πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Microsoft Condemns "Uncoordinated" Zero Day Disclosures πŸ“”

Microsoft warned the disclosure of several unpatched vulnerabilities without notice has put customers at unnecessary risk.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New Threat Actor Jinx-0164 Targets Crypto Developers on macOS πŸ“”

New actor Jinx0164 hit crypto developers with fake recruiter lures and macOS malware.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Cybersecurity Staff Prefer CISOs With Real Attack Response Experience, Study Reveals πŸ“”

ISC2 survey of cybersecurity professionals suggests that staff want their information security leaders to have experienced reacting to a significant cyber incident.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” GCHQ Chief Urges Action as AI Reshapes Cyber Threats πŸ“”

GCHQ director urges urgent business cyber action as AI and quantum reshape the threat.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” CrowdStrike, Google Take Down Glassworm Botnet πŸ“”

Operators of the malicious Glassworm botnet have been targeting software developers since at least early 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Why Burnout in Cybersecurity Demands Risk-Based Response πŸ“”

Cybermindz warns that cybersecurity burnout is a growing risk, urging organizations to move beyond wellness initiatives and adopt a measurable, riskbased approach to workforce stress.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Thousands of Fake FIFA Domains Target World Cup Fans πŸ“”

GroupIB uncovered Ghost Stadium phishing and 4300 fake FIFA World Cup domains targeting fans.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” 68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise πŸ“”

UK firms plan higher cyber spending as AI adoption raises security concerns.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” PureLogs Variant Steals Data via Purchase Order Lures πŸ“”

FortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowing.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Chinese Threat Actors Ditch Static Phishing Pages for Live Credential Interception πŸ“”

Almost all organizations impersonated by Chinese phishing platforms are nonChinese entities, suggesting operators deliberately avoid domestic targets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” BTMOB Android RAT Spreads Through No-Code Builder Tooling πŸ“”

BTMOB Android RAT sold as a service with a nocode builder for fast, regional phishing lures.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws πŸ“”

CERTIn urges 12hour patching of exposed flaws as AI compresses exploitation timelines.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign πŸ“”

Iran's Nimbus Manticore pushes AIbuilt MiniFast backdoor via phishing and SEO poisoning.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens πŸ“”

The Kali365 phishingasaservice platform lowers the barrier of entry for cybercriminals, said the FBI.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fake Streams, Counterfeit Merch and Other Scams: How Fraudsters Target F1 Fans πŸ“”

From fake F1 streams to counterfeit merch, fraudsters are exploiting fans online and the Bitdefender Cybersecurity Grand Prix Fan Threat Index details how.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Security Awareness Training Pricing in 2026: 15+ Vendors Compared, ROI Proven, Hidden Costs Exposed 🌊

We map SAT spend to NIST CSF 2.0, NIS2, and SEC Item 1.05 with audit evidence requirements. Explore the 90day execution plan inside. The post Security Awareness Training Pricing in 2026 15 Vendors Compared, ROI Proven, Hidden Costs Exposed appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Huntress Pricing 2026: MDR, ITDR, SIEM & SAT Costs with Real MSP vs. Direct Numbers 🌊

Get Huntress EDR, ITDR, SIEM, and SAT pricing for 2026 with reverseengineering MSP markup calculator. Compare 3year TCO at 75, 175, and 375 users. The post Huntress Pricing 2026 MDR, ITDR, SIEM SAT Costs with Real MSP vs. Direct Numbers appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Arctic Wolf Pricing Guide 2026: Real Costs, Tier Breakdowns & Negotiation Playbook 🌊

Got an Arctic Wolf quote? Explore the 8 hidden cost layers, the 3M warranty exclusions, and 9 negotiation levers ranked by savings impact for 2026. The post Arctic Wolf Pricing Guide 2026 Real Costs, Tier Breakdowns Negotiation Playbook appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight πŸ¦…

Executive Summary Cyble Research and Intelligence Labs CRIL has identified a novel Android banking trojan, dubbed OverlayPhantom, actively distributed in the wild via malicious URLs. The malware employs a twostage infection chain, using a dropper application that impersonates trusted platforms, including the official Austrian government identity application, ID Austria, and the widely used consumer platform TikTok, to deceive victims into installing it. Once deployed, OverlayPhantom masquerades as "Google Play Services" and abuses Android's Accessibility Service to gain persistent, elevated control of the infected device. The malware is capable of executing over 30 remote commands, conducting realtime screen streaming, performing overlay attacks using embedded HTML phishin...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Chinese Hackers Exploit Iran War to Target Maritime and Energy Companies πŸ“”

ESETs 2026 APT Activity Report suggests Chinabacked APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globe.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity