πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 πŸ–‹οΈ

Device code phishing the abuse of the OAuth 2.0 device authorization grant to steal access tokens has evolved from a niche redteam technique to an industrialscale threat in under six months. Designed for inputconstrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and usecases that it wasn't originally.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks πŸ–‹οΈ

Palo Alto Networks' Unit 42 says a Chinesespeaking threat actor used DeepSeek through the opensource Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internetfacing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations πŸ–‹οΈ

Anthropic on Thursday became the latest artificial intelligence AI company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks πŸ“”

AWS has linked North Korea to the axios campaign to other attacks on npm libraries.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies πŸ–‹οΈ

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The OpenAI and Anthropic containment breaches are a bit spooky, but also quite silly πŸ“’

An AI leaving notes to future versions of itself is pure scifi forgetting to lock down an environment is prosaic.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm πŸ–‹οΈ

Cybersecurity researchers have shed light on a previously undocumented Gobased loader framework called HollowFrame and a Rustbased malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spearphishing message containing a link to an encrypted archive, which holds a Windows Shortcut LNK. Executing the file triggers a multistage chain that.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical 🦿

Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk πŸ–‹οΈ

A Chinesespeaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 AI SOC and Analyst Retention: Moving Senior Engineers Off Alert Triage and Onto Work Worth Keeping Them For 🌊

Is SOAR dead? Discover why playbooks stall on investigation and how an AI SOC reasons per alert to cut noise. The post AI SOC and Analyst Retention Moving Senior Engineers Off Alert Triage and Onto Work Worth Keeping Them For appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits πŸ“”

A Chinesespeaking threat actor has been using DeepSeeks AI models to orchestrate cyberattacks targeting Asian organizations.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites πŸ–‹οΈ

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browserside tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction πŸ–‹οΈ

Adobe has released security updates to address a maximumseverity security flaw in Campaign Classic ACC, its enterprisefocused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE202648449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware πŸ–‹οΈ

A fake browser update served over hijacked hotel WiFi has been used to deliver CornFlake, a remote access trojan RAT that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm2945. It assesses Storm2945 to be an operational subcluster of Midnight Blizzard, also known as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ This month in security with Tony Anscombe – July 2026 edition πŸš€

OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AIdriven supply chain threat made for a packed July roundup.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes πŸ–‹οΈ

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about 70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoinonly hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator PRNG.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
πŸ–‹οΈ N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete πŸ–‹οΈ

Nable said attackers exploited an authentication bypass in Ncentral to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE202618577 affects Ncentral builds prior to 2026.3.1.7. Nable shipped build 2026.3.1.7 on August 2 as the first unaffected version. Ncentral is the remote monitoring and management platform.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code πŸ–‹οΈ

Three highseverity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence AI supply chain to security risk. "These vulnerabilities are bypassing trustremotecode, the safeguard designed to stop unreviewed code from running in the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable πŸ–‹οΈ

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE202617583 and rates it.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked πŸ“”

A hacker has drained nearly 89m from Coldcard Bitcoin wallets after exploiting a legacy bug.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
πŸ“’ One-in-five breaches are now AI-related, IBM warns πŸ“’

While AI threats are rising, enterprises are bolstering cyber resilience capabilities.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity