πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Password Reuse in Disguise: An Often-Missed Risky Workaround πŸ–‹οΈ

When security teams discuss credentialrelated risk, the focus typically falls on threats such as phishing, malware, or ransomware. These attack methods continue to evolve and rightly command attention. However, one of the most persistent and underestimated risks to organizational security remains far more ordinary. Nearidentical password reuse continues to slip past security controls, often.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088 πŸ–‹οΈ

Google on Tuesday revealed that multiple threat actors, including nationstate adversaries and financially motivated groups, are exploiting a nowpatched critical security flaw in RARLAB WinRAR to establish initial access and deploy a diverse array of payloads. "Discovered and patched in July 2025, governmentbacked threat actors linked to Russia and China as well as financially motivated.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan πŸ–‹οΈ

Cybersecurity researchers have discovered two malicious packages in the Python Package Index PyPI repository that masquerade as spellcheckers but contain functionality to deliver a remote access trojan RAT. The packages, named spellcheckerpy and spellcheckpy, are no longer available on PyPI, but not before they were collectively downloaded a little over 1,000 times. "Hidden inside the Basque.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected πŸ–‹οΈ

Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE202624858 CVSS score 9.4, has been described as an authentication bypass related to FortiOS single signon SSO. The flaw also affects FortiManager and FortiAnalyzer. The company said it's.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan πŸš€

ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cybersecurity Teams Embrace AI, Just Not at the Scale Marketing Suggests πŸ“”

Despite the seemingly widespread adoption of AI for security operations, security leaders primarily use it for relatively basic use cases, said a Sumo Logic study.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Autonomous System Uncovers Long-Standing OpenSSL Flaws πŸ“”

A recent update has fixed 12 vulnerabilities in OpenSSL, some existing in the codebase for years.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Critical and High Severity n8n Sandbox Flaws Allow RCE πŸ“”

Two critical security flaws in n8n have exposed sandboxing vulnerabilities, enabling remote code execution for attackers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign πŸ“”

Researchers discover that PureRATs code now contains emojis indicating it has been written by AI basedon comments ripped from social media.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI Security Threats Loom as Enterprise Usage Jumps 91% πŸ“”

Zscaler analysts found critical vulnerabilities in 100 of enterprise AI systems, with 90 compromised in under 90 minutes.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Researchers Uncover 454,000+ Malicious Open Source Packages πŸ“”

Sonatype warns that open source threats became industrialized with a surge in malicious packages in 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Chinese Money Launderers Drive Global Ecosystem Worth $82bn πŸ“”

Chainalysis claims Chinese money launderers now account for 20 of global activity.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… The Week in Vulnerabilities: Cyble Urges Oracle, OpenStack Fixes πŸ¦…

Cyble Vulnerability Intelligence researchers tracked 1,031 vulnerabilities in the last week, and nearly 200 already have a publicly available ProofofConcept PoC, significantly increasing the likelihood of realworld attacks on those vulnerabilities.  A total of 72 vulnerabilities were rated as critical under the CVSS v3.1 scoring system, while 33 received a critical severity rating based on the newer CVSS v4.0 scoring system.  Below are some of the vulnerabilities flagged by Cyble threat intelligence researchers for prioritization by security teams in recent reports to clients.  The Weeks Top IT Vulnerabilities  CVE202621969 is a 9.8severity vulnerability in Oracle Agile Product Lifecycle Management for Process, specifically in the Supplier Portal component of Oracle Supply Cha...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass πŸ–‹οΈ

SolarWinds has released security updates to address multiple security vulnerabilities impacting SolarWinds Web Help Desk, including four critical vulnerabilities that could result in authentication bypass and remote code execution RCE. The list of vulnerabilities is as follows CVE202540536 CVSS score 8.1 A security control bypass vulnerability that could allow an unauthenticated.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Number of Cybersecurity Pros Surges 194% in Four Years πŸ“”

Cybersecurity is now the fifth fastestgrowing occupation in the UK, says Socura.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The open source ecosystem is booming thanks to AI, but hackers are taking advantage πŸ“’

Analysis by Sonatype found that AI is giving attackers new opportunities to target victims.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach 🦿

The dataset allegedly includes names, email addresses, postal addresses, phone numbers, and accountrelated details. The post ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 πŸ–‹οΈ

Beyond the direct impact of cyberattacks, enterprises suffer from a secondary but potentially even more costly risk operational downtime, any amount of which translates into very real damage. Thats why for CISOs, its key to prioritize decisions that reduce dwell time and protect their company from risk.  Three strategic steps you can take this year for better results 1. Focus on today's.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps πŸ–‹οΈ

A study by OMICRON has revealed widespread cybersecurity gaps in the operational technology OT networks of substations, power plants, and control centers worldwide. Drawing on data from more than 100 installations, the analysis highlights recurring technical, organizational, and functional issues that leave critical energy infrastructure vulnerable to cyber threats. The findings are based on.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Data Breaches Hit Record High but Victim Numbers Decline πŸ“”

Nonprofit ITRC says the number of data breaches increased 5 annually to reach a record total in 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” FBI Takes Down RAMP Ransomware Forum πŸ“”

The dark web forum administrator confirmed the takedown and said they had no plans to rebuild.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity