πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.3K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Indirect Prompt Injection in Web Content Targets AI Agents πŸ“”

Zscaler found sites hiding promptinjection text to manipulate AI agents into crypto payments.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Opera GX Flaw Let Sites Auto-Install Mods to Steal Data πŸ“”

Opera GX flaw let sites automatically install mods to steal data from other pages, now patched.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCA Issues Warning to Parents As Shared Child Photos Exploited by AI Tools πŸ“”

IWF and NCA warn that growing numbers of images and videos are being manipulated into sexual abuse material.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Researchers Claim First Fully Agentic Ransomware: JadePuffer πŸ“”

Researchers have revealed JadePuffer, the first agentic AIpowered ransomware campaign, highlighting how autonomous agents can automate cyberattacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 AI SOC in 500 Real Incidents: What It Handled, What It Escalated, and Where It Still Asks for a Human 🌊

Explore AI security limitations and why a fully autonomous SOC stays unrealistic in 2026, with the red lines that still need a human. The post AI SOC in 500 Real Incidents What It Handled, What It Escalated, and Where It Still Asks for a Human appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 5 Security Operations Problems an AI SOC Solves in Practice: Evidence From 500+ Real Incidents 🌊

Discover the 5 security operations problems an AI SOC solves, with evidence from 500 real incidents. Built for CTOs and security leaders. The post 5 Security Operations Problems an AI SOC Solves in Practice Evidence From 500 Real Incidents appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Mid-Year Threat Trends: What H1 2026 Signals for the Rest of the Year πŸ¦…

The first half of 2026 has given security teams little room to breathe. Ransomware operators kept up a punishing pace. If that wasnt enough, access brokers turned network intrusions into a marketplace, and nationstate activity blurred further into hacktivism and organized cybercrime. Taken together, the numbers point to a threat landscape that isn't just growing louder it's becoming faster, more coordinated, and harder to attribute.  Cyble's monthly and quarterly research has tracked this shift in real time, and the pattern across regions is consistent. In short, attackers are scaling operations while defenders are still catching up. These threat intelligence trends 2026 also provide an early look at the top cyber threats 2026 and what organizations should expect during the remainde...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Government Launches Cyber Resilience Pledge, Claiming 60+ Signatories πŸ“”

More than 60 organizations, including MS, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businesses.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Government Launches Cyber Resilience Pledge, Claiming 60+ Signatories πŸ“”

More than 60 organizations, including MS, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businesses.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2πŸ‘Ž1
πŸ“’ This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June πŸ“’

The Gentlemen, a ransomware a service operator, now accounts for 17 of published attacks.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ NCSC issues warning over Russian intelligence-backed threat group πŸ“’

The advisory comes as the government cracks down on groups involved in destructive cyber and hybrid operations.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Meta Removes Muse Image Instagram Feature After Consent Backlash 🦿

Meta scrapped a Muse Image feature days after launch following backlash over consent, privacy, and the use of public Instagram photos. The post Meta Removes Muse Image Instagram Feature After Consent Backlash appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Fake Bank Apps Let Scammers Control Android Phones in Southeast Asia 🦿

RedHook malware uses fake banking and government apps to steal data and control Android phones, with attacks confirmed in Vietnam and Indonesia so far. The post Fake Bank Apps Let Scammers Control Android Phones in Southeast Asia appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Get Peace of Mind: Protect Data for Life With BigMind DR for $59.99 🦿

With a lifetime subscription to BigMIND DR, you can recover your data for 83 off the regular price of 357. The post Get Peace of Mind Protect Data for Life With BigMind DR for 59.99 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Lessons Learned from CISA’s Recent GitHub Leak β™ŸοΈ

The Cybersecurity and Infrastructure Security Agency CISA has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials including AWS Govcloud keys in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks πŸ–‹οΈ

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or ObjectiveCbased wrappers, CrashStealer is implemented in native C, according to Jamf Threat Labs. "It validates the victim's login password locally before.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found πŸ–‹οΈ

Google and Microsoft have pulled ModHeader, a popular headerediting extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsinghistory collector built into its official store version. The collector was dormant. An empty allowlist kept it switched off, and no proof has emerged that it ever gathered or sent a single browsing domain. The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More πŸ–‹οΈ

Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email πŸ–‹οΈ

Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. When it works, the person reads an ordinarylooking reply and never learns their assistant was tampered with. The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft πŸ–‹οΈ

A new phishingasaservice PhaaS operation called Forg365 is using a combination of device code phishing, adversaryinthemiddle AitM tactics, antibot evasion, artificial intelligence AIassisted lure creation, and postcompromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing 400 a month or 3,800 per year, attack chains leverage phishing.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling πŸ–‹οΈ

Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day others would.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity