πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28.1K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database πŸ–‹οΈ

A nowpatched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents πŸ–‹οΈ

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Hkon Mly disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Mly's.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Network Has Become the Control Plane for AI Security πŸ–‹οΈ

Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts πŸ–‹οΈ

South Korean authorities and four security firms have disclosed a statesponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financialsecurity software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT πŸ–‹οΈ

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver BYOVD attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT aka Winos 4.0 for persistent remote access. "In this campaign, the group combines new vulnerabledriver abuse, newly observed abuse of legitimate.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation πŸ–‹οΈ

The Russian threat actors recently linked to the exploitation of a nowpatched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access OWA, to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks πŸ–‹οΈ

The Federal Communications Commission FCC added foreignproduced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet πŸ–‹οΈ

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft a maintainer phished through a lookalike npm domain and a walletdraining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center FMC Software to its Known Exploited Vulnerabilities KEV catalog, following reports of zeroday exploitation. The vulnerability, assigned CVE202620316 CVSS score 5.3, could permit an unauthenticated, remote attacker to log.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware πŸ–‹οΈ

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a fullscreen nonexistent update sequence to deliver malware as part of a new iteration of the longrunning Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads πŸ–‹οΈ

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE202666066 CVSS score 9.5, the flaw can expose the Rails process environment and secrets such as secretkeybase, the Rails master key, database passwords, cloud storage credentials,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories πŸ–‹οΈ

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory πŸ–‹οΈ

Cybersecurity researchers have flagged a maximumseverity security flaw in Ruflo, an opensource agent metaharness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE202659726 CVSS score 10.0, impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database πŸ–‹οΈ

A nowpatched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape πŸ–‹οΈ

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three criticalrated flaws is CVE202659309 CVSS score 9.8, which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents πŸ–‹οΈ

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Hkon Mly disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Mly's.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline πŸ–‹οΈ

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to minimize.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Network Has Become the Control Plane for AI Security πŸ–‹οΈ

Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a largescale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts πŸ–‹οΈ

South Korean authorities and four security firms have disclosed a statesponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financialsecurity software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Mythos Asks the Right Question. It Doesn't Answer It. πŸ–‹οΈ

AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity