🛡 Cybersecurity & Privacy 🛡 - News
27.3K subscribers
89.9K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🦿 ClickLock Mac Malware Traps Users in a Three-Day Password Loop 🦿

ClickLock can shut down Mac apps for more than three days while pressuring users to enter a password and stealing sensitive account data in the background. The post ClickLock Mac Malware Traps Users in a ThreeDay Password Loop appeared first on TechRepublic.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🦿 EU Orders Google to Open Android AI Features, Share Search Data With Rivals 🦿

EU rules will make Google share anonymized search data and give rival AI assistants broader access to Android features across Europe. The post EU Orders Google to Open Android AI Features, Share Search Data With Rivals appeared first on TechRepublic.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🖋️ New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 🖋️

Updated July 18, 2026 the two flaws now carry CVE IDs, the full mechanism has been published, a persistentobjectcache condition has surfaced, and a working proofofconcept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 🖋️

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denialofservice bug and named it, published the.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 🖋️

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" fourtier blockchainbased commandandcontrol C2 infrastructure spanning Tron,.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens 🖋️

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft 🖋️

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a subgroup of GoldenEyeDog aka APTQ27, Dragon Breath, and Miuuti Group, a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images 🖋️

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a fourstage payload aligned with OTTERCOOKIE a browser credential and crypto wallet stealer, a file stealer, a.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants 🖋️

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? 🖋️

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man 🖋️

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files 🖋️

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 🖋️

Updated July 18, 2026 the two flaws now carry CVE IDs, the full mechanism has been published, a persistentobjectcache condition has surfaced, and a working proofofconcept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 🖋️

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denialofservice bug and named it, published the.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 🖋️

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" fourtier blockchainbased commandandcontrol C2 infrastructure spanning Tron,.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens 🖋️

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft 🖋️

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a subgroup of GoldenEyeDog aka APTQ27, Dragon Breath, and Miuuti Group, a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images 🖋️

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a fourstage payload aligned with OTTERCOOKIE a browser credential and crypto wallet stealer, a file stealer, a.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants 🖋️

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? 🖋️

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man 🖋️

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity