πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.2K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks πŸ–‹οΈ

SonicWall on Wednesday disclosed that an unauthorized party accessed firewall configuration backup files for all customers who have used the cloud backup service. "The files contain encrypted credentials and configuration data while encryption remains in place, possession of these files could increase the risk of targeted attacks," the company said. It also noted that it's working to notify all.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ThreatsDay Bulletin: MS Teams Hack, MFA Hijacking, $2B Crypto Heist, Apple Siri Probe & More πŸ–‹οΈ

Cyber threats are evolving faster than ever. Attackers now combine social engineering, AIdriven manipulation, and cloud exploitation to breach targets once considered secure. From communication platforms to connected devices, every system that enhances convenience also expands the attack surface. This edition of ThreatsDay Bulletin explores these converging risks and the safeguards that help.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
πŸ–‹οΈ From HealthKick to GOVERSHELL: The Evolution of UTA0388's Espionage Malware πŸ–‹οΈ

A Chinaaligned threat actor codenamed UTA0388 has been attributed to a series of spearphishing campaigns targeting North America, Asia, and Europe that are designed to deliver a Gobased implant known as GOVERSHELL. "The initially observed campaigns were tailored to the targets, and the messages purported to be sent by senior researchers and analysts from legitimatesounding, completely.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps πŸ–‹οΈ

A rapidly evolving Android spyware campaign called ClayRat has targeted users in Russia using a mix of Telegram channels and lookalike phishing websites by impersonating popular apps like WhatsApp, Google Photos, TikTok, and YouTube as lures to install them. "Once active, the spyware can exfiltrate SMS messages, call logs, notifications, and device information taking photos with the front.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Why SIEM Alone Isn’t Enough: Lessons from a Fortune-500 Ransomware Breach 🌊

In December 2024, hackers slipped into our clients network without setting off any alarms. They went unnoticed until January 2025, when the attackers unleashed the ransomware breach and caused a The post Why SIEM Alone Isnt Enough Lessons from a Fortune500 Ransomware Breach appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw πŸ–‹οΈ

Dozens of organizations may have been impacted following the zeroday exploitation of a security flaw in Oracle's EBusiness Suite EBS software since August 9, 2025, Google Threat Intelligence Group GTIG and Mandiant said in a new report released Thursday. "We're still assessing the scope of this incident, but we believe it affected dozens of organizations," John Hultquist, chief analyst of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Rocketing number of ransomware groups as new, smaller players emerge πŸ“’

The good news is that the number of victims remains steady.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The AI SOC Stack of 2026: What Sets Top-Tier Platforms Apart? πŸ–‹οΈ

The SOC of 2026 will no longer be a humanonly battlefield. As organizations scale and threats evolve in sophistication and velocity, a new generation of AIpowered agents is reshaping how Security Operations Centers SOCs detect, respond, and adapt. But not all AI SOC platforms are created equal. From promptdependent copilots to autonomous, multiagent systems, the current market offers.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign πŸ–‹οΈ

Cybersecurity researchers have flagged a new set of 175 malicious packages on the npm registry that have been used to facilitate credential harvesting attacks as part of an unusual campaign. The packages have been collectively downloaded 26,000 times, acting as an infrastructure for a widespread phishing campaign codenamed Beamglea targeting more than 135 industrial, technology, and energy.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability πŸ–‹οΈ

Cybersecurity company Huntress said it has observed active inthewild exploitation of an unpatched security flaw impacting Gladinet CentreStack and TrioFox products. The zeroday vulnerability, tracked as CVE202511371 CVSS score 6.1, is an unauthenticated local file inclusion bug that allows unintended disclosure of system files. It impacts all versions of the software prior to and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Google Launches AI Bug Bounty with $30,000 Top Reward πŸ“”

Google has introduced a new AI Vulnerability Reward Program offering up to 30,000 for bug discoveries in its AI products.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Google: Clop Accessed β€œSignificant Amount” of Data in Oracle EBS Exploit πŸ“”

GTIG highlighted indicators that Clop is behind the extortion campaign targeting Oracle EBS instances, with its activity likely beginning as early as August 9.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Pro-Russia Hacktivists β€œClaim” Attack on Water Utility Honeypot πŸ“”

Forescout said that the TwoNet actor was lured into attacking a honeypot disguised as a water treatment utility, providing insights into the groups tactics.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 When a $6 Billion Business Faces Purple Team Testing: Human and Technical Gaps Exposed 🌊

On paper, a 6 billion food production company in the United States looked unwavering. Having a reliable global reputation, 10,000 employees on board, Palo Alto WildFire and Cortex XDR in The post When a 6 Billion Business Faces Purple Team Testing Human and Technical Gaps Exposed appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Cyber Threats in the EU Escalate as Diverse Groups Target Critical Sectors πŸ¦…

EU Threat Landscape " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202510EUThreatLandscape300x150.webp" datalargefile"httpscyble.comwpcontentuploads202510EUThreatLandscape1024x512.webp" title"Cyber Threats in the EU Escalate as Diverse Groups Target Critical Sectors 1" The European Union continues to face a complex web of cyber threats, according to the 2025 ENISA Threat Landscape report. Covering incidents from July 2024 through June 2025, the report details how a variety of threat actors are targeting the EUs digital infrastructure with overlapping tactics, highly technical attack models, and heightened collaboration. The EU Threat Landscape and Converging Threat Groups  ENISAs latest analysis, based on 4,875 recorded cybersecurity incidents, reveals a reuse of...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ From Detection to Patch: Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation πŸ–‹οΈ

Fortra on Thursday revealed the results of its investigation into CVE202510035, a critical security flaw in GoAnywhere Managed File Transfer MFT that's assessed to have come under active exploitation since at least September 11, 2025. The company said it began its investigation on September 11 following a "potential vulnerability" reported by a customer, uncovering "potentially suspicious.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Oberig IT Becomes the Official Distributor of UnderDefense Solutions 🌊

Oberig IT, a distributor of advanced integrated solutions in IT and cybersecurity, has signed a strategic distribution agreement with UnderDefense Cybersecurity, a global provider of cybersecurity services and solutions. The The post Oberig IT Becomes the Official Distributor of UnderDefense Solutions appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ 'Payroll Pirates' target US universities, Microsoft warns πŸ“’

Group uses simple but effective tactics to divert staff salaries to themselves.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Researchers sound alarm over AI hardware vulnerabilities that expose training data πŸ“’

Hackers can abuse flaws in AI accelerators to break AI privacy and a reliable fix could be years away.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers πŸ–‹οΈ

Cybersecurity researchers have disclosed details of an active malware campaign called Stealit that has leveraged Node.js' Single Executable Application SEA feature as a way to distribute its payloads. According to Fortinet FortiGuard Labs, select iterations have also employed the opensource Electron framework to deliver the malware. It's assessed that the malware is being propagated through.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Warns of β€˜Payroll Pirates’ Hijacking HR SaaS Accounts to Steal Employee Salaries πŸ–‹οΈ

A threat actor known as Storm2657 has been observed hijacking employee accounts with the end goal of diverting salary payments to attackercontrolled accounts. "Storm2657 is actively targeting a range of U.S.based organizations, particularly employees in sectors like higher education, to gain access to thirdparty human resources HR software as a service SaaS platforms like Workday," the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity