πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.2K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🌊 9 ReliaQuest Alternatives for AI‑Driven SOC in 2025 🌊

This guide breaks down the top ReliaQuest alternatives. Below are 9 AI SOC platforms that offer a path forward whether you want true MDR, stronger automation, or smarter detection coverage. For The post 9 ReliaQuest Alternatives for AIDriven SOC in 2025 appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Sophos vs. Cisco-Splunk Ecosystem (2025): XDR Copilot vs. Agentic SOC 🌊

Sophos vs. CiscoSplunk is a clash of AI philosophies in SecOps. Sophos drops an AI copilot into your XDR, speeding human judgment where investigations actually happen. Cisco and Splunk wire The post Sophos vs. CiscoSplunk Ecosystem 2025 XDR Copilot vs. Agentic SOC appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a new Rustbased backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts. "Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an overprivileged Active Directory account named, 'serviceaccount,'" eSentire said in a technical report published.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns πŸ–‹οΈ

Cybersecurity researchers are calling attention to a new campaign that delivers the Astaroth banking trojan that employs GitHub as a backbone for its operations to stay resilient in the face of infrastructure takedowns. "Instead of relying solely on traditional commandandcontrol C2 servers that can be taken down, these attackers are leveraging GitHub repositories to host malware.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” FBI and French Police Shutter BreachForums Domain Again πŸ“”

The infamous BreachForums site has been taken offline again to disrupt Scattered Lapsus Hunters.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Third time lucky? The FBI just took down BreachForums, again πŸ“’

The hacking forum is down for now, but the group behind it, Scattered Lapsus Hunters, isn't going to stop extorting victims of the Salesforce breach.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Microsoft says 71% of workers have used unapproved AI tools at work – and it’s a trend that enterprises need to crack down on πŸ“’

Shadow AI is by no means a new trend, but its creating significant risks for enterprises.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More πŸ–‹οΈ

Every week, the cyber world reminds us that silence doesnt mean safety. Attacks often begin quietly one unpatched flaw, one overlooked credential, one backup left unencrypted. By the time alarms sound, the damage is done. This weeks edition looks at how attackers are changing the game linking different flaws, working together across borders, and even turning trusted tools into weapons.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk πŸ–‹οΈ

Think your WAF has you covered? Think again. This holiday season, unmonitored JavaScript is a critical oversight allowing attackers to steal payment data while your WAF and intrusion detection systems see nothing. With the 2025 shopping season weeks away, visibility gaps must close now. Get the complete Holiday Season Security Playbook here. Bottom Line Up Front The 2024 holiday season saw major.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors πŸ–‹οΈ

Malware campaigns distributing the RondoDox botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30 vendors. The activity, described as akin to an "exploit shotgun" approach, has singled out a wide range of internetexposed infrastructure, including routers, digital video recorders DVRs, network video recorders NVRs, CCTV systems, web servers, and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor πŸ–‹οΈ

Microsoft said it has revamped the Internet Explorer IE mode in its Edge browser after receiving "credible reports" in August 2025 that unknown threat actors were abusing the backward compatibility feature to gain unauthorized access to users' devices. "Threat actors were leveraging basic social engineering techniques alongside unpatched 0day exploits in Internet Explorer's JavaScript.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New Stealit Malware Campaign Spreads via VPN and Game Installer Apps πŸ“”

A new campaign distributing the Stealit infostealer employs previously unknown malware delivery techniques and infrastructure.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Apple Bug Bounty Payouts Can Now Top $5m πŸ“”

Apple has doubled its top bug bounty reward to 2m but with bonuses it could reach 5m.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Exabeam vs. Anvilogic: The 2025 AI SOC Face-Off 🌊

This Exabeam vs. Anvilogic comparison is by someone whos spent too many late nights wrestling with broken detections and watching vendors pitch SOCless futures from AIpowered podiums. Key Takeaways Exabeam The post Exabeam vs. Anvilogic The 2025 AI SOC FaceOff appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Spain Arrests Alleged Leader of GXC Team Cybercrime Network πŸ“”

Spanish authorities have arrested a 25yearold Brazilian accused of leading the GXC Team and selling malware and AI tools to cybercriminals.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“” Hackers Target ScreenConnect Features For Network Intrusions πŸ“”

A rise in attacks exploiting RMM tools like ScreenConnect enables system control via phishing tactics.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Critical Oracle EBS Flaw Could Expose Sensitive Data 🦿

Oracle patches a highseverity EBS flaw that could let attackers bypass authentication and access sensitive enterprise data. The post Critical Oracle EBS Flaw Could Expose Sensitive Data appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Critical Oracle EBS Flaw Could Expose Sensitive Data 🦿

Oracle patches a highseverity EBS flaw that could let attackers bypass authentication and access sensitive enterprise data. The post Critical Oracle EBS Flaw Could Expose Sensitive Data appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 UK experiencing four 'nationally significant' cyber attacks every week 🚨

Latest Annual Review reveals that the cyber threats facing the UK continue to escalate.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 Small businesses to receive cyber security boost with new toolkit from experts 🚨

NCSC CEO unveils a new Cyber Action Toolkit at the NCSCs Annual Review launch with clear message to small businesses that it is time to act.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence πŸ“”

Trend Micro have reported a campaign exploiting a flaw in Cisco SNMP to install Linux rootkits on devices.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity