πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” 1 in 3 Android Apps Leak Sensitive Data πŸ“”

One third of Android and over half iOS apps shown to be leaking insecure APIs and hardcoded secrets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” SonicWall Discloses Compromise of Cloud Backup Service πŸ“”

SonicWall said that threat actors accessed firewall preference files stored in the cloud for around 5 of its firewall install base.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” VC Firm Insight Partners Notifies Victims After Ransomware Breach πŸ“”

Insight Partners has released more details of a 2024 ransomware breach impacting thousands of individuals.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCA Singles Out β€œThe Com” as it Chairs Five Eyes Group πŸ“”

The UKs National Crime Agency is the new chair of the Five Eyes Law Enforcement Group.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Ransomware Landscape August 2025: Qilin Dominates as Sinobi Emerges πŸ¦…

In August, Qilin was the most active ransomware group for the fourth time in five months, while a new ransomware group is quickly moving up the ranks.  Qilins 104 claimed victims in August were nearly double secondplace Akiras 56, but the rapid rise of Sinobi to third place has been one of the more intriguing recent developments in the ransomware landscape chart below.   The dominance of Qilin and the rise of Sinobi were among the revelations in Cybles latest global threat landscape report, which also documents a surge in supply chain and critical infrastructure attacks, among other findings.  Ransomware attacks rose to 467 in August, the fourth straight monthly increase, even as attack totals remain well below Februarys record chart below. Several attacks had significant sup...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader πŸ–‹οΈ

Cybersecurity researchers have discovered a new malware loader codenamed CountLoader that has been put to use by Russian ransomware gangs to deliver postexploitation tools like Cobalt Strike and AdaptixC2, and a remote access trojan known as PureHVNC RAT. "CountLoader is being used either as part of an Initial Access Broker's IAB toolset or by a ransomware affiliate with ties to the LockBit,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers πŸ–‹οΈ

SonicWall is urging customers to reset credentials after their firewall configuration backup files were exposed in a security breach impacting MySonicWall accounts. The company said it recently detected suspicious activity targeting the cloud backup service for firewalls, and that unknown threat actors accessed backup firewall preference files stored in the cloud for less than 5 of its.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” New York Blood Center Alerts 194,000 People to Data Breach πŸ“”

A breach at the New York Blood Center resulted in theft of data for 194,000 people, including SSNs, IDs, bank and health information.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The top ransomware trends for businesses in 2025 πŸ“’

A splintering of top groups and changing attitudes toward payments are changing attacker tactics at speed.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Pair of Suspected Scattered Spider Hackers Charged by UK, US Authorities πŸ“”

One of the teenage suspects is accused of involvement in at least 120 attacks, resulting in 115m in ransom payments.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428 πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Thursday released details of two sets of malware that were discovered in an unnamed organization's network following the exploitation of security flaws in Ivanti Endpoint Manager Mobile EPMM. "Each set contains loaders for malicious listeners that enable cyber threat actors to run arbitrary code on the compromised server,".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack πŸ–‹οΈ

Law enforcement authorities in the U.K. have arrested two teen members of the Scattered Spider hacking group in connection with their alleged participation in an August 2024 cyber attack targeting Transport for London TfL, the city's public transportation agency. Thalha Jubair aka EarthtoStar, Brad, Austin, and autistic, 19, from East London and Owen Flowers, 18, from Walsall, West Midlands.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The Salesloft hackers claim they have 1.5 billion compromised Salesforce records πŸ“’

Dozens of big tech companies have been impacted by the Salesloft Drift attacks.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines πŸ–‹οΈ

Run by the team at workflow orchestration and AI platform Tines, the Tines library features over 1,000 prebuilt workflows shared by security practitioners from across the community all free to import and deploy through the platform's Community Edition. The workflow we are highlighting streamlines security alert handling by automatically identifying and executing the appropriate Standard.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine πŸ–‹οΈ

Cybersecurity researchers have discerned evidence of two Russian hacking groups Gamaredon and Turla collaborating together to target and cocomprise Ukrainian entities. Slovak cybersecurity company ESET said it observed the Gamaredon tools PteroGraphin and PteroOdd being used to execute Turla group's Kazuar backdoor on an endpoint in Ukraine in February 2025, indicating that Turla is very likely.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Small businesses, big targets: Protecting your business against ransomware πŸš€

Long known to be a sweet spot for cybercriminals, small businesses are more likely to be victimized by ransomware than large enterprises.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Zero-Click Vulnerability in ChatGPT's Agent Enables Silent Gmail Data Theft πŸ“”

Researchers at Radware found a zeroclick flaw in ChatGPT Deep Research agent when connected to Gmail and browsing.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Attackers Abuse AI Tools to Generate Fake CAPTCHAs in Phishing Attacks πŸ“”

Trend Micro said the use of AI platforms to create and host fake CAPTCHA pages helps attackers develop more sophisticated phishing campaigns at scale and speed.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Lawyer 🌊

The post Lawyer appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Russian State Hackers Collaborate in Attacks Against Ukraine πŸ“”

ESET found that the FSBaffiliated groups, Gamaredon and Turla, are sharing tools to help conduct espionage attacks against Ukrainian organizations.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ 17,500 Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge πŸ–‹οΈ

The phishingasaservice PhaaS offering known as Lighthouse and Lucid has been linked to more than 17,500 phishing domains targeting 316 brands from 74 countries. "PhishingasaService PhaaS deployments have risen significantly recently," Netcraft said in a new report. "The PhaaS operators charge a monthly fee for phishing software with preinstalled templates impersonating, in some cases,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity