πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” OpenAI To Extend Cyber Program to Government Agencies πŸ“”

OpenAI announced its intention to expand the Trusted Access for Cyber program for cyber defenders at the federal, state and local government levels.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools πŸ–‹οΈ

An active phishing campaign has been observed targeting multiple vectors since at least April 2025 with legitimate Remote Monitoring and Management RMM software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUSHELPER, has impacted over 80 organizations, most of which are in the U.S., according to Securonix. It shares overlaps with clusters.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 MAXI Copilot vs. Microsoft Security Copilot: Same Incident, Different Outcomes 🌊

The investigative behavior of the two AI systems, and why "we already have an AI security tool" stops being a reassuring sentence the moment a real incident starts? The post MAXI Copilot vs. Microsoft Security Copilot Same Incident, Different Outcomes appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 MAXI Copilot vs. Microsoft Security Copilot: Same Incident, Different Outcomes 🌊

The investigative behavior of the two AI systems, and why "we already have an AI security tool" stops being a reassuring sentence the moment a real incident starts? The post MAXI Copilot vs. Microsoft Security Copilot Same Incident, Different Outcomes appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Defender Bug Triggers False Malware Alerts for DigiCert Certificates 🦿

Microsoft fixed a Defender false positive that flagged legitimate DigiCert certificates as malware, disrupting Windows trust stores for some IT teams. The post Microsoft Defender Bug Triggers False Malware Alerts for DigiCert Certificates appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 5 Best VPNs for Android in 2026 🦿

Explore the best VPNs for Android devices in 2026. Find out which VPN offers the best security, speed and features for your Android device. The post 5 Best VPNs for Android in 2026 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 The 7 Best iPhone VPNs in 2026 🦿

Which VPN works best on iPhones? Use our guide to compare the pricing and features of the 7 best VPNs for iPhone in 2026. The post The 7 Best iPhone VPNs in 2026 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Indirect Prompt Injection Is Now a Real-World AI Security Threat 🦿

AI agents are now being weaponized through prompt injection, exposing why model guardrails are not enough to protect enterprise data. The post Indirect Prompt Injection Is Now a RealWorld AI Security Threat appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Canvas Breach May Put 275M Users, 9,000 Schools at Risk 🦿

Instructure confirms a Canvas breach involving user information and messages as hackers claim 275M users and nearly 9,000 schools were affected. The post Canvas Breach May Put 275M Users, 9,000 Schools at Risk appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API πŸ–‹οΈ

A critical security vulnerability in Weaver Fanwei Ecology, an enterprise office automation OA and collaboration platform, has come under active exploitation in the wild. The vulnerability CVE202622679, CVSS score 9.8 relates to a case of unauthenticated remote code execution affecting Weaver Ecology 10.0 versions prior to 20260312. The issue resides in the "papiesearchdatadevops.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries πŸ–‹οΈ

Microsoft has disclosed details of a largescale credential theft campaign that has leveraged a combination of code of conductthemed lures and legitimate email services to direct users to attackercontrolled domains and steal authentication tokens. The multistage campaign, observed between April 14 and 16, 2026, targeted more than 35,000 users across over 13,000 organizations in 26 countries,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools πŸ–‹οΈ

An active phishing campaign has been observed targeting multiple vectors since at least April 2025 with legitimate Remote Monitoring and Management RMM software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUSHELPER, has impacted over 80 organizations, most of which are in the U.S., according to Securonix. It shares overlaps with clusters.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass πŸ–‹οΈ

Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation formerly Central is a secure, serverbased managed file transfer MFT solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts.  The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More πŸ–‹οΈ

This week, the shadows moved faster than the patches. While most teams were still triaging last months alerts, attackers had already turned control panels into kill switches, kernels into open doors, and opensource pipelines into silent delivery systems. The game has shifted from breach to occupation. Theyre living inside SaaS sessions, pushing code with trusted commits, and scaling.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 2026: The Year of AI-Assisted Attacks πŸ–‹οΈ

On December 4, 2025, a 17yearold was arrested in Osaka under Japans Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan's largest internet cafe chain. When asked, the young man shared his motivation for the hack he wanted to buy Pokmon cards. In a sense, this is a fairly conventional story.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia πŸ–‹οΈ

The Chinabased cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities in January 2026. "Both waves followed a nearly.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks πŸ–‹οΈ

A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service providers MSPs and hosting providers in the Philippines, Laos, Canada, South Africa, and the U.S., by exploiting the recently disclosed vulnerability in cPanel. The activity, detected by CtrlAltIntel on May 2, 2026, involves the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Trellix Reveals Unauthorized Access to Source Code πŸ“”

Security vendor Trellix has suffered a breach involving unauthorized access.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Five Eyes agencies sound alarm over risky agentic AI deployments πŸ“’

Security agencies have urged organizations to establish clear boundaries and guardrails for AI agents.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ β€˜Panthalassa has opened the ocean frontier’: Thiel-backed startup secures $140 million to deploy floating AI data centers πŸ“’

Panthalassa plans to deploy autonomous AI data centers in the North Pacific Ocean.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is πŸ–‹οΈ

While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk. Businesses are moving fast to selfhost LLM infrastructure, drawn by the promise of AI as a force multiplier and the pressure to deliver more value faster. But speed is coming at the expense of security. In the wake of the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity