πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.3K subscribers
89.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels πŸ–‹οΈ

The North Korean statesponsored threat actor known as Kimsuky aka Velvet Chollima has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. "Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex meeting page that leveraged.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems πŸ“”

Threat actors from the Silent Ransom Group, aka Luna Moth, are escalating attacks by impersonating IT staff in phone calls and even showing up in person to gain direct access to victim systems.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: CyCOS Project Expands to Support UK SMEs as CIISec Takes Over πŸ“”

From a researchdriven pilot, the Cybersecurity Communities of Support CyCOS is about to be handed over to CIISec.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Chinese Hackers Exploit Iran War to Target Maritime and Energy Companies πŸ“”

ESETs 2026 APT Activity Report suggests Chinabacked APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globe.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI-Generated npm Malware Leaks Its Own GitHub Token πŸ“”

Sloppy AIgenerated npm infostealer leaked its own GitHub token, exposing the operator.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 VMware Carbon Black Pricing Guide 2026: Every Tier, Real Costs & Negotiation Tactics 🌊

Explore the full Carbon Black pricing guide tier costs, tuning labor math, compliance mapping, and the stayvsmigratevsMDR decision framework. The post VMware Carbon Black Pricing Guide 2026 Every Tier, Real Costs Negotiation Tactics appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence AI assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. "The chatgpt.com response renderer trusts Markdown links and Markdown.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Dexcom Warns Stolen G7 Glucose Sensors May Pose Infection, Reading Risks 🦿

Dexcom says stolen G7 sensors from two scrapped lots were sold through unauthorized channels, creating infection and readingfailure risks. The post Dexcom Warns Stolen G7 Glucose Sensors May Pose Infection, Reading Risks appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Illumio Pricing Guide: Real Costs, Hidden Fees & ROI for 2026 🌊

Explore Illumio pricing, hidden costs, switching risks, and cheaper Zero Trust paths. Built for IT Directors negotiating segmentation budgets in 2026. The post Illumio Pricing Guide Real Costs, Hidden Fees ROI for 2026 appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices πŸ–‹οΈ

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center NCSC, consisted of at least 17 million infected devices. More than 200 servers located in the Netherlands acted as the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools πŸ–‹οΈ

Three years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good shorthand for the work at the time assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor. A Security Growth Platform is the more precise name for what MSPs and MSSPs need from the software.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimatelooking remote web UI. The tool, named codexuiandroid, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository. What.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts πŸ–‹οΈ

Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location features on WordPress sites. It is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: AI SOCs Will Still Need SOC Analysts, Security Vendors Say πŸ“”

Top cybersecurity vendors said AI won't replace entrylevel only routine tickettaking and triage.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” FSB Group Gamaredon Hides Worm in Windows Data Streams πŸ“”

FSBlinked Gamaredon concealed a fileless worm in NTFS data streams to spy on Ukraine targets.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Attackers Abuse Shared Content for ChatGPT Phishing Campaign πŸ“”

Push Security says threat actors are delivering malware hosted on chatgpt.coms domain.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Palo Alto Warns High-Severity Bug Is Being Actively Exploited πŸ“”

A vulnerability in Palo Alto Networks PANOS software is being exploited in attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: OWASP Forms New Agentic Research Council πŸ“”

OWASPs new Agentic Research Council will aim to connect academic work to operational realities on agentic AI security.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Abnormal Security Pricing Guide 2026: Actual Costs, Modules, and What Enterprises Really Pay 🌊

Explore verified Abnormal Security pricing bands, 8lever negotiation playbook, and competitor comparisons across Defender, Mimecast, and Sublime. The post Abnormal Security Pricing Guide 2026 Actual Costs, Modules, and What Enterprises Really Pay appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Tabletop Exercise to Test How CISOs Respond to Major Supermarket Cyber-Attack πŸ“”

Semperis is set to bring Enter the War Room A Tabletop Experience to Infosecurity Europe to help cybersecurity leaders prepare to face real incidents.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Critical Flowise Flaw Gives Attackers Full Server Control πŸ“”

Obsidian publishes PoC for a 1click Flowise RCE that can fully compromise selfhosted servers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity