πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.3K subscribers
90K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Singapore Officials Impersonated in Sophisticated Investment Scam πŸ“”

GroupIB has uncovered a scam operation impersonating Singapore officials using Google Ads and deepfakes.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Ransomware Payouts Surge to $3.6m Amid Evolving Tactics πŸ“”

According to ExtraHops latest threat landscape report, average ransomware payments surged 44 to 3.6m in 2025 despite fewer incidents.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Singapore Officials Impersonated in Sophisticated Investment Scam πŸ“”

GroupIB has uncovered a scam operation impersonating Singapore officials using Google Ads and deepfakes.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Singapore Officials Impersonated in Sophisticated Investment Scam πŸ“”

GroupIB has uncovered a scam operation impersonating Singapore officials using Google Ads and deepfakes.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Ransomware Payouts Surge to $3.6m Amid Evolving Tactics πŸ“”

According to ExtraHops latest threat landscape report, average ransomware payments surged 44 to 3.6m in 2025 despite fewer incidents.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft's July Patch πŸ–‹οΈ

Threat actors with ties to China exploited the ToolShell security vulnerability in Microsoft SharePoint to breach a telecommunications company in the Middle East after it was publicly disclosed and patched in July 2025. Also targeted were government departments in an African country, as well as government agencies in South America, a university in the U.S., as well as likely a state technology.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Bridging the Remediation Gap: Introducing Pentera Resolve πŸ–‹οΈ

From Detection to Resolution Why the Gap Persists A critical vulnerability is identified in an exposed cloud asset. Within hours, five different tools alert you about it your vulnerability scanner, XDR, CSPM, SIEM, and CMDB each surface the issue in their own way, with different severity levels, metadata, and context. Whats missing is a system of action. How do you transition from the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys πŸ–‹οΈ

Cybersecurity researchers have uncovered a new supply chain attack targeting the NuGet package manager with malicious typosquats of Nethereum, a popular Ethereum .NET integration platform, to steal victims' cryptocurrency wallet keys. The package, Netherum.All, has been found to harbor functionality to decode a commandandcontrol C2 endpoint and exfiltrate mnemonic phrases, private keys, and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Why You Should Swap Passwords for Passphrases πŸ–‹οΈ

The advice didn't change for decades use complex passwords with uppercase, lowercase, numbers, and symbols. The idea is to make passwords harder for hackers to crack via brute force methods. But more recent guidance shows our focus should be on password length, rather than complexity. Length is the more important security factor, and passphrases are the simplest way to get your users to create.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Identify PassiveNeuron APT Using Neursite and NeuralExecutor Malware πŸ–‹οΈ

Government, financial, and industrial organizations located in Asia, Africa, and Latin America are the target of a new campaign dubbed PassiveNeuron, according to findings from Kaspersky. The cyber espionage activity was first flagged by the Russian cybersecurity vendor in November 2024, when it disclosed a set of attacks aimed at government entities in Latin America and East Asia in June, using.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a highseverity flaw impacting the popular asynctar Rust library and its forks, including tokiotar, that could result in remote code execution under certain conditions. The vulnerability, tracked as CVE202562518 CVSS score 8.1, has been codenamed TARmageddon by Edera, which discovered the issue in late August 2025. It impacts several.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ TP-Link Patches Four Omada Gateway Flaws, Two Allow Remote Code Execution πŸ–‹οΈ

TPLink has released security updates to address four security flaws impacting Omada gateway devices, including two critical bugs that could result in arbitrary code execution. The vulnerabilities in question are listed below CVE20256541 CVSS score 8.6 An operating system command injection vulnerability that could be exploited by an attacker who can log in to the web management.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams πŸ–‹οΈ

Meta on Tuesday said it's launching new tools to protect Messenger and WhatsApp users from potential scams. To that end, the company said it's introducing new warnings on WhatsApp when users attempt to share their screen with an unknown contact during a video call so as to prevent them from giving away sensitive information like bank details or verification codes. On Messenger, users can opt to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ PolarEdge Targets Cisco, ASUS, QNAP, Synology Routers in Expanding Botnet Campaign πŸ–‹οΈ

Cybersecurity researchers have shed light on the inner workings of a botnet malware called PolarEdge. PolarEdge was first documented by Sekoia in February 2025, attributing it to a campaign targeting routers from Cisco, ASUS, QNAP, and Synology with the goal of corralling them into a network for an asyetundetermined purpose. The TLSbased ELF implant, at its core, is designed to monitor.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” JLR Hack UK's Costliest Ever, Hitting Economy with Β£1.9bn Loss πŸ“”

The Cyber Monitoring Centre has classified the cyberattack against Jaguar Land Rover as a systemic cyber event.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Scattered Lapsus$ Hunters Signal Shift in Tactics πŸ“”

Scattered Lapsus Hunters may be preparing to launch an extortionasaservice model, according to Palo Alto Networks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Singapore Officials Impersonated in Sophisticated Investment Scam πŸ“”

GroupIB has uncovered a scam operation impersonating Singapore officials using Google Ads and deepfakes.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ AI-generated code is now the cause of one-in-five breaches – but developers and security leaders alike are convinced the technology will come good eventually πŸ“’

AI coding tools now write 24 of production code globally, but it's risky and causing issues for developers and security practitioners alike.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bare πŸ“’

Researchers said they place the UK financial impact of the attack on Jaguar Land Rover at around 1.9 billion.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Dataminr to Acquire Cybersecurity Firm ThreatConnect in $290M Deal 🦿

The acquisition aims to merge Dataminrs AIdriven realtime event detection with ThreatConnects internal threat management capabilities. The post Dataminr to Acquire Cybersecurity Firm ThreatConnect in 290M Deal appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” PhantomCaptcha Campaign Targets Ukraine Relief Organizations πŸ“”

SentinelLABS Researchers have uncovered a new phishing campaign, PhantomCaptcha, targeting aid organizations supporting Ukraine.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity