πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28.1K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Zscaler and Schwarz Digits team up on sovereign cloud security platform πŸ“’

The sovereign Zero Trust SASE service is aimed at critical sectors such as government, defense, finance, and healthcare.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Head teacher data accessed in Department for Education cyber attack πŸ“’

The incident highlights the continuing vulnerability of the education sector.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Zscaler and Schwarz Digits team up on sovereign cloud security platform πŸ“’

The sovereign Zero Trust SASE service is aimed at critical sectors such as government, defense, finance, and healthcare.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ A new vishing campaign is targeting Microsoft Teams – here's what users need to know πŸ“’

Researchers warn Microsoft Teams users across North America are in the crosshairs.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google Plans Global Rollout of Privacy-Focused Age Signals API 🦿

Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates. The post Google Plans Global Rollout of PrivacyFocused Age Signals API appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Hugging Face Deepfake Tests Raise New Risks for AI Procurement 🦿

Researchers found that seven of nine tested Hugging Face imageediting tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls. The post Hugging Face Deepfake Tests Raise New Risks for AI Procurement appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them 🦿

GitHubs new Actions safeguard pauses potentially malicious workflow runs before execution, leaving repository owners to decide who can approve them and what checks must come first. The post GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Top 8 Penetration Testing Tools to Enhance Your Security in 2026 🦿

Compare the best penetration testing tools for 2026, including pricing, key features, use cases, and top picks for modern security teams today. The post Top 8 Penetration Testing Tools to Enhance Your Security in 2026 appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 The 5 Best VPN Extensions for Chrome 🦿

Looking for the best Chrome VPN extensions in 2026 to enhance your online security and privacy? Dive into our list of toprated VPNs and find your best fit. The post The 5 Best VPN Extensions for Chrome appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Sued After Alleged Fake Crypto Wallet App Cost Users $1.8 Million 🦿

Three investors allege a fake Sparrow Wallet app listed in Apples App Store caused approximately 1.8 million in Bitcoin losses. The post Apple Sued After Alleged Fake Crypto Wallet App Cost Users 1.8 Million appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
🦿 The Hidden Security Problem Holding Enterprise AI Back 🦿

Enterprise AI adoption is accelerating, but new research suggests identity governance is lagging behind. Here's why AI agent identities are becoming a critical security challenge. The post The Hidden Security Problem Holding Enterprise AI Back appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff 🦿

Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs, and automated workflows before the cutoff. The post Microsoft Threat Intelligence Portal Retires in August 4 Checks Before the Cutoff appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Read This Before You Buy That TV Streaming Stick β™ŸοΈ

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a onetime fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AIgenerated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware πŸ–‹οΈ

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a fullscreen nonexistent update sequence to deliver malware as part of a new iteration of the longrunning Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories πŸ–‹οΈ

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database πŸ–‹οΈ

A nowpatched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents πŸ–‹οΈ

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Hkon Mly disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Mly's.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Network Has Become the Control Plane for AI Security πŸ–‹οΈ

Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts πŸ–‹οΈ

South Korean authorities and four security firms have disclosed a statesponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financialsecurity software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT πŸ–‹οΈ

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver BYOVD attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT aka Winos 4.0 for persistent remote access. "In this campaign, the group combines new vulnerabledriver abuse, newly observed abuse of legitimate.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation πŸ–‹οΈ

The Russian threat actors recently linked to the exploitation of a nowpatched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access OWA, to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity