πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Grafana Labs Says Code Breach Stemmed from TanStack Attack πŸ“”

Grafana Labs has confirmed a recent data breach was caused by the TanStack supply chain attack.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Lawmakers Demand Answers as CISA Tries to Contain Data Leak β™ŸοΈ

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity Infrastructure Security Agency CISA after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware πŸ–‹οΈ

The Belarusaligned threat actor known as Ghostwriter aka UAC0057 and UNC1151Ukraine's National Security and Defense Council has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Computer Emergency Response Team of Ukraine CERTUA, involves sending phishing emails to government.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Hackers are turning up at law firms to gain physical access to machines πŸ“’

The FBI is warning companies to look out for fake IT staff.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ UK wants an AI-powered anti-hacking system πŸ“’

GCHQ is building a national cyber defence capability powered by AI though it may take five years.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 ShinyHunters Alleges 42M Records Stolen from Charter Communications 🦿

Charter confirmed a cyber incident after ShinyHunters claimed it stole Spectrum customer data through vishing and SaaS account access. The post ShinyHunters Alleges 42M Records Stolen from Charter Communications appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Krispy Kreme Settlement Deadline Nears: Eligible Members Could Claim Up to $3,500 🦿

Krispy Kreme data breach settlement claims are due June 22. See who qualifies, payment options, key deadlines, and what eligible people need to file. The post Krispy Kreme Settlement Deadline Nears Eligible Members Could Claim Up to 3,500 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 FBI Warns Companies About Ransom Gang’s Fake IT Support Tactics 🦿

The FBI warns Silent Ransom Group is targeting US law firms with phishing, fake IT calls, and inperson visits to steal data for extortion. The post FBI Warns Companies About Ransom Gangs Fake IT Support Tactics appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple May Bring Android-Style Theft Detection to iPhones 🦿

Apple is reportedly testing an iPhone antisnatching feature that would lock stolen devices using motion signals and checks for familiar locations. The post Apple May Bring AndroidStyle Theft Detection to iPhones appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google’s $135M Android Privacy Settlement: Who May Be Eligible 🦿

Googles 135 million Android settlement could pay eligible US users who used Android devices with cellular data since November 2017. The post Googles 135M Android Privacy Settlement Who May Be Eligible appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code πŸ–‹οΈ

A critical security vulnerability has been disclosed in Gogs, a popular opensource selfhosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier. "The vulnerability allows any authenticated user to achieve remote code execution RCE on.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer πŸ–‹οΈ

Threat actors are continuing to exploit a critical, nowpatched security flaw impacting FortiClient Endpoint Management Server EMS deployments to deliver credentialstealing malware. "The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints," Arctic Wolf said. "Threat actors disguised the credential stealer payload as a Fortinet endpoint.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal πŸ–‹οΈ

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure CVD, urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The development comes after a researcher named Chaotic Eclipse aka NightmareEclipse disclosed details of multiple zeroday.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More πŸ–‹οΈ

Every time you think the industry has finally stopped doing some reckless, loweffort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled socialengineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now meanwhile some researcher casually drops a technique that turns a "minor" foothold into total account.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users" πŸ–‹οΈ

State of AI Usage Report 2026 full report here by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don't understand where their AI exposure is actually coming from. The research shows that enterprise AI risk is not distributed evenly across users or platforms. Instead, it is heavily concentrated among a small group of AI power users and a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware πŸ–‹οΈ

A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitmentthemed social engineering and bespoke macOS malware. "These campaigns leveraged sophisticated social engineering techniques, custom macOS malware, and deep targeting of CICD infrastructure," Wiz researchers Shira Ayal,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ What to consider before asking an AI chatbot for health advice πŸš€

Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Heres whats at stake and how to stay safe.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ BTMOB: A stealthy RAT burrowing deep into Android devices πŸš€

The malware pairs remote access capabilities with readymade campaign tools, lowering the barrier for full device compromise.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise πŸš€

Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Attackers Move Past Typosquatting to Realistic Package Impersonation πŸ“”

Most malicious open source packages now mimic real code rather than rely on typosquatting.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft Condemns "Uncoordinated" Zero Day Disclosures πŸ“”

Microsoft warned the disclosure of several unpatched vulnerabilities without notice has put customers at unnecessary risk.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity