πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Gmail’s New Feature Warns You Before Revealing You Were BCC’d 🦿

Gmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address. The post Gmails New Feature Warns You Before Revealing You Were BCCd appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Samsung Will Ban Smart TV Apps Containing Residential Proxy Software 🦿

Samsung plans to ban Smart TV apps containing residential proxy software after researchers found apps could route traffic through users home connections. The post Samsung Will Ban Smart TV Apps Containing Residential Proxy Software appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Chrome to Block Policy-Abusing Extensions on Personal Devices 🦿

Google is developing Chrome protections that could block policyinstalled extensions from hijacking New Tab pages and search settings on personal devices. The post Chrome to Block PolicyAbusing Extensions on Personal Devices appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
🦿 Why Apple’s Recent Crypto Lawsuit Should Worry Australian IT Leaders 🦿

A 1.8 million App Store scam lawsuit tests how much software vetting Australian firms can safely outsource. The post Why Apples Recent Crypto Lawsuit Should Worry Australian IT Leaders appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Project Perception Enters Public Preview: What Security Teams Should Know 🦿

Microsofts Project Perception brings coordinated AI agents into security operations, raising new questions about permissions, oversight, accuracy, and deployment risk. The post Microsoft Project Perception Enters Public Preview What Security Teams Should Know appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ–‹οΈ Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens πŸ–‹οΈ

The commercial phishingasaservice PhaaS toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass MultiFactor Authentication MFA and seize control of user accounts. "Greatness supports AiTM adversaryinthemiddle credential and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks πŸ–‹οΈ

A credentialstealing npm worm that first appeared in keyv6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access πŸ–‹οΈ

Cybersecurity researchers have disclosed details of an active, multiwave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management RMM programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKESCREEN by Securonix Threat.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted πŸ–‹οΈ

The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nationstate actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as "script kiddies," sat at the other end, running public.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent πŸ–‹οΈ

Google deleted three AI agent workflows from its Agent Development Kit ADK Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged codefixing agent. The researchers said the public agent could be promptinjected into posting adkissuefix as adkbot. They identified the bot as a collaborator, so that comment satisfied.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root πŸ–‹οΈ

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE202658048 CVSS 4.0 score 9.4 and affects.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT πŸ–‹οΈ

A new Russian loaderasaservice LaaS codenamed DOUBLECUP has been using ClickFix lures as a way to stage malwarelaced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Monday added a highseverity security flaw impacting Nable Ncentral to its Known Exploited Vulnerabilities KEV catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE202618577 CVSS score 8.2, is a case of incomplete patching for CVE202618556 CVSS score 8.2 that allows.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” WhatsApp Scam Hijacks Accounts via Linked Devices Feature πŸ“”

WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions πŸ“”

Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” Cloud and SaaS Environments Now Top Targets for Attackers πŸ“”

Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI Accounts for Over Half of Cybercrime in Africa, Says Interpol πŸ“”

Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK’s Police National Legal Database Reveals Data Breach πŸ“”

The UKs Police National Legal Database and Ask the Police service have been breached.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 UnderDefense MAXI Notifications – Officially Published in the Slack Marketplace 🌊

The UnderDefense Notifications Slack app has completed Slacks full marketplace review. It is now publicly listed, verified, and searchable under the UnderDefense name. Security teams connecting their workspaces will no longer see an app not approved by Slack warning during setup. What Changed The app itself, the connection flow, and the underlying data handling are The post UnderDefense MAXI Notifications Officially Published in the Slack Marketplace appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 MITRE ATT&CK Coverage Comparison: How to Score AI SOC Vendors on Technique Detection Before You Buy 🌊

Discover how to prove AI SOC MITRE ATTCK cloud coverage with adversary emulation, confidence scoring, and onprem telemetry options for compliance. The post MITRE ATTCK Coverage Comparison How to Score AI SOC Vendors on Technique Detection Before You Buy appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity