πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.4K subscribers
90K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Lumma Stealer Vacuum Filled by Upgraded Vidar 2.0 Infostealer, Researchers Say πŸ“”

Trend Micro believe security teams should anticipate increased Vidar 2.0 prevalence in campaigns through Q4 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Secure AI at Scale and Speed β€” Learn the Framework in this Free Webinar πŸ–‹οΈ

AI is everywhereand your company wants in. Faster products, smarter systems, fewer bottlenecks. But if you're in security, that excitement often comes with a sinking feeling. Because while everyone else is racing ahead, you're left trying to manage a growing web of AI agents you didnt create, cant fully see, and werent designed to control. Join our upcoming webinar and learn how to make AI.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ThreatsDay Bulletin: $176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More πŸ–‹οΈ

Criminals dont need to be clever all the time they just follow the easiest path in trick users, exploit stale components, or abuse trusted systems like OAuth and package registries. If your stack or habits make any of those easy, youre already a target. This weeks ThreatsDay highlights show exactly how those weak points are being exploited from overlooked.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Lazarus Group’s Operation DreamJob Targets European Defense Firms πŸ“”

Cyberattacks by North Koreas Lazarus Group target European defense firms in drone development.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Fortinet Alternatives 2025: When Your All‑in‑One Starts Fraying Edges 🌊

Fortinet covers a lot, until scale makes policy sprawl, thin SSE depth, and murky investigations slow you down, or TLSDLP licensing bumps your costs. If roaming users, SaaS access, and The post Fortinet Alternatives 2025 When Your AllinOne Starts Fraying Edges appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Red Canary Alternatives (2025): 8 Serious Options & When They Win 🌊

Red Canary is widely respected for telemetryfirst MDR and crisp analyst narrative. But not every program wants a pure bringyourownEDR MDR on top posture, and your edges, cloud mix, The post Red Canary Alternatives 2025 8 Serious Options When They Win appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Zscaler Alternatives (2025): 9 Serious Options & When They Win 🌊

Zscaler owns the roaminguser SaaS access story. But not every program wants allin SSE, or your edges just dont look like the demo. This guide lays out the nine The post Zscaler Alternatives 2025 9 Serious Options When They Win appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Pakistani-Linked Hacker Group Targets Indian Government πŸ“”

A cyberespionage campaign by Pakistans TransparentTribe has been identified, targeting Indian government systems using DeskRAT.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets πŸ–‹οΈ

Threat actors with ties to North Korea have been attributed to a new wave of attacks targeting European companies active in the defense industry as part of a longrunning campaign known as Operation Dream Job. "Some of these companies' are heavily involved in the unmanned aerial vehicle UAV sector, suggesting that the operation may be linked to North Korea's current efforts to scale up its.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation πŸ–‹οΈ

The threat actors behind a largescale, ongoing smishing campaign have been attributed to more than 194,000 malicious domains since January 1, 2024, targeting a broad range of services across the world, according to new findings from Palo Alto Networks Unit 42. "Although these domains are registered through a Hong Kongbased registrar and use Chinese nameservers, the attack infrastructure is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation πŸ–‹οΈ

Microsoft on Thursday released outofband security updates to patch a criticalseverity Windows Server Update Service WSUS vulnerability with a proofofconcept Poc exploit publicly available and has come under active exploitation in the wild. The vulnerability in question is CVE202559287 CVSS score 9.8, a remote code execution flaw in WSUS that was originally fixed by the tech giant.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign πŸ–‹οΈ

A Pakistannexus threat actor has been observed targeting Indian government entities as part of spearphishing attacks designed to deliver a Golangbased malware known as DeskRAT. The activity, observed in August and September 2025 by Sekoia, has been attributed to Transparent Tribe aka APT36, a statesponsored hacking group known to be active since at least 2013. It also builds upon a prior.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Cybersecurity Perception Gap: Why Executives and Practitioners See Risk Differently πŸ–‹οΈ

Does your organization suffer from a cybersecurity perception gap? Findings from the Bitdefender 2025 Cybersecurity Assessment suggest the answer is probably yes and many leaders may not even realize it. This disconnect matters. Small differences in perception today can evolve into major blind spots tomorrow. After all, perception influences what organizations prioritize, where they.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation πŸ–‹οΈ

A malicious network of YouTube accounts has been observed publishing and promoting videos that lead to malware downloads, essentially abusing the popularity and trust associated with the video hosting platform for propagating malicious payloads. Active since 2021, the network has published more than 3,000 malicious videos to date, with the volume of such videos tripling since the start of the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Self-Spreading 'GlassWorm' Infects VS Code Extensions in Widespread Supply Chain Attack πŸ–‹οΈ

Cybersecurity researchers have discovered a selfpropagating worm that spreads via Visual Studio Code VS Code extensions on the Open VSX Registry and the Microsoft Extension Marketplace, underscoring how developers have become a prime target for attacks. The sophisticated threat, codenamed GlassWorm by Koi Security, is the second such supply chain attack to hit the DevOps space within a span.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Newcomers Fuel Ransomware Explosion in 2025 as Old Groups Fade πŸ¦…

Despite major changes in the leading ransomware groups, ransomware attacks have surged 50 in 2025, as cybercriminals have proven adept at finding new opportunities and exploiting vulnerabilities.  Ransomware attacks were up 50 in 2025 through October 21, according to Cyble data, rising to 5,010 from 3,335 in the same period of 2024. Cybles data is based on ransomware group claims on their dark web data leak sites.  From the decline of RansomHub to the rise of Qilin and newcomers like Sinobi and The Gentlemen, ransomware group leadership has been in flux for much of 2025, but affiliates have been quick to find new opportunities, and a steady supply of critical vulnerabilities has helped fuel attacks.  Dramatic changes in the ransomware landscape were among the revelations in Cybl...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New LockBit Ransomware Victims Identified by Security Researchers πŸ“”

Check Point has identified a dozen attacks in September that bore the LockBit stamp, with half of them attributed to the groups new ransomware version.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Blitz Spear Phishing Campaign Targets NGOs Supporting Ukraine πŸ“”

A spear phishing campaign dubbed PhantomCaptcha targeted Ukraines war relief efforts and regional government administrations for a single day in October.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction πŸ“”

ToolShell exploit activity surged last quarter, appearing in over 60 of Cisco Talos IR cases and driving a sharp rise in publicfacing application attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Qilin Ransomware Group Publishes Over 40 Cases Monthly πŸ“”

Qilin ransomware activity has surged in late 2025, threatening data leaks via double extortion tactics.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Critical Dell Storage Manager flaws could let hackers access sensitive data – patch now πŸ“’

A trio of flaws in Dell Storage Manager has prompted a customer alert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity