πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Midnight Blizzard Targets Travelers via Captive Portals πŸ“”

Russian actor Storm2945 hijacked hotel captive portals to push fake updates and steal tokens.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” HollowFrame Loader Uses Fake Python DLL to Evade Defender πŸ“”

New HollowFrame loader hid Go code in a fake Python DLL after prestaging Defender exclusions.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Korea’s Largest Telco KT Fined $38m After Femtocell Campaign πŸ“”

Korean telco KT has been fined 39m for a yearlong breach linked to femtocell compromise.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 11 Best AI SOC for Manufacturing in 2026: Compared on IT and OT Coverage 🌊

Explore our practitionerbuilt comparison of AI SOC platforms for manufacturing, ranked on real OTICS coverage and response, not just IT triage. The post 11 Best AI SOC for Manufacturing in 2026 Compared on IT and OT Coverage appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 9 Best AI SOC Tools with Detection Logic as Code: Including Python CI/CD for Detection Rules 🌊

Discover which AI SOC tools support Python CICD detection rules, agentic triage, and vendoragnostic integration. Built for securityconscious CTOs. The post 9 Best AI SOC Tools with Detection Logic as Code Including Python CICD for Detection Rules appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem πŸ¦…

Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, thirdparty integrations, and rapid digital expansion have made the boundary between "inside" and "outside" for the enterprise increasingly difficult to define.  Attackers exploit this ambiguity by scanning continuously for weaknesses across an organization's hardware, software, cloud, and internetfacing assets. The uncomfortable truth security leaders must confront is simple an organization cannot secure what it does not know it has.  Attack surface expansion is frequently framed as a tooling gap, but the evidence points elsewhere toward a persistent, structural failure in attack surface discovery, asset discovery, and visibility.  Why Attack Surface Sprawl Happens  Attack su...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts πŸ–‹οΈ

Malware running as an ordinary user on a Windows machine can sign into a victim's passkeyprotected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Passtakey, Silver Passtakey and Golden Passtakey the strongest targets the master key.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws πŸ–‹οΈ

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access SMA 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users πŸ–‹οΈ

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a crossplatform remote access trojan RAT as part of a sophisticated, targeted software supply chain attack targeting Chinesespeaking environments. One of the packages in question is "libmtop," an unscoped package with the same name as a private Alibaba package.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Claude Opus 5 Vending Test Shows Profit-Driven AI Risks 🦿

Claude Opus 5 set a VendingBench record while fabricating supplier bids, breaking truces, and ignoring refunds, showing why companies need stronger AI agent controls. The post Claude Opus 5 Vending Test Shows ProfitDriven AI Risks appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
🦿 Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities 🦿

Google is testing twiceweekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browsers patch gap. The post Google Tests TwiceWeekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ MSPs urged to patch immediately after N-able issues hotfix for N-central β€˜god mode’ flaw πŸ“’

The authentication bypass flaw in Ncentral could grant threat actors god mode access.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ β€˜I bought the tool to save time, but I did more manual work than before’: Pentesters are finding more bugs with AI than they can fix πŸ“’

Hallucinated exploits and fabricated vulnerabilities are adding to pentester workloads.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Police National Legal Database confirms data leaked on the dark web πŸ“’

The hack has been claimed by the same group as last week's Department for Education breach.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Open Secure AI Alliance Expands at Black Hat: What You Should Know 🦿

The Open Secure AI Alliance introduced SAFE guidelines and open agentsecurity tools at Black Hat, giving enterprises a framework for safer AI deployment. The post Open Secure AI Alliance Expands at Black Hat What You Should Know appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Gmail’s New Feature Warns You Before Revealing You Were BCC’d 🦿

Gmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address. The post Gmails New Feature Warns You Before Revealing You Were BCCd appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Samsung Will Ban Smart TV Apps Containing Residential Proxy Software 🦿

Samsung plans to ban Smart TV apps containing residential proxy software after researchers found apps could route traffic through users home connections. The post Samsung Will Ban Smart TV Apps Containing Residential Proxy Software appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Chrome to Block Policy-Abusing Extensions on Personal Devices 🦿

Google is developing Chrome protections that could block policyinstalled extensions from hijacking New Tab pages and search settings on personal devices. The post Chrome to Block PolicyAbusing Extensions on Personal Devices appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
🦿 Why Apple’s Recent Crypto Lawsuit Should Worry Australian IT Leaders 🦿

A 1.8 million App Store scam lawsuit tests how much software vetting Australian firms can safely outsource. The post Why Apples Recent Crypto Lawsuit Should Worry Australian IT Leaders appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Project Perception Enters Public Preview: What Security Teams Should Know 🦿

Microsofts Project Perception brings coordinated AI agents into security operations, raising new questions about permissions, oversight, accuracy, and deployment risk. The post Microsoft Project Perception Enters Public Preview What Security Teams Should Know appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ–‹οΈ Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens πŸ–‹οΈ

The commercial phishingasaservice PhaaS toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass MultiFactor Authentication MFA and seize control of user accounts. "Greatness supports AiTM adversaryinthemiddle credential and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity