πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.3K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks πŸ–‹οΈ

CrowdStrike on Monday said it's attributing the exploitation of a recently disclosed security flaw in Oracle EBusiness Suite with moderate confidence to a threat actor it tracks as Graceful Spider aka Cl0p, and that the first known exploitation occurred on August 9, 2025. The exploitation involves the exploitation of CVE202561882 CVSS score 9.8, a critical vulnerability that facilitates.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations πŸ–‹οΈ

A Chinese company named the Beijing Institute of Electronics Technology and Application BIETA has been assessed to be likely led by the Ministry of State Security MSS. The assessment comes from evidence that at least four BIETA personnel have clear or possible links to MSS officers and their relationship with the University of International Relations, which is known to share links with the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More πŸ–‹οΈ

The cyber world never hits pause, and staying alert matters more than ever. Every week brings new tricks, smarter attacks, and fresh lessons from the field. This recap cuts through the noise to share what really matterskey trends, warning signs, and stories shaping todays security landscape. Whether youre defending systems or just keeping up, these highlights help you spot whats coming.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 5 Critical Questions For Adopting an AI Security Solution πŸ–‹οΈ

In the era of rapidly advancing artificial intelligence AI and cloud technologies, organizations are increasingly implementing security measures to protect sensitive data and ensure regulatory compliance. Among these measures, AISPM AI Security Posture Management solutions have gained traction to secure AI pipelines, sensitive data assets, and the overall AI ecosystem. These solutions help.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks πŸ–‹οΈ

Oracle has released an emergency update to address a critical security flaw in its EBusiness Suite software that it said has been exploited in the recent wave of Cl0p data theft attacks. The vulnerability, tracked as CVE202561882 CVSS score 9.8, concerns an unspecified bug that could allow an unauthenticated attacker with network access via HTTP to compromise and take control of the Oracle.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers πŸ–‹οΈ

Cybersecurity researchers have shed light on a Chinesespeaking cybercrime group codenamed UAT8099 that has been attributed to search engine optimization SEO fraud and theft of highvalue credentials, configuration files, and certificate data.  The attacks are designed to target Microsoft Internet Information Services IIS servers, with most of the infections reported in India, Thailand.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCSC: Patch Critical Oracle EBS Bug Now πŸ“”

A critical Oracle EBusiness Suite vulnerability is being actively exploited by the Clop ransomware group.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft: Critical GoAnywhere Bug Exploited in Medusa Ransomware Campaign πŸ“”

A critical GoAnywhere vulnerability is being exploited by the Medusa ransomware group, says Microsoft.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Europol Calls for Stronger Data Laws to Combat Cybercrime πŸ“”

Europols Cybercrime Conference has warned that cybercriminals are exploiting new technologies faster than law enforcement can adapt.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Ransomware Group β€œTrinity of Chaos” Launches Data Leak Site πŸ“”

A new TOR data leak site published by the Trinity of Chaos ransomware group unveils 39 firms data and threatens Salesforce litigation.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Scanning of Palo Alto Portals Surges 500% πŸ“”

Experts warn that threat actors may be gearing up for compromise after large uptick in scans of Palo Alto Network portals.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Asahi Confirms Ransomware Attack, Data Stolen from Servers πŸ“”

Asahi confirmed it has fallen victim to a ransomware attack, and revealed it has started manual order processing amid ongoing operational disruption.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Renault Informs Customers of Supply Chain Data Breach πŸ“”

Renault and Dacia have become the latest bigname brands to suffer a supply chain breach.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Cybersecurity Technical Debt: Risks, Impacts, and Strategies Explained 🌊

Starting the journey to a secure organisation is like fixing a broken lock on your front door you can ignore it and save time today, but every day you wait The post Cybersecurity Technical Debt Risks, Impacts, and Strategies Explained appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 From $67M in Losses to Zero Ransom Paid: A Ransomware Rescue Case 🌊

How ransomware removal experts recovered critical systems and prevented longterm damage to business. The post From 67M in Losses to Zero Ransom Paid A Ransomware Rescue Case appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Cybersecurity Awareness Month 2025: Don’t Just Be Aware, Be Ahead πŸ¦…

Cybersecurity Awareness Month 2025 " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202510CybersecurityAwarenessMonth2025300x150.webp" datalargefile"httpscyble.comwpcontentuploads202510CybersecurityAwarenessMonth2025.webp" title"Cybersecurity Awareness Month 2025 Don't Just Be Aware, Be Ahead   1" Every October, the cybersecurity world comes together to mark Cybersecurity Awareness Month. Organizations send out reminders. Security teams run training sessions. Everyone emphasizes the importance of creating strong passwords and recognizing phishing emails. And yet, here's the uncomfortable truth despite all this awareness, we're still losing ground.  Too many incident response calls start with someone saying, "We knew this could happen." That's the problem right there....

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Research: AI Is Already the #1 Data Exfiltration Channel in the Enterprise πŸ–‹οΈ

For years, security leaders have treated artificial intelligence as an emerging technology, something to keep an eye on but not yet missioncritical. A new Enterprise AI and SaaS Data Security Report by AI Browser Security company LayerX proves just how outdated that mindset has become. Far from a future concern, AI is already the single largest uncontrolled channel for corporate data.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities πŸ–‹οΈ

Cybersecurity researchers have charted the evolution of XWorm malware, turning it into a versatile tool for supporting a wide range of malicious actions on compromised hosts. "XWorm's modular design is built around a core client and an array of specialized components known as plugins," Trellix researchers Niranjan Hegde and Sijo Jacob said in an analysis published last week. "These plugins are.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Discord Reveals Data Breach Following Third-Party Compromise πŸ“”

Discord said a thirdparty customer services provider was compromised to access user data, with the attackers aiming to extort a financial ransom.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Critical Flaw Exposes 60,000 Redis Servers to Remote Exploitation πŸ“”

A critical Redis flaw, dubbed RediShell, has exposed 60,000 unprotected servers to exploitation.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Qilin Claims Ransomware Attack on Mecklenburg Schools πŸ“”

The Qilin ransomware gang has claimed attacks at Mecklenburg County Public Schools, stealing financial records and childrens medical files.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity