πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.3K subscribers
89.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes πŸ–‹οΈ

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE202633829, which impacted the Windows Snipping Tool's msscreensketch URI handler, the newly flagged issue resides in the search URI handler, per Huntress. CVE202633829 refers to a spoofing vulnerability that could expose.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare πŸ–‹οΈ

Cybersecurity researchers have discovered a remote denialofservice exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP2 Bomb by Calif. "The vulnerable behavior exists in each server's default HTTP2 configuration," the company said, adding it was discovered by OpenAI Codex by chaining.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Vulnerability Management Innovator Konvu Wins Cyber Startup Award πŸ“”

Inaugural Infosecurity Europe Cyber Startup Award Winner Impresses Panel with Ability Help Prioritize Vulnerabilities in AI era.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Trump Signs Order Inviting Voluntary Review of Frontier AI Models πŸ“”

Trump's executive order invites voluntary prerelease review of frontier AI models.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: How to Get Boards to Prioritize Cyber Risk Quantification πŸ“”

Cybersecurity leaders major companies discuss how they got support from the board on cyber risk.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Anthropic Expands Mythos Access to 150 More Organizations πŸ“”

Anthropic widens Project Glasswing access to 150 more firms as patching becomes the bottleneck.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of Flaws πŸ“”

The emergence of AI models capable to autonomously find and fix vulnerabilities at scale is having a significant impact on patching management, experts say.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Infosecurity Europe: Execs Must Treat Cyber Threats as Statecraft, ISACA Expert Say πŸ“”

Private firms are being targeted by nationstate groups for reasons beyond finance, argued ISACAs Bharat Thakrar.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… How AI-Powered Brand Impersonation Works β€” And Why Traditional Security Misses It Entirely πŸ¦…

For most of the digital era, fraud had friction. It required effort, time, and enough technical inconsistency that security systems or even a careful human could spot the seams. That assumption no longer holds. Brand impersonation has evolved into a scalable, automated industry powered by generative AI. What used to be isolated phishing attempts has become a distributed ecosystem of cloned identities, synthetic media, and disposable infrastructure that can convincingly replicate trusted organizations on a global scale. The uncomfortable reality modern impersonation campaigns don't need to break in anywhere. They only need to look legitimate long enough to be believed. And increasingly, that window is all attackers need. According to the U.S. Federal Trade Commission, consume...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ WhatsApp, Slack Notifications Could Hijack Google Gemini on Android πŸ–‹οΈ

A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly poison its longterm memory. No malicious app on the phone is required. The assistant just had to treat a hostile.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT πŸ–‹οΈ

Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan RAT named DesckVB RAT. "Before the victim ever reaches attackercontrolled infrastructure, the lure routes through DoubleClick, a legitimate Googleowned domain that many security tools are less likely to treat as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore πŸ–‹οΈ

Assume the breach. Zerodays keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does. That is a question about the shape of your network, and most teams have the shape wrong. HD Moore, creator of Metasploit.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag πŸ–‹οΈ

A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits accounttoken sharing to trusted Microsoft apps. Any other app on the same phone could ask for the signedin user's token and get it, then read email, open files, browse the calendar, and send messages as that user. No password, no login screen, no permission prompt.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) πŸ–‹οΈ

Redis has patched a useafterfree in its blockingclient code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases. Tracked as CVE202623479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple’s 2026 Security Events: iPhone Exploits, Zero-Days Put Millions at Risk 🦿

Apples 2026 security year includes zerodays, iPhone exploit kits, WebKit fixes, and background patches that users and IT teams need to track. The post Apples 2026 Security Events iPhone Exploits, ZeroDays Put Millions at Risk appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Tests Wearable AI Badge for Office Workers 🦿

Microsoft showed Project Solara concept devices at Build 2026, including a wearable AI badge for office workers using AI agents. The post Microsoft Tests Wearable AI Badge for Office Workers appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 CISA Flags 2-Year-Old Oracle WebLogic Vulnerability as Actively Exploited 🦿

CISA added Oracle WebLogic flaw CVE202421182 to its KEV catalog, giving federal agencies until June 4 to patch exposed servers. The post CISA Flags 2YearOld Oracle WebLogic Vulnerability as Actively Exploited appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1