πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ πŸ•΅οΈ Webinar: Discover and Control Shadow AI Agents in Your Enterprise Before Hackers Do πŸ–‹οΈ

Do you know how many AI agents are running inside your business right now? If the answer is not sure, youre not aloneand thats exactly the concern. Across industries, AI agents are being set up every day. Sometimes by IT, but often by business units moving fast to get results. That means agents are running quietly in the backgroundwithout proper IDs, without owners, and without logs of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage πŸ–‹οΈ

A Russian statesponsored cyber espionage group known as Static Tundra has been observed actively exploiting a sevenyearold security flaw in Cisco IOS and Cisco IOS XE software as a means to establish persistent access to target networks. Cisco Talos, which disclosed details of the activity, said the attacks single out organizations in telecommunications, higher education and manufacturing.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Pharmaceutical Company Inotiv Confirms Ransomware Attack πŸ“”

Indianabased pharmaceutical research company Inotiv has confirmed it suffered a ransomware attack, disrupting operations and compromising data.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks πŸ–‹οΈ

Apple has released security updates to address a security flaw impacting iOS, iPadOS, and macOS that it said has come under active exploitation in the wild. The zeroday outofbounds write vulnerability, tracked as CVE202543300, resides in the ImageIO framework that could result in memory corruption when processing a malicious image. "Apple is aware of a report that this issue may have been.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀3
πŸ–‹οΈ GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets πŸ–‹οΈ

Cybersecurity researchers are calling attention to multiple campaigns that leverage known security vulnerabilities and expose Redis servers to various malicious activities, including leveraging the compromised devices as IoT botnets, residential proxies, or cryptocurrency mining infrastructure. The first set of attacks entails the exploitation of CVE202436401 CVSS score 9.8, a critical.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ¦… SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh πŸ¦…

Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " dataimagecaption"Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " datamediumfile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot.jpg" title"SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh 1" Executive Summary Cyble Research and Intelligence Labs CRIL has uncovered an ongoing Android malware tracker named "SikkahBot," active since July 2024 and explicitly targeting students in Bangladesh. Disguised as applications from the Bangladesh Education Board, the malware lures victims with promises of scholarships, coerces them into sharing sensitive information, and grants highr...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fake IT Support Attacks Hit Microsoft Teams πŸ“”

Fake IT support lures are being used to trick employees into installing remoteaccess tools via Microsoft Teams.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ A notorious hacker group is ramping up cloud-based ransomware attacks πŸ“’

The Storm0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpointbased attacks and toward cloudbased ransomware.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh πŸ¦…

Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " dataimagecaption"Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " datamediumfile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot.jpg" title"SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh 1" Executive Summary Cyble Research and Intelligence Labs CRIL has uncovered an ongoing Android malware tracker named "SikkahBot," active since July 2024 and explicitly targeting students in Bangladesh. Disguised as applications from the Bangladesh Education Board, the malware lures victims with promises of scholarships, coerces them into sharing sensitive information, and grants highr...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Hackers are abusing ConnectWise ScreenConnect, again πŸ“’

A new spear phishing campaign has targeted more than 900 organizations with fake invitations from platforms like Zoom and Microsoft Teams.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh πŸ¦…

Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " dataimagecaption"Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " datamediumfile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot.jpg" title"SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh 1" Executive Summary Cyble Research and Intelligence Labs CRIL has uncovered an ongoing Android malware tracker named "SikkahBot," active since July 2024 and explicitly targeting students in Bangladesh. Disguised as applications from the Bangladesh Education Board, the malware lures victims with promises of scholarships, coerces them into sharing sensitive information, and grants highr...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh πŸ¦…

Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " dataimagecaption"Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " datamediumfile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot.jpg" title"SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh 1" Executive Summary Cyble Research and Intelligence Labs CRIL has uncovered an ongoing Android malware tracker named "SikkahBot," active since July 2024 and explicitly targeting students in Bangladesh. Disguised as applications from the Bangladesh Education Board, the malware lures victims with promises of scholarships, coerces them into sharing sensitive information, and grants highr...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Netherlands Confirms China's Salt Typhoon Targeted Small Dutch Telcos πŸ“”

Salt Typhoons primary Dutch targets were small internet service providers and hosting providers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fake IT Support Attacks Hit Microsoft Teams πŸ“”

Fake IT support lures are being used to trick employees into installing remoteaccess tools via Microsoft Teams.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ A notorious hacker group is ramping up cloud-based ransomware attacks πŸ“’

The Storm0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpointbased attacks and toward cloudbased ransomware.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Netherlands Confirms China's Salt Typhoon Targeted Small Dutch Telcos πŸ“”

Salt Typhoons primary Dutch targets were small internet service providers and hosting providers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh πŸ¦…

Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " dataimagecaption"Cyble SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh " datamediumfile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202508CybleBlogsSikkahbot.jpg" title"SikkahBot Malware Campaign Lures and Defrauds Students in Bangladesh 1" Executive Summary Cyble Research and Intelligence Labs CRIL has uncovered an ongoing Android malware tracker named "SikkahBot," active since July 2024 and explicitly targeting students in Bangladesh. Disguised as applications from the Bangladesh Education Board, the malware lures victims with promises of scholarships, coerces them into sharing sensitive information, and grants highr...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Malicious VS Code Extensions Exploit Name Reuse Loophole πŸ“”

Visual Studio Code extensions have been identified exploiting a loophole that allows reuse of names from removed packages.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google Identifies β€˜Widespread Data Theft’ Impacting Salesforce-Salesloft Drift Users 🦿

Google Threat Intelligence Group shared its findings about a threat actor responsible for stealing Salesforce customer data via Salesloft Drift.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Hackers are abusing ConnectWise ScreenConnect, again πŸ“’

A new spear phishing campaign has targeted more than 900 organizations with fake invitations from platforms like Zoom and Microsoft Teams.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fake IT Support Attacks Hit Microsoft Teams πŸ“”

Fake IT support lures are being used to trick employees into installing remoteaccess tools via Microsoft Teams.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity