πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added a critical security flaw affecting Broadcom VMware vCenter Server that was patched in June 2024 to its Known Exploited Vulnerabilities KEV catalog, citing evidence of active exploitation in the wild. The vulnerability in question is CVE202437079 CVSS score 9.8, which refers to a heap overflow in the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ How can businesses make their cybersecurity training stick? πŸ“’

Who in the modern business needs cybersecurity training and what key factors should firms keep in mind?.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ Thousands of Microsoft Teams users are being targeted in a new phishing campaign πŸ“’

Microsoft Teams users should be on the alert, according to researchers at Check Point.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Shared BitLocker Keys With FBI, Raising Privacy Fears 🦿

Microsoft confirmed it can hand over BitLocker recovery keys stored in the cloud under warrant, reviving debate over who controls encrypted data. The post Microsoft Shared BitLocker Keys With FBI, Raising Privacy Fears appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Gmail Spam Filter Breakdown Affects 1.8B Users 🦿

The disruption began Saturday 5am Pacific time, Jan .24 affecting approximately 1.8 billion Gmail users worldwide with widespread email misclassification. The post Gmail Spam Filter Breakdown Affects 1.8B Users appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code πŸ–‹οΈ

Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code VS Code extensions that are advertised as artificial intelligence AIpowered coding assistants, but also harbor covert functionality to siphon developer data to Chinabased servers. The extensions, which have 1.5 million combined installs and are still available for download from the official Visual Studio.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More πŸ–‹οΈ

Security failures rarely arrive loudly. They slip in through trusted tools, halffixed problems, and habits people stop questioning. This weeks recap shows that pattern clearly. Attackers are moving faster than defenses, mixing old tricks with new paths. Patched no longer means safe, and every day, software keeps becoming the entry point. What follows is a set of small but telling signals.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Winning Against AI-Based Attacks Requires a Combined Defensive Approach πŸ–‹οΈ

If theres a constant in cybersecurity, its that adversaries are always innovating. The rise of offensive AI is transforming attack strategies and making them harder to detect. Googles Threat Intelligence Group, recently reported on adversaries using Large Language Models LLMs to both conceal code and generate malicious scripts on the fly, letting malware shapeshift in realtime to evade.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers πŸ–‹οΈ

The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence AI tools to target developers and engineering teams in the blockchain sector. The phishing campaign has targeted Japan, Australia, and India, highlighting the adversary's expansion of the targeting scope beyond South Korea, Russia, Ukraine, and European nations, Check.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” CISA Releases List of Post-Quantum Cryptography Product Categories πŸ“”

CISA released initial list of PQCcapable hardware and software to guide companies amid quantum threats.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Researchers Uncover β€œHaxor” SEO Poisoning Marketplace πŸ“”

Fortra researchers have discovered a new SEO poisoning operation known as HaxorSEO.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Law Firm Investigates Coupang Security Failures Ahead of Class Action Deadline πŸ“”

The US law firm Hagens Berman will lead a class action lawsuit against Coupang over security failures that led to a June 2025 data breach.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Okta Flags Customized, Reactive Vishing Attacks Which Bypass MFA πŸ“”

Threat actors posing as IT support teams use phishing kits to generate fake login sites in realtime to trick victims into handing over credentials.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Wiper Attack on Polish Power Grid Linked to Russia’s Sandworm πŸ“”

A destructive cyber attack targeting Polands energy sector has been linked to Russian APT group Sandworm.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Python Developer 🌊

The post Python Developer appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware πŸ–‹οΈ

Cybersecurity researchers have discovered an ongoing campaign that's targeting Indian users with a multistage backdoor as part of a suspected cyber espionage campaign. The activity, per the eSentire Threat Response Unit TRU, involves using phishing emails impersonating the Income Tax Department of India to trick victims into downloading a malicious archive, ultimately granting the threat.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 B2b Growth Marketing Manager (Online media, external placements, integrated campaigns) 🌊

The post B2b Growth Marketing Manager Online media, external placements, integrated campaigns appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” eScan Antivirus Supply Chain Breach Delivers Signed Malware πŸ“”

Supply chain breach in eScan antivirus distributes multistage malware via legitimate updates.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
πŸ“’ Hackers are using LLMs to generate malicious JavaScript in real time – and they’re going after web browsers πŸ“’

Defenders advised to use runtime behavioral analysis to detect and block malicious activity at the point of execution, directly within the browser.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 $95M Payout: Apple Begins Compensating Users in Siri Eavesdropping Case 🦿

Apple has started issuing Siri privacy settlement payouts, with claimants seeing deposits as low as 8 per device from a 95 million fund. The post 95M Payout Apple Begins Compensating Users in Siri Eavesdropping Case appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 WhatsApp Adds One-Tap Security Settings for Added Privacy 🦿

WhatsApp rolled out Strict Account Settings, a lockdownstyle mode that blocks unknown attachments, disables link previews, and silences unknown callers. The post WhatsApp Adds OneTap Security Settings for Added Privacy appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity