πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.4K subscribers
90K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Self-Spreading 'GlassWorm' Infects VS Code Extensions in Widespread Supply Chain Attack πŸ–‹οΈ

Cybersecurity researchers have discovered a selfpropagating worm that spreads via Visual Studio Code VS Code extensions on the Open VSX Registry and the Microsoft Extension Marketplace, underscoring how developers have become a prime target for attacks. The sophisticated threat, codenamed GlassWorm by Koi Security, is the second such supply chain attack to hit the DevOps space within a span.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Newcomers Fuel Ransomware Explosion in 2025 as Old Groups Fade πŸ¦…

Despite major changes in the leading ransomware groups, ransomware attacks have surged 50 in 2025, as cybercriminals have proven adept at finding new opportunities and exploiting vulnerabilities.  Ransomware attacks were up 50 in 2025 through October 21, according to Cyble data, rising to 5,010 from 3,335 in the same period of 2024. Cybles data is based on ransomware group claims on their dark web data leak sites.  From the decline of RansomHub to the rise of Qilin and newcomers like Sinobi and The Gentlemen, ransomware group leadership has been in flux for much of 2025, but affiliates have been quick to find new opportunities, and a steady supply of critical vulnerabilities has helped fuel attacks.  Dramatic changes in the ransomware landscape were among the revelations in Cybl...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New LockBit Ransomware Victims Identified by Security Researchers πŸ“”

Check Point has identified a dozen attacks in September that bore the LockBit stamp, with half of them attributed to the groups new ransomware version.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Blitz Spear Phishing Campaign Targets NGOs Supporting Ukraine πŸ“”

A spear phishing campaign dubbed PhantomCaptcha targeted Ukraines war relief efforts and regional government administrations for a single day in October.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction πŸ“”

ToolShell exploit activity surged last quarter, appearing in over 60 of Cisco Talos IR cases and driving a sharp rise in publicfacing application attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Qilin Ransomware Group Publishes Over 40 Cases Monthly πŸ“”

Qilin ransomware activity has surged in late 2025, threatening data leaks via double extortion tactics.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Critical Dell Storage Manager flaws could let hackers access sensitive data – patch now πŸ“’

A trio of flaws in Dell Storage Manager has prompted a customer alert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… APT-C-60 Escalates SpyGlace Campaigns Targeting Japan with Evolved Malware, Advanced Evasion TTPs πŸ¦…

APTC60 " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202510APTC60300x150.webp" datalargefile"httpscyble.comwpcontentuploads202510APTC60.webp" title"APTC60 Escalates SpyGlace Campaigns Targeting Japan with Evolved Malware, Advanced Evasion TTPs 1" The South Koreaaligned cyber espionage group APTC60 continued its aggressive targeting of Japanese organizations throughout Q3 2025, deploying three updated versions of its SpyGlace backdoor with enhanced capabilities and improved evasion techniques.  JPCERTCC's latest analysis reveals that attacks between June and August employed refined delivery mechanisms, more sophisticated victim tracking methods, and modified encryption schemes designed to complicate detection and analysis.  Unlike previous campaigns that relied o...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Qilin Ransomware Group Publishes Over 40 Cases Monthly πŸ“”

Qilin ransomware activity has surged in late 2025, threatening data leaks via double extortion tactics.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Critical Dell Storage Manager flaws could let hackers access sensitive data – patch now πŸ“’

A trio of flaws in Dell Storage Manager has prompted a customer alert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Critical Dell Storage Manager flaws could let hackers access sensitive data – patch now πŸ“’

A trio of flaws in Dell Storage Manager has prompted a customer alert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Critical Dell Storage Manager flaws could let hackers access sensitive data – patch now πŸ“’

A trio of flaws in Dell Storage Manager has prompted a customer alert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Critical Dell Storage Manager flaws could let hackers access sensitive data – patch now πŸ“’

A trio of flaws in Dell Storage Manager has prompted a customer alert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Critical Dell Storage Manager flaws could let hackers access sensitive data – patch now πŸ“’

A trio of flaws in Dell Storage Manager has prompted a customer alert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… From Human-Led to AI-Driven: Why Agentic AI Is Redefining Cybersecurity Strategy πŸ¦…

For years, cybersecurity has revolved around one enduring truth humans make the final call. Analysts detect, respond, and recover often under immense pressure and shrinking time windows. But as threat actors grow more sophisticated and the global digital surface expands, that humanled model is nearing its breaking point.  The next evolution in defense is already underway Agentic AI. Unlike conventional AI systems that assist with specific tasks, agentic AI represents a fundamental shift it is designed to perceive, reason, decide, and act autonomously. This new intelligence layer is not just an upgrade in automation its a complete rethinking of how organizations detect, defend, and adapt to cyber risk in real time.  Why Agentic AI Matters Now  The global cyber threat landscape ...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ CISA issues alert after botched Windows Server patch exposes critical flaw πŸ“’

A critical remote code execution flaw in Windows Server is being exploited in the wild, despite a previous 'fix'.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Qilin Ransomware Group Publishes Over 40 Cases Monthly πŸ“”

Qilin ransomware activity has surged in late 2025, threatening data leaks via double extortion tactics.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ CISA issues alert after botched Windows Server patch exposes critical flaw πŸ“’

A critical remote code execution flaw in Windows Server is being exploited in the wild, despite a previous 'fix'.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ CISA issues alert after botched Windows Server patch exposes critical flaw πŸ“’

A critical remote code execution flaw in Windows Server is being exploited in the wild, despite a previous 'fix'.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ CISA issues alert after botched Windows Server patch exposes critical flaw πŸ“’

A critical remote code execution flaw in Windows Server is being exploited in the wild, despite a previous 'fix'.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Europol Warns of Rising Threat From Caller ID Spoofing Attacks πŸ“”

Europol called for action against caller ID spoofing, linking attacks to significant online fraud.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity