πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Vibe Coding Cheat Sheet: Tools, Prompts, Security Tips, and More 🦿

This vibe coding cheat sheet explains how plainlanguage prompts can build apps fast, plus the planning, testing, and security checks needed. The post Vibe Coding Cheat Sheet Tools, Prompts, Security Tips, and More appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 OpenAI Warns Mac Users to Update Apps After Supply-Chain Attack 🦿

OpenAI says Mac users must update ChatGPT, Codex, and Atlas apps by June 12 after an npm supplychain attack exposed signing certificates. The post OpenAI Warns Mac Users to Update Apps After SupplyChain Attack appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Two Unpatched Windows Exploits Target BitLocker, SYSTEM Access 🦿

Two unpatched Windows exploit PoCs target BitLocker protections and privilege controls after Microsofts May Patch Tuesday security update. The post Two Unpatched Windows Exploits Target BitLocker, SYSTEM Access appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access πŸ–‹οΈ

The Russian statesponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peertopeer P2P botnet that's engineered for stealth and persistent access to compromised hosts. Turla, per the U.S. Cybersecurity and Infrastructure Security Agency CISA, is assessed to be affiliated with Center 16 of Russia's Federal Security Service FSB.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence πŸ–‹οΈ

Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸš€ Why geopolitical turmoil is a gift for scammers, and how to stay safe πŸš€

Conflict is a boon for opportunistic fraudsters. Look out for their ploys.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming πŸ–‹οΈ

A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by Sansec this week. The vulnerability currently does not have an official CVE identifier. It.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt πŸ–‹οΈ

Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations," Grafana said in a series of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE πŸ–‹οΈ

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE202642945 CVSS score 9.2, is a heap buffer overflow in ngxhttprewritemodule affecting NGINX versions 0.6.27 through 1.30.0. According to AInative security company depthfirst, the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀5
πŸ“” Cybercriminal VPN Dismantled in Europol Crackdown πŸ“”

First VPN, a service used by ransomware actors and fraudsters, was dismantled by Europol.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ GitHub internal repositories exfiltrated via malicious VS Code extension πŸ“’

The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension πŸ“”

A threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual Studio Marketplace.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Wasabi ramps up EMEA channel push with focus on cyber resilience πŸ“’

The cloud storage vendor is expanding partner tools and integrations as AIdriven data growth and ransomware threats continue to rise.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity