πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.3K subscribers
89.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit πŸ–‹οΈ

An unknown threat actor has been observed using a large language model LLM agent to conduct postcompromise actions after obtaining initial access following the exploitation of a publiclyaccessible Marimo network using a recently disclosed vulnerability. "The attacker compromised an internetreachable Marimo notebook via CVE202639987, extracted two cloud credentials from the compromised.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks πŸ–‹οΈ

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukrainerelated entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russianspeaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks πŸ–‹οΈ

Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop. The artifact moved from a prompt to a product. The risk surface moved with it. In The Shadow Builders report get it here, a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets πŸ–‹οΈ

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C software development kit for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of "Sicoob.Sdk" contain functionality to exfiltrate sensitive information, including PFX certificates that are used to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels πŸ–‹οΈ

The North Korean statesponsored threat actor known as Kimsuky aka Velvet Chollima has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. "Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex meeting page that leveraged.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems πŸ“”

Threat actors from the Silent Ransom Group, aka Luna Moth, are escalating attacks by impersonating IT staff in phone calls and even showing up in person to gain direct access to victim systems.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: CyCOS Project Expands to Support UK SMEs as CIISec Takes Over πŸ“”

From a researchdriven pilot, the Cybersecurity Communities of Support CyCOS is about to be handed over to CIISec.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Chinese Hackers Exploit Iran War to Target Maritime and Energy Companies πŸ“”

ESETs 2026 APT Activity Report suggests Chinabacked APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globe.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI-Generated npm Malware Leaks Its Own GitHub Token πŸ“”

Sloppy AIgenerated npm infostealer leaked its own GitHub token, exposing the operator.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 VMware Carbon Black Pricing Guide 2026: Every Tier, Real Costs & Negotiation Tactics 🌊

Explore the full Carbon Black pricing guide tier costs, tuning labor math, compliance mapping, and the stayvsmigratevsMDR decision framework. The post VMware Carbon Black Pricing Guide 2026 Every Tier, Real Costs Negotiation Tactics appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence AI assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. "The chatgpt.com response renderer trusts Markdown links and Markdown.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Dexcom Warns Stolen G7 Glucose Sensors May Pose Infection, Reading Risks 🦿

Dexcom says stolen G7 sensors from two scrapped lots were sold through unauthorized channels, creating infection and readingfailure risks. The post Dexcom Warns Stolen G7 Glucose Sensors May Pose Infection, Reading Risks appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Illumio Pricing Guide: Real Costs, Hidden Fees & ROI for 2026 🌊

Explore Illumio pricing, hidden costs, switching risks, and cheaper Zero Trust paths. Built for IT Directors negotiating segmentation budgets in 2026. The post Illumio Pricing Guide Real Costs, Hidden Fees ROI for 2026 appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices πŸ–‹οΈ

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center NCSC, consisted of at least 17 million infected devices. More than 200 servers located in the Netherlands acted as the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1