πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.4K subscribers
90K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ TP-Link Patches Four Omada Gateway Flaws, Two Allow Remote Code Execution πŸ–‹οΈ

TPLink has released security updates to address four security flaws impacting Omada gateway devices, including two critical bugs that could result in arbitrary code execution. The vulnerabilities in question are listed below CVE20256541 CVSS score 8.6 An operating system command injection vulnerability that could be exploited by an attacker who can log in to the web management.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams πŸ–‹οΈ

Meta on Tuesday said it's launching new tools to protect Messenger and WhatsApp users from potential scams. To that end, the company said it's introducing new warnings on WhatsApp when users attempt to share their screen with an unknown contact during a video call so as to prevent them from giving away sensitive information like bank details or verification codes. On Messenger, users can opt to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ PolarEdge Targets Cisco, ASUS, QNAP, Synology Routers in Expanding Botnet Campaign πŸ–‹οΈ

Cybersecurity researchers have shed light on the inner workings of a botnet malware called PolarEdge. PolarEdge was first documented by Sekoia in February 2025, attributing it to a campaign targeting routers from Cisco, ASUS, QNAP, and Synology with the goal of corralling them into a network for an asyetundetermined purpose. The TLSbased ELF implant, at its core, is designed to monitor.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” JLR Hack UK's Costliest Ever, Hitting Economy with Β£1.9bn Loss πŸ“”

The Cyber Monitoring Centre has classified the cyberattack against Jaguar Land Rover as a systemic cyber event.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Scattered Lapsus$ Hunters Signal Shift in Tactics πŸ“”

Scattered Lapsus Hunters may be preparing to launch an extortionasaservice model, according to Palo Alto Networks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Singapore Officials Impersonated in Sophisticated Investment Scam πŸ“”

GroupIB has uncovered a scam operation impersonating Singapore officials using Google Ads and deepfakes.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ AI-generated code is now the cause of one-in-five breaches – but developers and security leaders alike are convinced the technology will come good eventually πŸ“’

AI coding tools now write 24 of production code globally, but it's risky and causing issues for developers and security practitioners alike.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bare πŸ“’

Researchers said they place the UK financial impact of the attack on Jaguar Land Rover at around 1.9 billion.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Dataminr to Acquire Cybersecurity Firm ThreatConnect in $290M Deal 🦿

The acquisition aims to merge Dataminrs AIdriven realtime event detection with ThreatConnects internal threat management capabilities. The post Dataminr to Acquire Cybersecurity Firm ThreatConnect in 290M Deal appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” PhantomCaptcha Campaign Targets Ukraine Relief Organizations πŸ“”

SentinelLABS Researchers have uncovered a new phishing campaign, PhantomCaptcha, targeting aid organizations supporting Ukraine.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” MuddyWater Uses Compromised Mailboxes in Global Phishing Campaign πŸ“”

GroupIB has uncovered a phishing campaign by Iranlinked MuddyWater, exploiting compromised emails for foreign intelligence.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Canada Fines Cybercrime Friendly Cryptomus $176M β™ŸοΈ

Financial regulators in Canada this week levied 176 million in fines against Cryptomus, a digital payments platform that supports dozens of Russian cryptocurrency exchanges and websites hawking cybercrime services. The penalties for violating Canada's anti moneylaundering laws come ten months after KrebsOnSecurity noted that Cryptomus's Vancouver street address was home to dozens of foreign currency dealers, money transfer businesses, and cryptocurrency exchanges none of which were physically located there.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign πŸ–‹οΈ

The Iranian nationstate group known as MuddyWater has been attributed to a new campaign that has leveraged a compromised email account to distribute a backdoor called Phoenix to various organizations across the Middle East and North Africa MENA region, including over 100 government entities. The end goal of the campaign is to infiltrate highvalue targets and facilitate intelligence gathering.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Files πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a coordinated spearphishing campaign dubbed PhantomCaptcha targeting organizations associated with Ukraine's war relief efforts to deliver a remote access trojan that uses a WebSocket for commandandcontrol C2. The activity, which took place on October 8, 2025, targeted individual members of the International Red Cross, Norwegian Refugee.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw πŸ–‹οΈ

Ecommerce security company Sansec has warned that threat actors have begun to exploit a recently disclosed security vulnerability in Adobe Commerce and Magento Open Source platforms, with more than 250 attack attempts recorded against multiple stores over the past 24 hours. The vulnerability in question is CVE202554236 CVSS score 9.1, a critical improper input validation flaw that could be.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added a critical security flaw impacting Motex Lanscope Endpoint Manager to its Known Exploited Vulnerabilities KEV catalog, stating it has been actively exploited in the wild. The vulnerability, CVE202561932 CVSS v4 score 9.3, impacts onpremises versions of Lanscope Endpoint Manager, specifically Client.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ What is memory forensics? πŸ“’

Once used to recover encrypted data, memory forensics is now a core tool in the fight against rootkits.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Warning issued over critical flaws spotted in TP-Link routers πŸ“’

Researchers have spotted a pair of flaws in TPLink routers, including a variation of a previously patched vulnerability.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Master IT Fundamentals with This CompTIA Certification Prep Bundle 🦿

Prepare for a successful IT career with lifetime access to expertled courses covering CompTIA A, Network, Security, and Cloud certification prep. The post Master IT Fundamentals with This CompTIA Certification Prep Bundle appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Why Organizations Are Abandoning Static Secrets for Managed Identities πŸ–‹οΈ

As machine identities explode across cloud environments, enterprises report dramatic productivity gains from eliminating static credentials. And only legacy systems remain the weak link. For decades, organizations have relied on static secrets, such as API keys, passwords, and tokens, as unique identifiers for workloads. While this approach provides clear traceability, it creates what security.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ β€œJingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards πŸ–‹οΈ

Cybersecurity researchers have shed light on a cybercriminal group called Jingle Thief that has been observed targeting cloud environments associated with organizations in the retail and consumer services sectors for gift card fraud. "Jingle Thief attackers use phishing and smishing to steal credentials, to compromise organizations that issue gift cards," Palo Alto Networks Unit 42 researchers.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity