πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.3K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a new attack called CometJacking targeting Perplexity's agentic AI browser Comet by embedding malicious prompts within a seemingly innocuous link to siphon sensitive data, including from connected services, like email and calendar. The sneaky prompt injection attack plays out in the form of a malicious link that, when clicked, triggers the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a new attack called CometJacking targeting Perplexity's agentic AI browser Comet by embedding malicious prompts within a seemingly innocuous link to siphon sensitive data, including from connected services, like email and calendar. The sneaky prompt injection attack plays out in the form of a malicious link that, when clicked, triggers the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day πŸ–‹οΈ

Threat intelligence firm GreyNoise disclosed on Friday that it has observed a spike in scanning activity targeting Palo Alto Networks login portals. The company said it observed a nearly 500 increase in IP addresses scanning Palo Alto Networks login portals on October 3, 2025, the highest level recorded in the last three months. It described the traffic as targeted and structured, and aimed.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day πŸ–‹οΈ

Threat intelligence firm GreyNoise disclosed on Friday that it has observed a spike in scanning activity targeting Palo Alto Networks login portals. The company said it observed a nearly 500 increase in IP addresses scanning Palo Alto Networks login portals on October 3, 2025, the highest level recorded in the last three months. It described the traffic as targeted and structured, and aimed.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day πŸ–‹οΈ

Threat intelligence firm GreyNoise disclosed on Friday that it has observed a spike in scanning activity targeting Palo Alto Networks login portals. The company said it observed a nearly 500 increase in IP addresses scanning Palo Alto Networks login portals on October 3, 2025, the highest level recorded in the last three months. It described the traffic as targeted and structured, and aimed.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 CrowdStrike vs. SentinelOne (2025): Who’s Building the Better AI SOC Brain? 🌊

CrowdStrike and SentinelOne are both strapping AI boosters onto the SOC engine. Same destination faster, smarter defense. But they fly in totally different airspace. Lets unpack CrowdStrike vs. SentinelOne whos The post CrowdStrike vs. SentinelOne 2025 Whos Building the Better AI SOC Brain? appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Palo Alto Networks vs. SentinelOne: Who Offers Better AI SOC Models in 2025? 🌊

Youre not choosing between toys. Palo Alto Networks and SentinelOne are the strongest players in AIaugmented SOC. The real debate is which operating model you want to live with Palo The post Palo Alto Networks vs. SentinelOne Who Offers Better AI SOC Models in 2025? appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Oracle patches EBS amid extortion attacks πŸ“’

Red alert Companies told to drop everything and take action now.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ TD Synnex adds Boxphish security awareness training to UK&I portfolio πŸ“’

Partners can now provide customers with Boxphish's security training, combined with phishing simulations and dark web monitoring services.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Agentic AI poses major challenge for security professionals, says Palo Alto Networks’ EMEA CISO πŸ“’

Runtime security and employee oversight are necessary to achieve success with AI agents, according to Haider Pasha.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely πŸ–‹οΈ

Redis has disclosed details of a maximumseverity security flaw in its inmemory database software that could result in remote code execution under certain circumstances. The vulnerability, tracked as CVE202549844 aka RediShell, has been assigned a CVSS score of 10.0. "An authenticated user may use a specially crafted Lua script to manipulate the garbage collector, trigger a useafterfree,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware πŸ–‹οΈ

Microsoft on Monday attributed a threat actor it tracks as Storm1175 to the exploitation of a critical security flaw in Fortra GoAnywhere software to facilitate the deployment of Medusa ransomware. The vulnerability is CVE202510035 CVSS score 10.0, a critical deserialization bug that could result in command injection without authentication. It was addressed in version 7.8.4, or the Sustain.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks πŸ–‹οΈ

CrowdStrike on Monday said it's attributing the exploitation of a recently disclosed security flaw in Oracle EBusiness Suite with moderate confidence to a threat actor it tracks as Graceful Spider aka Cl0p, and that the first known exploitation occurred on August 9, 2025. The exploitation involves the exploitation of CVE202561882 CVSS score 9.8, a critical vulnerability that facilitates.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations πŸ–‹οΈ

A Chinese company named the Beijing Institute of Electronics Technology and Application BIETA has been assessed to be likely led by the Ministry of State Security MSS. The assessment comes from evidence that at least four BIETA personnel have clear or possible links to MSS officers and their relationship with the University of International Relations, which is known to share links with the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More πŸ–‹οΈ

The cyber world never hits pause, and staying alert matters more than ever. Every week brings new tricks, smarter attacks, and fresh lessons from the field. This recap cuts through the noise to share what really matterskey trends, warning signs, and stories shaping todays security landscape. Whether youre defending systems or just keeping up, these highlights help you spot whats coming.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 5 Critical Questions For Adopting an AI Security Solution πŸ–‹οΈ

In the era of rapidly advancing artificial intelligence AI and cloud technologies, organizations are increasingly implementing security measures to protect sensitive data and ensure regulatory compliance. Among these measures, AISPM AI Security Posture Management solutions have gained traction to secure AI pipelines, sensitive data assets, and the overall AI ecosystem. These solutions help.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks πŸ–‹οΈ

Oracle has released an emergency update to address a critical security flaw in its EBusiness Suite software that it said has been exploited in the recent wave of Cl0p data theft attacks. The vulnerability, tracked as CVE202561882 CVSS score 9.8, concerns an unspecified bug that could allow an unauthenticated attacker with network access via HTTP to compromise and take control of the Oracle.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers πŸ–‹οΈ

Cybersecurity researchers have shed light on a Chinesespeaking cybercrime group codenamed UAT8099 that has been attributed to search engine optimization SEO fraud and theft of highvalue credentials, configuration files, and certificate data.  The attacks are designed to target Microsoft Internet Information Services IIS servers, with most of the infections reported in India, Thailand.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCSC: Patch Critical Oracle EBS Bug Now πŸ“”

A critical Oracle EBusiness Suite vulnerability is being actively exploited by the Clop ransomware group.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft: Critical GoAnywhere Bug Exploited in Medusa Ransomware Campaign πŸ“”

A critical GoAnywhere vulnerability is being exploited by the Medusa ransomware group, says Microsoft.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Europol Calls for Stronger Data Laws to Combat Cybercrime πŸ“”

Europols Cybercrime Conference has warned that cybercriminals are exploiting new technologies faster than law enforcement can adapt.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity