πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.3K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 New FCC Proposal Pits Phone Privacy Against Fraud Prevention 🦿

The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy. The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Sued Over Hide My Email Privacy Claims 🦿

Apple faces a proposed class action alleging a Hide My Email flaw could expose users real addresses despite the companys privacy claims. The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 AI Hardware, App Store Shifts, and Security Scares Define This Week in Tech 🦿

Catch up on the week's biggest tech news, including Google's app store shakeup, Apple's AI expansion, OpenAI's hardware plans, and critical security threats. The post AI Hardware, App Store Shifts, and Security Scares Define This Week in Tech appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 1Password Lets Claude Sign In Without Revealing Passwords 🦿

1Password's new Claude integration lets AI agents sign in to websites without exposing passwords, adding user approval and credential protection. The post 1Password Lets Claude Sign In Without Revealing Passwords appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Hugging Face Says Autonomous AI System Executed Multi-Stage Cyberattack 🦿

Hugging Face says an autonomous AI agent carried out a cyberattack against its production systems, highlighting the growing role of AI in offensive and defensive cybersecurity. The post Hugging Face Says Autonomous AI System Executed MultiStage Cyberattack appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 ClickLock Mac Malware Traps Users in a Three-Day Password Loop 🦿

ClickLock can shut down Mac apps for more than three days while pressuring users to enter a password and stealing sensitive account data in the background. The post ClickLock Mac Malware Traps Users in a ThreeDay Password Loop appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 EU Orders Google to Open Android AI Features, Share Search Data With Rivals 🦿

EU rules will make Google share anonymized search data and give rival AI assistants broader access to Android features across Europe. The post EU Orders Google to Open Android AI Features, Share Search Data With Rivals appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code πŸ–‹οΈ

Updated July 18, 2026 the two flaws now carry CVE IDs, the full mechanism has been published, a persistentobjectcache condition has surfaced, and a working proofofconcept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests πŸ–‹οΈ

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denialofservice bug and named it, published the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT πŸ–‹οΈ

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" fourtier blockchainbased commandandcontrol C2 infrastructure spanning Tron,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens πŸ–‹οΈ

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft πŸ–‹οΈ

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a subgroup of GoldenEyeDog aka APTQ27, Dragon Breath, and Miuuti Group, a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images πŸ–‹οΈ

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a fourstage payload aligned with OTTERCOOKIE a browser credential and crypto wallet stealer, a file stealer, a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants πŸ–‹οΈ

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? πŸ–‹οΈ

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man πŸ–‹οΈ

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files πŸ–‹οΈ

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code πŸ–‹οΈ

Updated July 18, 2026 the two flaws now carry CVE IDs, the full mechanism has been published, a persistentobjectcache condition has surfaced, and a working proofofconcept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests πŸ–‹οΈ

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denialofservice bug and named it, published the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT πŸ–‹οΈ

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" fourtier blockchainbased commandandcontrol C2 infrastructure spanning Tron,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens πŸ–‹οΈ

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity