πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal πŸ–‹οΈ

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure CVD, urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The development comes after a researcher named Chaotic Eclipse aka NightmareEclipse disclosed details of multiple zeroday.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More πŸ–‹οΈ

Every time you think the industry has finally stopped doing some reckless, loweffort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled socialengineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now meanwhile some researcher casually drops a technique that turns a "minor" foothold into total account.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users" πŸ–‹οΈ

State of AI Usage Report 2026 full report here by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don't understand where their AI exposure is actually coming from. The research shows that enterprise AI risk is not distributed evenly across users or platforms. Instead, it is heavily concentrated among a small group of AI power users and a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware πŸ–‹οΈ

A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitmentthemed social engineering and bespoke macOS malware. "These campaigns leveraged sophisticated social engineering techniques, custom macOS malware, and deep targeting of CICD infrastructure," Wiz researchers Shira Ayal,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ What to consider before asking an AI chatbot for health advice πŸš€

Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Heres whats at stake and how to stay safe.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ BTMOB: A stealthy RAT burrowing deep into Android devices πŸš€

The malware pairs remote access capabilities with readymade campaign tools, lowering the barrier for full device compromise.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise πŸš€

Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Attackers Move Past Typosquatting to Realistic Package Impersonation πŸ“”

Most malicious open source packages now mimic real code rather than rely on typosquatting.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft Condemns "Uncoordinated" Zero Day Disclosures πŸ“”

Microsoft warned the disclosure of several unpatched vulnerabilities without notice has put customers at unnecessary risk.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New Threat Actor Jinx-0164 Targets Crypto Developers on macOS πŸ“”

New actor Jinx0164 hit crypto developers with fake recruiter lures and macOS malware.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Cybersecurity Staff Prefer CISOs With Real Attack Response Experience, Study Reveals πŸ“”

ISC2 survey of cybersecurity professionals suggests that staff want their information security leaders to have experienced reacting to a significant cyber incident.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” GCHQ Chief Urges Action as AI Reshapes Cyber Threats πŸ“”

GCHQ director urges urgent business cyber action as AI and quantum reshape the threat.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” CrowdStrike, Google Take Down Glassworm Botnet πŸ“”

Operators of the malicious Glassworm botnet have been targeting software developers since at least early 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Why Burnout in Cybersecurity Demands Risk-Based Response πŸ“”

Cybermindz warns that cybersecurity burnout is a growing risk, urging organizations to move beyond wellness initiatives and adopt a measurable, riskbased approach to workforce stress.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Thousands of Fake FIFA Domains Target World Cup Fans πŸ“”

GroupIB uncovered Ghost Stadium phishing and 4300 fake FIFA World Cup domains targeting fans.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” 68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise πŸ“”

UK firms plan higher cyber spending as AI adoption raises security concerns.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” PureLogs Variant Steals Data via Purchase Order Lures πŸ“”

FortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowing.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Chinese Threat Actors Ditch Static Phishing Pages for Live Credential Interception πŸ“”

Almost all organizations impersonated by Chinese phishing platforms are nonChinese entities, suggesting operators deliberately avoid domestic targets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” BTMOB Android RAT Spreads Through No-Code Builder Tooling πŸ“”

BTMOB Android RAT sold as a service with a nocode builder for fast, regional phishing lures.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws πŸ“”

CERTIn urges 12hour patching of exposed flaws as AI compresses exploitation timelines.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity