πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a malware campaign that's targeting software developers with a new information stealer called Evelyn Stealer by weaponizing the Microsoft Visual Studio Code VS Code extension ecosystem. "The malware is designed to exfiltrate sensitive information, including developer credentials and cryptocurrencyrelated data. Compromised developer.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Linkedin Phishing Campaign Exploits Open-Source Pen Testing Tool to Compromise Business Execs πŸ“”

Cybersecurity Researchers at ReliaQuest warn of an ongoing campaign delivered to highvalue individuals via LinkedIn messages.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution πŸ–‹οΈ

A set of three security vulnerabilities has been disclosed in mcpservergit, the official Git Model Context Protocol MCP server maintained by Anthropic, that could be exploited to read or delete arbitrary files and execute code under certain conditions. "These flaws can be exploited through prompt injection, meaning an attacker who can influence what an AI assistant reads a malicious README,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading πŸ–‹οΈ

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads, likely with the intent to deploy a remote access trojan RAT. The activity delivers "weaponized files via Dynamic Link Library DLL sideloading, combined with a legitimate, opensource Python pentesting script," ReliaQuest said in a report shared with.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” Cyber Risks Among CEOs’ Top Worries Amid Weak Short Term Growth Outlook πŸ“”

PwCs 29th Global CEO Survey shows cyber risk rising to the top of CEO concerns as confidence in short term business growth weakens.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 New Windows Flaw Lets Attackers Bypass Mark of the Web 🦿

Microsoft patched a Windows Remote Assistance flaw that lets attackers bypass Mark of the Web, weakening protections against malicious downloads and phishing files. The post New Windows Flaw Lets Attackers Bypass Mark of the Web appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Prompt Injection Bugs Found in Official Anthropic Git MCP Server πŸ“”

Three vulnerabilities in Anthropic's Git server for the MCP can be exploited via prompt injection.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff πŸ–‹οΈ

Every managed security provider is chasing the same problem in 2026 too many alerts, too few analysts, and clients demanding CISOlevel protection at SMB budgets. The truth? Most MSSPs are running harder, not smarter. And its breaking their margins. Thats where the quiet revolution is happening AI isnt just writing reports or surfacing risks its rebuilding how security services are.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff πŸ–‹οΈ

Every managed security provider is chasing the same problem in 2026 too many alerts, too few analysts, and clients demanding CISOlevel protection at SMB budgets. The truth? Most MSSPs are running harder, not smarter. And its breaking their margins. Thats where the quiet revolution is happening AI isnt just writing reports or surfacing risks its rebuilding how security services are.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Exposure Assessment Platforms Signal a Shift in Focus πŸ–‹οΈ

Gartner doesnt create new categories lightly. Generally speaking, a new acronym only emerges when the industry's collective "todo list" has become mathematically impossible to complete. And so it seems that the introduction of the Exposure Assessment Platforms EAP category is a formal admission that traditional Vulnerability Management VM is no longer a viable way to secure a modern.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Exposure Assessment Platforms Signal a Shift in Focus πŸ–‹οΈ

Gartner doesnt create new categories lightly. Generally speaking, a new acronym only emerges when the industry's collective "todo list" has become mathematically impossible to complete. And so it seems that the introduction of the Exposure Assessment Platforms EAP category is a formal admission that traditional Vulnerability Management VM is no longer a viable way to secure a modern.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs πŸ–‹οΈ

Security vulnerabilities were uncovered in the popular opensource artificial intelligence AI framework Chainlit that could allow attackers to steal sensitive data, which may allow for lateral movement within a susceptible organization. Zafran Security said the highseverity flaws, collectively dubbed ChainLeak, could be abused to leak cloud environment API keys and steal sensitive files, or.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ LastPass issues alert as customers targeted in new phishing campaign πŸ“’

LastPass has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign that encourages users to backup vaults.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Ransomware is on the rise. Again πŸ“’

Ransomware resurges with AIdriven sophistication, challenging defenders and creating opportunities for MSPs.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 EU’s New Cybersecurity Act Could Ban High-Risk Suppliers 🦿

This sweeping update introduces measures to identify and potentially exclude "highrisk" third countries and companies across 18 essential sectors. The post EUs New Cybersecurity Act Could Ban HighRisk Suppliers appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 EU’s New Cybersecurity Act Could Ban High-Risk Suppliers 🦿

This sweeping update introduces measures to identify and potentially exclude "highrisk" third countries and companies across 18 essential sectors. The post EUs New Cybersecurity Act Could Ban HighRisk Suppliers appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 New iOS and iPadOS Flaws Leave Millions of iPhones at Risk 🦿

Critical iOS and iPadOS WebKit flaws put millions of iPhones and iPads at risk of silent takeover. Apple urges users to update immediately. The post New iOS and iPadOS Flaws Leave Millions of iPhones at Risk appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 New iOS and iPadOS Flaws Leave Millions of iPhones at Risk 🦿

Critical iOS and iPadOS WebKit flaws put millions of iPhones and iPads at risk of silent takeover. Apple urges users to update immediately. The post New iOS and iPadOS Flaws Leave Millions of iPhones at Risk appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google Gemini Flaw Let Attackers Access Private Calendar Data 🦿

Security researchers found a Google Gemini flaw that let hidden instructions in a meeting invite extract private calendar data and create deceptive events. The post Google Gemini Flaw Let Attackers Access Private Calendar Data appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google Gemini Flaw Let Attackers Access Private Calendar Data 🦿

Security researchers found a Google Gemini flaw that let hidden instructions in a meeting invite extract private calendar data and create deceptive events. The post Google Gemini Flaw Let Attackers Access Private Calendar Data appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Secure Your Business Traffic With Military-Grade VPN for Only $20 🦿

This nologging VPN with AES256 encryption protects your remote teams and client data for the low price of 19.99 annually. The post Secure Your Business Traffic With MilitaryGrade VPN for Only 20 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity