πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet πŸ–‹οΈ

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft a maintainer phished through a lookalike npm domain and a walletdraining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass πŸ–‹οΈ

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and MultiDomain Security Management Server MDS that has come under active exploitation in the wild. The vulnerability, tracked as CVE202616232 CVSS score 9.3, is an authentication bypass in the SmartConsole login process that.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center FMC Software to its Known Exploited Vulnerabilities KEV catalog, following reports of zeroday exploitation. The vulnerability, assigned CVE202620316 CVSS score 5.3, could permit an unauthenticated, remote attacker to log.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach πŸ–‹οΈ

OpenAI on Tuesday revealed the rogue artificial intelligence AI agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple thirdparty accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than previously.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads πŸ–‹οΈ

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE202666066 CVSS score 9.5, the flaw can expose the Rails process environment and secrets such as secretkeybase, the Rails master key, database passwords, cloud storage credentials,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands πŸ–‹οΈ

Gitea, the selfhosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attackercontrolled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE202660004 CVSS score 9.8, the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Security Budget Planning for 2027: Sizing AI SOC, Compliance Automation, and Managed Security Services 🌊

Discover how to build a defensible 2027 security budget, from the 13 benchmark to NIST CSF allocation. Practical guidance for CISOs and IT Directors The post Security Budget Planning for 2027 Sizing AI SOC, Compliance Automation, and Managed Security Services appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cryptominer Abuses Linux PAM to Hide From SOC Analysts πŸ“”

Cryptomining crew abandoned root to impersonate lowprivileged Linux users and evade SOC alerts.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Case Study: Social Engineering via WhatsApp Against an Insurance Company 🌊

The names of the company, its employees, internal systems, and some technical indicators have been changed or withheld at the clients request. An insurance company received a routine WhatsApp message from someone who said they had just bought a car and wanted to arrange thirdparty liability coverage. Nothing about the request stood out. What followed The post Case Study Social Engineering via WhatsApp Against an Insurance Company appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AiTM Phishing Becomes Top Initial Access Threat to Law Firms πŸ“”

AiTM phishing is now the top entry point into law firms, with identity behind 56 of threats.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 How to assess ROI of an AI SOC? Against Managed SOC, SOAR or a DIY Security SOC 🌊

Discover how to assess AI SOC ROI against managed SOC, SOAR, and DIY models with a boardready formula built for security leaders The post How to assess ROI of an AI SOC? Against Managed SOC, SOAR or a DIY Security SOC appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI and Automation Fall Short of Sysadmin Expectations πŸ“”

Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Inside a ClickFix Attack: How VeiloVPN Hid Its Command Server Inside a Polygon Smart Contract 🌊

CTOs and SOC Directors explore SOAR, XDR, and agentic AI options for 2026 incident response, with pricing, OSS alternatives, and 30day rollout plans. The post Inside a ClickFix Attack How VeiloVPN Hid Its Command Server Inside a Polygon Smart Contract appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages πŸ“”

Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsofts legitimate authentication infrastructure.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Google Releases Patches for 370 Vulnerabilities in Chrome 151 πŸ“”

The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” NCSC Calls on Vendors to Embed β€˜Forensic Observability’ in Network Devices πŸ“”

The UKs National Cyber Security Centre wants network device makers to improve forensic observability.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” LogoKit Phishing Kit Screenshots Victim Sites in Real Time πŸ“”

LogoKit now builds pervictim phishing pages using live screenshots of the target's real website.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack πŸ“”

TA488 returned with OWA halfclick exploit deploying OWAReaper implant that survived reimaging.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Anthropic Reveals Claude Escaped Testing, Breaching Three Companies πŸ“”

Anthropic has revealed that Claude AI models broke free of sandbox to compromise thirdparty organizations.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”2
πŸ“’ Anthropic joins OpenAI in admitting loss of control in cybersecurity tests πŸ“’

The company found Claude AI had escaped containment three times and targeted other organizations.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined πŸ–‹οΈ

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity