πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.3K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling πŸ–‹οΈ

Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day others would.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots πŸ–‹οΈ

A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they were building.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory πŸ–‹οΈ

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibecoded PowerShell script for Active Directory AD enumeration. "The script looked for the Domain Controller DC and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating ADReport.html to measure the success of the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 πŸ–‹οΈ

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it python3 m http.server 8080, was still sitting in the readable .bashhistory. From that one lapse, French security firm Lexfo lifted the operator's entire toolkit and pivoted through it to two more.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA has added two maximumseverity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities KEV catalog, following reports of zeroday exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below CVE202648939 A vulnerability in the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 UK and Allies urge critical sectors to improve defences against Russian intelligence targeting 🚨

New advisory highlights Russian state cyber actors global exploitation of poorly configured routers.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Open Directory Exposes Three Evilginx Phishing Operators πŸ“”

Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Pakistani Police Systems Hit by Chinese and Indian Espionage πŸ“”

Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Novel OAuth Client ID Spoofing Technique Targets Cloud Environments πŸ“”

New research reveals cyberattackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Progress Software Warns of "External Security Threat" to ShareFile πŸ“”

Progress Software, the provider of the popular filesharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns πŸ“”

Cybersecurity agencies from 12 countries have warned that Russian statebacked hackers are actively targeting vulnerable routers using weak SNMP credentials.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charges πŸ“”

An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Australian Cyber Agency Warns of Global CMS Exploitation Campaign πŸ“”

Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 The Budget Line That Did Not Exist Last Year: Where AI SOC Sits in a 2027 Plan 🌊

Explore how to fund the new AI SOC budget line through tool consolidation, NIST CSF mapping, and a boardready lossexposure story. The post The Budget Line That Did Not Exist Last Year Where AI SOC Sits in a 2027 Plan appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 AI SOC Pricing: What are the parameters you should account for? The hidden Costs and TCO 🌊

AI SOC pricing rarely matches the quote. Discover the hidden costs, real TCO, and pricing models security leaders must model first. The post AI SOC Pricing What are the parameters you should account for? The hidden Costs and TCO appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Lawyer 🌊

The post Lawyer appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe πŸ“’

UAT11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Why Microsoft paused Patch Tuesday updates for some Dell devices πŸ“’

Select devices running Intel Innovation Platform Framework drivers encountered poor performance.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach 🦿

23andMe will pay 18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people. The post 23andMe Agrees to 18M Settlement With 43 States Over 2023 Data Breach appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft’s β€˜Project Perception’ Could Challenge Anthropic’s Mythos in AI Security 🦿

Microsoft is reportedly developing Project Perception, a lowercost AI security tool that would use multiple models to identify enterprise vulnerabilities. The post Microsofts Project Perception Could Challenge Anthropics Mythos in AI Security appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Critical Zoom Flaw Could Let Attackers Take Over Windows Accounts 🦿

Zoom patched a critical Windows flaw that could enable remote account takeover, along with three highseverity privilegeescalation vulnerabilities. The post Critical Zoom Flaw Could Let Attackers Take Over Windows Accounts appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity