Central Intelligence Agency CIA analyst has been sentenced to little more than three years in prison for unlawfully retaining and transmitting top secret National Defense Information NDI to people who were not entitled to receive them and for attempting to cover up the malicious activity. Asif William Rahman, 34, of Vienna, has been sentenced today to 37 months on charges of.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📢 Government cybersecurity action plan includes £16 million in funding 📢

Cash will go to help startups, scaleups, and university spinouts, while a new advisory group will aim to improve public sector cybersecurity.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ How CISOs Can Govern AI & Meet Evolving Regulations 🕵️‍♂️

Security teams are no longer just the last line of defense they are the foundation for responsible AI adoption.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🤔1
🕵️‍♂️ Serpentine#Cloud Uses Cloudflare Tunnels in Sneak Attacks 🕵️‍♂️

An unidentified threat actor is using .lnk Windows shortcut files in a series of sophisticated attacks utilizing inmemory code execution and livingofftheland cyberattack strategies.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🖋️ FedRAMP at Startup Speed: Lessons Learned 🖋️

For organizations eyeing the federal market, FedRAMP can feel like a gated fortress. With strict compliance requirements and a notoriously long runway, many companies assume the path to authorization is reserved for the wellresourced enterprise. But thats changing. In this post, we break down how fastmoving startups can realistically achieve FedRAMP Moderate authorization without derailing.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Water Curse Employs 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign 🖋️

Cybersecurity researchers have exposed a previously unknown threat actor known as Water Curse that relies on weaponized GitHub repositories to deliver multistage malware. "The malware enables data exfiltration including credentials, browser data, and session tokens, remote access, and longterm persistence on infected systems," Trend Micro researchers Jovit Samaniego, Aira Marcelo, Mohamed.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity