πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.2K subscribers
89.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants πŸ–‹οΈ

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? πŸ–‹οΈ

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man πŸ–‹οΈ

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files πŸ–‹οΈ

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage πŸ–‹οΈ

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on longterm access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Government Agencies Falling Victim to Ransomware Daily, Warns Study πŸ“”

Government organizations are targeted by attackers who know agencies cannot afford disruption to public services.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” 23andMe Faces New Security Mandates in $18m Data Breach Settlement πŸ“”

23andMe has agreed to an 18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Pentest Preparation Guide and Scoping Questionnaire: Scope, Credentials, RFP, and Attestation Workflow 🌊

Explore a complete pentest preparation checklist scope, credentials, RFP, vendor scoring, and the retest and attestation workflow auditors accept. The post Pentest Preparation Guide and Scoping Questionnaire Scope, Credentials, RFP, and Attestation Workflow appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Splunk SOC Detection Engineering: Claimed Coverage vs. Measured Coverage 🌊

Compare 12 enterprise SIEM solutions for 2026 by AI detection, pricing, compliance, and deployment. Vendorneutral rankings from 500 SOC environments. Evaluate now. The post Splunk SOC Detection Engineering Claimed Coverage vs. Measured Coverage appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Health tech firm Craneware admits β€œsignificant volume” of customer and employee data exposed in cyber attack πŸ“’

The incident has been contained and Craneware has launched a probe into the breach.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 AWS Billion-Dollar Software Bug Explained 🦿

An AWS software bug showed some customers billing estimates in the billions and trillions. Here is what failed, why invoices were unaffected, and what IT teams should know. The post AWS BillionDollar Software Bug Explained appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Top 5 Disaster Recovery Companies in 2026 🦿

This is a comprehensive list of the top Disaster Recovery as a Service providers. Use this guide to compare and choose the best solution for you. The post Top 5 Disaster Recovery Companies in 2026 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware πŸ–‹οΈ

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence AI skills or Model Context Protocol MCP servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign πŸ–‹οΈ

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit 1,048 files spanning lure templates, filenamespoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government IDlookup site over WebDAV. What makes it more than a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 πŸ–‹οΈ

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. GroupIB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More πŸ–‹οΈ

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine πŸ–‹οΈ

At least one Russian intelligence service is systematically hijacking internetconnected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Mythos Didn't Break Your Security Program. Your Exposure Window Could. πŸ–‹οΈ

The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AIdriven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction πŸ–‹οΈ

Opening a crafted XZ archive in 7Zip could let an attacker run code on the machine. The flaw, CVE202614266, is a heapbased buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative ZDI detailed it on July 15. A fix shipped on June 25 in 7Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs πŸ–‹οΈ

A solo Russianspeaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's opensource Gemini CLI artificial intelligence AI and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent πŸ–‹οΈ

In an ironic twist, opensource artificial intelligence AI platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity