πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ One-in-five breaches are now AI-related, IBM warns πŸ“’

While AI threats are rising, enterprises are bolstering cyber resilience capabilities.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ⚑ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks πŸ–‹οΈ

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FOMO in the SOC: Where AI Platforms like Claude Actually Fit πŸ–‹οΈ

AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers the most value. With so many new AI.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS πŸ–‹οΈ

An unknown Chinesethreat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services AWS signin pages on a domain that also hosts the exploit toolkit. ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web πŸ–‹οΈ

The Police National Legal Database PNLD has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day πŸ“”

Chinese actors exploited the critical React2Shell exploit inside a day, while 88 of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Midnight Blizzard Targets Travelers via Captive Portals πŸ“”

Russian actor Storm2945 hijacked hotel captive portals to push fake updates and steal tokens.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” HollowFrame Loader Uses Fake Python DLL to Evade Defender πŸ“”

New HollowFrame loader hid Go code in a fake Python DLL after prestaging Defender exclusions.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Korea’s Largest Telco KT Fined $38m After Femtocell Campaign πŸ“”

Korean telco KT has been fined 39m for a yearlong breach linked to femtocell compromise.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 11 Best AI SOC for Manufacturing in 2026: Compared on IT and OT Coverage 🌊

Explore our practitionerbuilt comparison of AI SOC platforms for manufacturing, ranked on real OTICS coverage and response, not just IT triage. The post 11 Best AI SOC for Manufacturing in 2026 Compared on IT and OT Coverage appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 9 Best AI SOC Tools with Detection Logic as Code: Including Python CI/CD for Detection Rules 🌊

Discover which AI SOC tools support Python CICD detection rules, agentic triage, and vendoragnostic integration. Built for securityconscious CTOs. The post 9 Best AI SOC Tools with Detection Logic as Code Including Python CICD for Detection Rules appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem πŸ¦…

Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, thirdparty integrations, and rapid digital expansion have made the boundary between "inside" and "outside" for the enterprise increasingly difficult to define.  Attackers exploit this ambiguity by scanning continuously for weaknesses across an organization's hardware, software, cloud, and internetfacing assets. The uncomfortable truth security leaders must confront is simple an organization cannot secure what it does not know it has.  Attack surface expansion is frequently framed as a tooling gap, but the evidence points elsewhere toward a persistent, structural failure in attack surface discovery, asset discovery, and visibility.  Why Attack Surface Sprawl Happens  Attack su...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts πŸ–‹οΈ

Malware running as an ordinary user on a Windows machine can sign into a victim's passkeyprotected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Passtakey, Silver Passtakey and Golden Passtakey the strongest targets the master key.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws πŸ–‹οΈ

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access SMA 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users πŸ–‹οΈ

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a crossplatform remote access trojan RAT as part of a sophisticated, targeted software supply chain attack targeting Chinesespeaking environments. One of the packages in question is "libmtop," an unscoped package with the same name as a private Alibaba package.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Claude Opus 5 Vending Test Shows Profit-Driven AI Risks 🦿

Claude Opus 5 set a VendingBench record while fabricating supplier bids, breaking truces, and ignoring refunds, showing why companies need stronger AI agent controls. The post Claude Opus 5 Vending Test Shows ProfitDriven AI Risks appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
🦿 Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities 🦿

Google is testing twiceweekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browsers patch gap. The post Google Tests TwiceWeekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ MSPs urged to patch immediately after N-able issues hotfix for N-central β€˜god mode’ flaw πŸ“’

The authentication bypass flaw in Ncentral could grant threat actors god mode access.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ β€˜I bought the tool to save time, but I did more manual work than before’: Pentesters are finding more bugs with AI than they can fix πŸ“’

Hallucinated exploits and fabricated vulnerabilities are adding to pentester workloads.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Police National Legal Database confirms data leaked on the dark web πŸ“’

The hack has been claimed by the same group as last week's Department for Education breach.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Open Secure AI Alliance Expands at Black Hat: What You Should Know 🦿

The Open Secure AI Alliance introduced SAFE guidelines and open agentsecurity tools at Black Hat, giving enterprises a framework for safer AI deployment. The post Open Secure AI Alliance Expands at Black Hat What You Should Know appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity