πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.3K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? πŸ–‹οΈ

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man πŸ–‹οΈ

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files πŸ–‹οΈ

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code πŸ–‹οΈ

Updated July 18, 2026 the two flaws now carry CVE IDs, the full mechanism has been published, a persistentobjectcache condition has surfaced, and a working proofofconcept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests πŸ–‹οΈ

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denialofservice bug and named it, published the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT πŸ–‹οΈ

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" fourtier blockchainbased commandandcontrol C2 infrastructure spanning Tron,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens πŸ–‹οΈ

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft πŸ–‹οΈ

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a subgroup of GoldenEyeDog aka APTQ27, Dragon Breath, and Miuuti Group, a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images πŸ–‹οΈ

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a fourstage payload aligned with OTTERCOOKIE a browser credential and crypto wallet stealer, a file stealer, a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants πŸ–‹οΈ

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? πŸ–‹οΈ

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man πŸ–‹οΈ

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files πŸ–‹οΈ

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage πŸ–‹οΈ

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on longterm access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Government Agencies Falling Victim to Ransomware Daily, Warns Study πŸ“”

Government organizations are targeted by attackers who know agencies cannot afford disruption to public services.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” 23andMe Faces New Security Mandates in $18m Data Breach Settlement πŸ“”

23andMe has agreed to an 18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Pentest Preparation Guide and Scoping Questionnaire: Scope, Credentials, RFP, and Attestation Workflow 🌊

Explore a complete pentest preparation checklist scope, credentials, RFP, vendor scoring, and the retest and attestation workflow auditors accept. The post Pentest Preparation Guide and Scoping Questionnaire Scope, Credentials, RFP, and Attestation Workflow appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Splunk SOC Detection Engineering: Claimed Coverage vs. Measured Coverage 🌊

Compare 12 enterprise SIEM solutions for 2026 by AI detection, pricing, compliance, and deployment. Vendorneutral rankings from 500 SOC environments. Evaluate now. The post Splunk SOC Detection Engineering Claimed Coverage vs. Measured Coverage appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Health tech firm Craneware admits β€œsignificant volume” of customer and employee data exposed in cyber attack πŸ“’

The incident has been contained and Craneware has launched a probe into the breach.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 AWS Billion-Dollar Software Bug Explained 🦿

An AWS software bug showed some customers billing estimates in the billions and trillions. Here is what failed, why invoices were unaffected, and what IT teams should know. The post AWS BillionDollar Software Bug Explained appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Top 5 Disaster Recovery Companies in 2026 🦿

This is a comprehensive list of the top Disaster Recovery as a Service providers. Use this guide to compare and choose the best solution for you. The post Top 5 Disaster Recovery Companies in 2026 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity