πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root πŸ–‹οΈ

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE202658048 CVSS 4.0 score 9.4 and affects.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT πŸ–‹οΈ

A new Russian loaderasaservice LaaS codenamed DOUBLECUP has been using ClickFix lures as a way to stage malwarelaced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Monday added a highseverity security flaw impacting Nable Ncentral to its Known Exploited Vulnerabilities KEV catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE202618577 CVSS score 8.2, is a case of incomplete patching for CVE202618556 CVSS score 8.2 that allows.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” WhatsApp Scam Hijacks Accounts via Linked Devices Feature πŸ“”

WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions πŸ“”

Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” Cloud and SaaS Environments Now Top Targets for Attackers πŸ“”

Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI Accounts for Over Half of Cybercrime in Africa, Says Interpol πŸ“”

Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK’s Police National Legal Database Reveals Data Breach πŸ“”

The UKs Police National Legal Database and Ask the Police service have been breached.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 UnderDefense MAXI Notifications – Officially Published in the Slack Marketplace 🌊

The UnderDefense Notifications Slack app has completed Slacks full marketplace review. It is now publicly listed, verified, and searchable under the UnderDefense name. Security teams connecting their workspaces will no longer see an app not approved by Slack warning during setup. What Changed The app itself, the connection flow, and the underlying data handling are The post UnderDefense MAXI Notifications Officially Published in the Slack Marketplace appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 MITRE ATT&CK Coverage Comparison: How to Score AI SOC Vendors on Technique Detection Before You Buy 🌊

Discover how to prove AI SOC MITRE ATTCK cloud coverage with adversary emulation, confidence scoring, and onprem telemetry options for compliance. The post MITRE ATTCK Coverage Comparison How to Score AI SOC Vendors on Technique Detection Before You Buy appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ CMMC phase 2 Is suspended. The liability It created for MSPs isn't πŸ“’

Why the CMMC regulation is not dead and what MSPs need to do about it.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“’ Rubrik teams up with Wipro to launch 'enterprise resilience as a service' scheme πŸ“’

The new joint service aims to sharpen enterprise cyber resilience and recovery capabilities.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ 'The easiest way into a company isn't always through a vulnerability anymore': Hackers are building a global insider threat recruitment network – and they’re even offering referral bonuses πŸ“’

Cyber criminals have professionalized the recruitment of company employees to gain access to sensitive information.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Why quantum-ready data protection belongs in the channel portfolio πŸ“’

Quantumready, datacentric protection is the channels next major differentiator.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Attacks on US water systems could be the tip of the iceberg, cyber experts warn πŸ“’

Internetexposed programmable logic controllers are also found in electric utilities, manufacturing and transportation.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agents πŸ“’

Interagent collaboration is a serious cause for concern, says security expert.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Cyber criminals are selling discount AI tokens on underground forums πŸ“’

Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ β€˜Shai-Hulud: Here We Go Again’: Thousands of npm packages compromised in β€˜Chaindrop’ malware campaign where hackers taunt victims πŸ“’

The Chaindrop infostealer is a variant of the notorious ShaiHulud malware strain.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Cyber resilience 101: what it means and why Dell PowerProtect One is a vital piece of the puzzle πŸ“’

Cyber resilience is now a boardlevel priority, and solutions like Dell PowerProtect One can help make all the difference.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Microsoft forks out record-breaking sums with expanded bug bounty program πŸ“’

Hundreds of security researchers won a share of 20 million after the tech giant expanded its bug hunting scheme.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity