πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack πŸ–‹οΈ

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks πŸ–‹οΈ

The Federal Communications Commission FCC added foreignproduced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity πŸ–‹οΈ

The Federal Security Service of the Russian Federation FSB on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform that are.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet πŸ–‹οΈ

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft a maintainer phished through a lookalike npm domain and a walletdraining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass πŸ–‹οΈ

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and MultiDomain Security Management Server MDS that has come under active exploitation in the wild. The vulnerability, tracked as CVE202616232 CVSS score 9.3, is an authentication bypass in the SmartConsole login process that.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center FMC Software to its Known Exploited Vulnerabilities KEV catalog, following reports of zeroday exploitation. The vulnerability, assigned CVE202620316 CVSS score 5.3, could permit an unauthenticated, remote attacker to log.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach πŸ–‹οΈ

OpenAI on Tuesday revealed the rogue artificial intelligence AI agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple thirdparty accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than previously.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads πŸ–‹οΈ

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE202666066 CVSS score 9.5, the flaw can expose the Rails process environment and secrets such as secretkeybase, the Rails master key, database passwords, cloud storage credentials,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands πŸ–‹οΈ

Gitea, the selfhosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attackercontrolled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE202660004 CVSS score 9.8, the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Security Budget Planning for 2027: Sizing AI SOC, Compliance Automation, and Managed Security Services 🌊

Discover how to build a defensible 2027 security budget, from the 13 benchmark to NIST CSF allocation. Practical guidance for CISOs and IT Directors The post Security Budget Planning for 2027 Sizing AI SOC, Compliance Automation, and Managed Security Services appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cryptominer Abuses Linux PAM to Hide From SOC Analysts πŸ“”

Cryptomining crew abandoned root to impersonate lowprivileged Linux users and evade SOC alerts.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Case Study: Social Engineering via WhatsApp Against an Insurance Company 🌊

The names of the company, its employees, internal systems, and some technical indicators have been changed or withheld at the clients request. An insurance company received a routine WhatsApp message from someone who said they had just bought a car and wanted to arrange thirdparty liability coverage. Nothing about the request stood out. What followed The post Case Study Social Engineering via WhatsApp Against an Insurance Company appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AiTM Phishing Becomes Top Initial Access Threat to Law Firms πŸ“”

AiTM phishing is now the top entry point into law firms, with identity behind 56 of threats.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 How to assess ROI of an AI SOC? Against Managed SOC, SOAR or a DIY Security SOC 🌊

Discover how to assess AI SOC ROI against managed SOC, SOAR, and DIY models with a boardready formula built for security leaders The post How to assess ROI of an AI SOC? Against Managed SOC, SOAR or a DIY Security SOC appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI and Automation Fall Short of Sysadmin Expectations πŸ“”

Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Inside a ClickFix Attack: How VeiloVPN Hid Its Command Server Inside a Polygon Smart Contract 🌊

CTOs and SOC Directors explore SOAR, XDR, and agentic AI options for 2026 incident response, with pricing, OSS alternatives, and 30day rollout plans. The post Inside a ClickFix Attack How VeiloVPN Hid Its Command Server Inside a Polygon Smart Contract appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages πŸ“”

Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsofts legitimate authentication infrastructure.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Google Releases Patches for 370 Vulnerabilities in Chrome 151 πŸ“”

The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCSC Calls on Vendors to Embed β€˜Forensic Observability’ in Network Devices πŸ“”

The UKs National Cyber Security Centre wants network device makers to improve forensic observability.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” LogoKit Phishing Kit Screenshots Victim Sites in Real Time πŸ“”

LogoKit now builds pervictim phishing pages using live screenshots of the target's real website.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack πŸ“”

TA488 returned with OWA halfclick exploit deploying OWAReaper implant that survived reimaging.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity