π’ Hackers stole source code, bug details in disastrous F5 security incident β hereβs everything we know and how to protect yourself π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
CISA has warned the F5 security incident presents a serious threat to federal networks.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Hackers stole source code, bug details in disastrous F5 security incident β hereβs everything we know and how to protect yourself
CISA has warned the F5 security incident presents a serious threat to federal networks
π’ Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
A new Google Careers phishing scam is targeting tech workers looking for a change of scenery here's how to stay safe.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change
Researchers say the scam is evolving fast, as attackers take measures to avoid detection
π’ Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
A new Google Careers phishing scam is targeting tech workers looking for a change of scenery here's how to stay safe.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change
Researchers say the scam is evolving fast, as attackers take measures to avoid detection
π’ Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
A new Google Careers phishing scam is targeting tech workers looking for a change of scenery here's how to stay safe.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change
Researchers say the scam is evolving fast, as attackers take measures to avoid detection
ποΈ North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A threat actor with ties to the Democratic People's Republic of Korea aka North Korea has been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a statesponsored hacking group has embraced the method. The activity has been attributed by Google Threat Intelligence Group GTIG to a threat cluster it tracks as UNC5342,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A threat actor with ties to the Democratic People's Republic of Korea aka North Korea has been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a statesponsored hacking group has embraced the method. The activity has been attributed by Google Threat Intelligence Group GTIG to a threat cluster it tracks as UNC5342,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A threat actor with ties to the Democratic People's Republic of Korea aka North Korea has been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a statesponsored hacking group has embraced the method. The activity has been attributed by Google Threat Intelligence Group GTIG to a threat cluster it tracks as UNC5342,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A financially motivated threat actor codenamed UNC5142 has been observed abusing blockchain smart contracts as a way to facilitate the distribution of information stealers such as Atomic AMOS, Lumma, Rhadamanthys aka RADTHIEF, and Vidar, targeting both Windows and Apple macOS systems. "UNC5142 is characterized by its use of compromised WordPress websites and 'EtherHiding,' a technique used.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
An investigation into the compromise of an Amazon Web Services AWShosted infrastructure has led to the discovery of a new GNULinux rootkit dubbed LinkPro, according to findings from Synacktiv. "This backdoor features functionalities relying on the installation of two eBPF extended Berkeley Packet Filter modules, on the one hand to conceal itself, and on the other hand to be remotely.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Architectures, Risks, and Adoption: How to Assess and Choose the Right AI-SOC Platform ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Scaling the SOC with AI Why now? Security Operations Centers SOCs are under unprecedented pressure. According to SACRs AISOC Market Landscape 2025, the average organization now faces around 960 alerts per day, while large enterprises manage more than 3,000 alerts daily from an average of 28 different tools. Nearly 40 of those alerts go uninvestigated, and 61 of security teams admit.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in "Zero Disco' Attacks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a new campaign that exploited a recently disclosed security flaw impacting Cisco IOS Software and IOS XE Software to deploy Linux rootkits on older, unprotected systems. The activity, codenamed Operation Zero Disco by Trend Micro, involves the weaponization of CVE202520352 CVSS score 7.7, a stack overflow vulnerability in the Simple.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Beware the Hidden Costs of Pen Testing ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Penetration testing helps organizations ensure IT systems are secure, but it should never be treated in a onesizefitsall approach. Traditional approaches can be rigid and cost your organization time and money while producing inferior results. The benefits of pen testing are clear. By empowering white hat hackers to attempt to breach your system using similar tools and techniques to.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The online world is changing fast. Every week, new scams, hacks, and tricks show how easy its become to turn everyday technology into a weapon. Tools made to help us work, connect, and stay safe are now being used to steal, spy, and deceive. Hackers dont always break systems anymore they use them. They hide inside trusted apps, copy real websites, and trick people into giving up control.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ CISA Flags Adobe AEM Flaw with Perfect 10.0 Score β Already Under Active Attack ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added a critical security flaw impacting Adobe Experience Manager to its Known Exploited Vulnerabilities KEV catalog, based on evidence of active exploitation. The vulnerability in question is CVE202554253 CVSS score 10.0, a maximumseverity misconfiguration bug that could result in arbitrary code execution.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Microsoft on Thursday disclosed that it revoked more than 200 certificates used by a threat actor it tracks as Vanilla Tempest to fraudulently sign malicious binaries in ransomware attacks. The certificates were "used in fake Teams setup files to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware," the Microsoft Threat Intelligence team said in a post shared on X. The tech.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π’ Thousands of exposed civil servant passwords are up for grabs online π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
While the password security failures are concerning, they pale in comparison to other nations.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Thousands of exposed civil servant passwords are up for grabs online
While the password security failures are concerning, they pale in comparison to other nations
π¦Ώ Microsoftβs Patch Tuesday: 172 Flaws Fixed π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
The tech titan is addressing 172 security flaws, including six zeroday vulnerabilities. Among these, eight are rated Critical, consisting of five remote code execution bugs and three elevation of privilege issues. The post Microsofts Patch Tuesday 172 Flaws Fixed appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Microsoftβs Patch Tuesday: 172 Flaws Fixed
The tech titan is addressing 172 security flaws, including six zero-day vulnerabilities.
βοΈ Email Bombs Exploit Lax Authentication in Zendesk βοΈ
π Read more.
π Via "Krebs on Security"
----------
ποΈ Seen on @cibsecurity
Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages that come from hundreds of Zendesk corporate customers simultaneously.π Read more.
π Via "Krebs on Security"
----------
ποΈ Seen on @cibsecurity
Krebs on Security
Email Bombs Exploit Lax Authentication in Zendesk
Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages that come from hundreds of Zendesk corporate customers simultaneously.
ποΈ Identity Security: Your First and Last Line of Defense ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The danger isnt that AI agents have bad days its that they never do. They execute faithfully, even when what theyre executing is a mistake. A single misstep in logic or access can turn flawless automation into a flawless catastrophe. This isn't some dystopian fantasyit's Tuesday at the office now. We've entered a new phase where autonomous AI agents act with serious system privileges. They.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a recently patched critical security flaw in WatchGuard Fireware that could allow unauthenticated attackers to execute arbitrary code. The vulnerability, tracked as CVE20259242 CVSS score 9.3, is described as an outofbounds write vulnerability affecting Fireware OS 11.10.2 up to and including 11.12.4Update1, 12.0 up to and including.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Prosper Data Breach Exposes 17 Million Customers' Personal Info π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The US lending platform said early investigations found no evidence of unauthorized account access or fund theft.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Prosper Data Breach Exposes 17 Million Customersβ Personal Info
The US lending platform said early investigations found no evidence of unauthorized account access or fund theft