πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass πŸ–‹οΈ

Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation formerly Central is a secure, serverbased managed file transfer MFT solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts.  The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More πŸ–‹οΈ

This week, the shadows moved faster than the patches. While most teams were still triaging last months alerts, attackers had already turned control panels into kill switches, kernels into open doors, and opensource pipelines into silent delivery systems. The game has shifted from breach to occupation. Theyre living inside SaaS sessions, pushing code with trusted commits, and scaling.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 2026: The Year of AI-Assisted Attacks πŸ–‹οΈ

On December 4, 2025, a 17yearold was arrested in Osaka under Japans Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan's largest internet cafe chain. When asked, the young man shared his motivation for the hack he wanted to buy Pokmon cards. In a sense, this is a fairly conventional story.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia πŸ–‹οΈ

The Chinabased cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities in January 2026. "Both waves followed a nearly.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks πŸ–‹οΈ

A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service providers MSPs and hosting providers in the Philippines, Laos, Canada, South Africa, and the U.S., by exploiting the recently disclosed vulnerability in cPanel. The activity, detected by CtrlAltIntel on May 2, 2026, involves the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Trellix Reveals Unauthorized Access to Source Code πŸ“”

Security vendor Trellix has suffered a breach involving unauthorized access.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Five Eyes agencies sound alarm over risky agentic AI deployments πŸ“’

Security agencies have urged organizations to establish clear boundaries and guardrails for AI agents.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ β€˜Panthalassa has opened the ocean frontier’: Thiel-backed startup secures $140 million to deploy floating AI data centers πŸ“’

Panthalassa plans to deploy autonomous AI data centers in the North Pacific Ocean.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is πŸ–‹οΈ

While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk. Businesses are moving fast to selfhost LLM infrastructure, drawn by the promise of AI as a force multiplier and the pressure to deliver more value faster. But speed is coming at the expense of security. In the wake of the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows πŸ–‹οΈ

The North Koreaaligned statesponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing its components with a backdoor called BirdCallto likely target ethnic Koreans residing in China. While prior versions of the backdoor have primarily targeted Windows users only, the supply chain attack is assessed to have enabled the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed to Cyber Risk πŸ“”

ISACA report warns that while AI has become the norm, many organizations are yet to formally apply safety or security policies around its use.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCSC Warns of an AI-Fuelled β€œVulnerability Patch Wave” πŸ“”

The UK's National Cyber Security Centre is urging organizations to prepare for glut of new software updates.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Back Door Attackers Know About β€” and Most Security Teams Still Haven’t Closed πŸ–‹οΈ

Every AI tool, workflow automation, and productivity app your employees connected to Google or Microsoft this year left something behind a persistent OAuth token with no expiration date, no automatic cleanup, and in most organizations, no one watching it. Your perimeter controls don't see it. Your MFA doesn't stop it. And when an attacker gets hold of one, they don't need a password. OAuth.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks πŸ–‹οΈ

Threat actors are actively exploiting a critical security flaw impacting an opensource content management system CMS known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE202629014 CVSS score 9.8, a code injection flaw that could result in arbitrary code execution. "MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fake SSA Emails Drive Venomous#Helper Phishing Campaign πŸ“”

VenomousHelper attackers impersonate the US Social Security Administration to deploy signed RMM software and maintain persistent access across US networks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Everything you need to know about ChatGPT’s new Advanced Account Security features πŸ“’

OpenAI has introduced new tools to tightening up access to ChatGPT, Codex, and its other AI tools.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Ransomware negotiator sentenced for role in major cyber crime group πŸ“’

Deniss Zolotarjovs was a key player in a group associated with Conti.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” North Korean APT Targets Yanbian Gamers via Trojanized Platform πŸ“”

ESET warns that North Korean hackers compromised a Yanbian gaming site in a supplychain attack, trojanizing Windows and Android software to spy on users.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions πŸ–‹οΈ

A sophisticated Chinanexus advanced persistent threat APT group has been attributed to attacks targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. The activity is being tracked by Cisco Talos under the moniker UAT8302, with postexploitation involving the deployment of custommade malware families that have been put.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 What If Your Digital Footprint Could Shrink? 🦿

Get Surfshark One with Incogni for 91.99 reg. 500.40 and cover VPN, alerts, antivirus, and data removal. The post What If Your Digital Footprint Could Shrink? appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails πŸ“”

Microsoft researchers warn of a largescale phishing campaign using fake compliance emails to steal credentials, targeting 35,000 users across 13,000 organizations worldwide.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity