πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Automation and Vulnerability Exploitation Drive Mass Ransomware Breaches πŸ“”

ReliaQuest warns that initial access vulnerability exploitation is driving successful ransomware attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms πŸ–‹οΈ

The French cybersecurity agency on Tuesday revealed that a number of entities spanning governmental, telecommunications, media, finance, and transport sectors in the country were impacted by a malicious campaign undertaken by a Chinese hacking group by weaponizing several zeroday vulnerabilities in Ivanti Cloud Services Appliance CSA devices. The campaign, detected at the beginning of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Dark Web Vendors Shift to Third Parties, Supply Chains πŸ•΅οΈβ€β™‚οΈ

As attacks on software supply chains and third parties increase, more data on critical software and infrastructure services is being advertised and sold on the Dark Web.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms πŸ–‹οΈ

The French cybersecurity agency on Tuesday revealed that a number of entities spanning governmental, telecommunications, media, finance, and transport sectors in the country were impacted by a malicious campaign undertaken by a Chinese hacking group by weaponizing several zeroday vulnerabilities in Ivanti Cloud Services Appliance CSA devices. The campaign, detected at the beginning of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ A prolific ransomware group says it’s shutting down and giving out free decryption keys to victims – but cyber experts warn it's not exactly a 'gesture of goodwill' πŸ“’

The Hunters International ransomware group is rebranding and switching tactics.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”2
πŸ•΅οΈβ€β™‚οΈ New Cyber Blueprint Aims to Guide Organizations on AI Journey πŸ•΅οΈβ€β™‚οΈ

Deloitte's new blueprint looks to bridge the gap between the massive push for AI adoption and a lack of preparedness among leaders and employees.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Dark Web Vendors Shift to Third Parties, Supply Chains πŸ•΅οΈβ€β™‚οΈ

As attacks on software supply chains and third parties increase, more data on critical software and infrastructure services is being advertised and sold on the Dark Web.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Criminals Sending QR Codes in Phishing, Malware Campaigns πŸ•΅οΈβ€β™‚οΈ

The AntiPhishing Working Group observed how attackers are increasingly abusing QR codes to conduct phishing attacks or to trick users into downloading malware.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ IDE Extensions Pose Hidden Risks to Software Supply Chain πŸ•΅οΈβ€β™‚οΈ

Malicious extensions can be engineered to bypass verification checks for popular integrated development environments, according to research from OX Security.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Attackers Impersonate Top Brands in Callback Phishing πŸ•΅οΈβ€β™‚οΈ

Microsoft, PayPal, Docusign, and others are among the trusted brands threat actors use in socially engineered scams that try to get victims to call adversarycontrolled phone numbers.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Your AI Agents Might Be Leaking Data β€” Watch this Webinar to Learn How to Stop It πŸ–‹οΈ

Generative AI is changing how businesses work, learn, and innovate. But beneath the surface, something dangerous is happening. AI agents and custom GenAI workflows are creating new, hidden ways for sensitive enterprise data to leakand most teams dont even realize it. If youre building, deploying, or managing AI systems, now is the time to ask Are your AI agents exposing confidential data.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros πŸ–‹οΈ

Cybersecurity researchers have disclosed two security flaws in the Sudo commandline utility for Linux and Unixlike operating systems that could enable local attackers to escalate their privileges to root on susceptible machines. A brief description of the vulnerabilities is below CVE202532462 CVSS score 2.8 Sudo before 1.9.17p1, when used with a sudoers file that specifies a host.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Taiwan Flags Chinese Apps Over Data Security Violations πŸ“”

Taiwan warned that popular Chineseowned apps, including TikTok and Weibo, are harvesting personal data and sending it back to servers in China.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” EU Launches Plan to Implement Quantum-Secure Infrastructure πŸ“”

The EUs Quantum Strategy includes plans to develop secure quantum communication infrastructure across the region.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” WordPress Plugin Flaw Exposes 600,000 Sites to File Deletion πŸ“”

A severe flaw identified in the Forminator WordPress plugin allows arbitrary file deletion and potential site takeover.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Privilege Escalation Flaw Found in Azure Machine Learning Service πŸ“”

A critical Azure Machine Learning flaw allows privilege escalation, risking subscription compromise.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” CVE Program Launches Two New Forums to Enhance CVE Utilization πŸ“”

The CVE Board has launched a Consumer Working Group and a Researcher Working Group, allowing new stakeholders to shape the future of the CVE Program.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Automation and Vulnerability Exploitation Drive Mass Ransomware Breaches πŸ“”

ReliaQuest warns that initial access vulnerability exploitation is driving successful ransomware attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” North Korean Hackers Target Crypto Firms with Novel macOS Malware πŸ“”

SentinelLabs observed North Korean actors deploying novel TTPs to target crypto firms, including a mix of programming languages and signalbased persistence.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Ransomware: Hunters International Is Not Shutting Down, It's Rebranding πŸ“”

Some admins of Hunters International are now part of the encryptionless cyber extortion group World Leaks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… The Week in Vulnerabilities: High-Risk IT and ICS Flaws Flagged by Cyble πŸ¦…

IT Vulnerabilities " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202507ITVulnerabilities2300x150.webp" datalargefile"httpscyble.comwpcontentuploads202507ITVulnerabilities2.webp" title"The Week in Vulnerabilities HighRisk IT and ICS Flaws Flagged by Cyble 1" Cyble vulnerability intelligence researchers investigated dozens of vulnerabilities this week to highlight the IT and industrial control system ICS vulnerabilities that security teams should prioritize.  Cyble honeypot sensors also detected numerous vulnerabilities under active exploitation, and Cyble dark web researchers observed several threat actors discussing vulnerability exploits on underground and cybercrime forums, including a claimed Apple zeroday.  What follows are some highlights from Cybles IT and...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity