πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.3K subscribers
89.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Infosecurity Europe: Business Leaders Lack Understanding of Threat Intelligence, Study Warns πŸ“”

A new Silobreaker and SANS Institute paper examines the IntelligenceStakeholder Gap and what organizations must do to achieve business buyin on threat intelligence.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
🌊 CyberArk Pricing Guide 2026: Real Costs, Hidden Fees & Negotiation Playbook 🌊

Explore the full CyberArk TCO license, professional services, premium support, and the eight hidden cost layers no proposal will ever quote you. The post CyberArk Pricing Guide 2026 Real Costs, Hidden Fees Negotiation Playbook appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
🌊 Netskope Pricing Guide 2026: Actual Costs, Hidden Fees & Negotiation Tactics 🌊

Explore the data CFOs use to justify SASE renewals in 2026. And Learn which seven cost lines to neutralize before you sign your next contract. The post Netskope Pricing Guide 2026 Actual Costs, Hidden Fees Negotiation Tactics appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content πŸ–‹οΈ

Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims' systems. The Minecraftfocused malwareasaservice MaaS campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026 and impersonates Minecraft clients and mods to infect users. In all, 3820.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web πŸ“”

Halcyons Cynthia Kaiser lifts the lid on the dark web market for AI cybercrime tools.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Russian hackers are weaponizing CRMs, Ukraine’s former foreign minister warns πŸ“’

Dr Dmytro Kuleba told IT leaders in London that everyday business software is being actively exploited by nationstates.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Cisco Live 2026: New Security Tools Target AI Threats 🦿

Cisco unveiled Cloud Control, Live Protect, and Hybrid Mesh Firewall at Cisco Live to help enterprises manage AIera IT and security operations. The post Cisco Live 2026 New Security Tools Target AI Threats appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens πŸ–‹οΈ

Cybersecurity researchers have disclosed a oneclick attack via Microsoft Visual Studio Code VS Code that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones," security researcher Ammar Askar said. GitHub supports a feature called GitHub.dev that runs as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP) πŸ–‹οΈ

The Fragmented State of Modern Enterprise Identity Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams, machine identities, and autonomous systems. The result is Identity Dark Matter identity activity that sits outside the visibility of centralized IAM and beyond the reach of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore πŸ–‹οΈ

Assume the breach. Zerodays keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does. That is a question about the shape of your network, and most teams have the shape wrong. HD Moore, creator of Metasploit.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes πŸ–‹οΈ

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE202633829, which impacted the Windows Snipping Tool's msscreensketch URI handler, the newly flagged issue resides in the search URI handler, per Huntress. CVE202633829 refers to a spoofing vulnerability that could expose.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare πŸ–‹οΈ

Cybersecurity researchers have discovered a remote denialofservice exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP2 Bomb by Calif. "The vulnerable behavior exists in each server's default HTTP2 configuration," the company said, adding it was discovered by OpenAI Codex by chaining.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Vulnerability Management Innovator Konvu Wins Cyber Startup Award πŸ“”

Inaugural Infosecurity Europe Cyber Startup Award Winner Impresses Panel with Ability Help Prioritize Vulnerabilities in AI era.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Trump Signs Order Inviting Voluntary Review of Frontier AI Models πŸ“”

Trump's executive order invites voluntary prerelease review of frontier AI models.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: How to Get Boards to Prioritize Cyber Risk Quantification πŸ“”

Cybersecurity leaders major companies discuss how they got support from the board on cyber risk.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Anthropic Expands Mythos Access to 150 More Organizations πŸ“”

Anthropic widens Project Glasswing access to 150 more firms as patching becomes the bottleneck.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of Flaws πŸ“”

The emergence of AI models capable to autonomously find and fix vulnerabilities at scale is having a significant impact on patching management, experts say.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Execs Must Treat Cyber Threats as Statecraft, ISACA Expert Say πŸ“”

Private firms are being targeted by nationstate groups for reasons beyond finance, argued ISACAs Bharat Thakrar.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… How AI-Powered Brand Impersonation Works β€” And Why Traditional Security Misses It Entirely πŸ¦…

For most of the digital era, fraud had friction. It required effort, time, and enough technical inconsistency that security systems or even a careful human could spot the seams. That assumption no longer holds. Brand impersonation has evolved into a scalable, automated industry powered by generative AI. What used to be isolated phishing attempts has become a distributed ecosystem of cloned identities, synthetic media, and disposable infrastructure that can convincingly replicate trusted organizations on a global scale. The uncomfortable reality modern impersonation campaigns don't need to break in anywhere. They only need to look legitimate long enough to be believed. And increasingly, that window is all attackers need. According to the U.S. Federal Trade Commission, consume...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ WhatsApp, Slack Notifications Could Hijack Google Gemini on Android πŸ–‹οΈ

A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly poison its longterm memory. No malicious app on the phone is required. The assistant just had to treat a hostile.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT πŸ–‹οΈ

Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan RAT named DesckVB RAT. "Before the victim ever reaches attackercontrolled infrastructure, the lure routes through DoubleClick, a legitimate Googleowned domain that many security tools are less likely to treat as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity