πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Apple Photos Privacy Case Advances, With Up to $32.5 Billion Alleged Exposure 🦿

Apples Photos biometric privacy case will proceed after an appeals court declined to review class certification. Heres what remains unresolved. The post Apple Photos Privacy Case Advances, With Up to 32.5 Billion Alleged Exposure appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Briefly Removes Telegram From App Store Over Reported CSAM Violation 🦿

Apple briefly removed Telegram from the App Store over reported CSAM, highlighting moderation failures and the distribution power held by appstore operators. The post Apple Briefly Removes Telegram From App Store Over Reported CSAM Violation appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Challenges UK Demand For Access To Encrypted iCloud Data 🦿

Apple is challenging a UK order reportedly requiring access to encrypted iCloud data, reviving a wider dispute over privacy, security, and lawful access. The post Apple Challenges UK Demand For Access To Encrypted iCloud Data appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Seeks Injunction as OpenAI Blames Tech Giant for Security Lapses 🦿

Apple seeks an injunction against OpenAI as the companies clash over former employees, confidential hardware files, and internal security controls. The post Apple Seeks Injunction as OpenAI Blames Tech Giant for Security Lapses appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 WhatsApp Users Say They’re Being Locked Out of Accounts by Mistake 🦿

Several WhatsApp users say they were wrongly suspended after automated moderation errors, raising concerns about appeals, access, and false positives. The post WhatsApp Users Say Theyre Being Locked Out of Accounts by Mistake appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades 🦿

The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Heres how that split could affect app compatibility, device management, and longterm purchasing decisions. The post OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 OpenAI’s GPT-5.6 Tests Show Prompt-Injection Gains and Agent Risks 🦿

OpenAIs latest GPT5.6 safety results show low failure rates for direct prompt injection but higher success rates when attacks arrive through tools and external content. The post OpenAIs GPT5.6 Tests Show PromptInjection Gains and Agent Risks appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 CrowdStrike Warns AI Adoption Is Creating β€˜Underdefended’ Attack Surfaces 🦿

CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks. The post CrowdStrike Warns AI Adoption Is Creating Underdefended Attack Surfaces appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Canadian Man Pleads Guilty in Snowflake Extortions β™ŸοΈ

A 26yearold Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million ATT customers.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers πŸ–‹οΈ

Attackercontrolled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signedin user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens πŸ–‹οΈ

New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over thirdparty accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication πŸ–‹οΈ

Metabase has warned that a maximumseverity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zeroday. The vulnerability CVSS score 10.0, which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers πŸ–‹οΈ

Attackercontrolled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signedin user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist πŸ–‹οΈ

Nable has released a fresh round of hotfixes for Ncentral as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management RMM product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens πŸ–‹οΈ

New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over thirdparty accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added a criticalseverity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities KEV catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE20268037 CVSS score 9.6, is a command injection flaw that could be weaponized to achieve arbitrary.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication πŸ–‹οΈ

Metabase has warned that a maximumseverity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zeroday. The vulnerability CVSS score 10.0, which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer πŸ–‹οΈ

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver crossplatform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typosquatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist πŸ–‹οΈ

Nable has released a fresh round of hotfixes for Ncentral as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management RMM product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets πŸ–‹οΈ

ClickFixstyle attacks are being used to deliver a Gobased malware capable of stealing cryptocurrency assets, as well as browserstored passwords, Apple iCloud Keychain data, and cached credentials. The macOSfocused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added a criticalseverity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities KEV catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE20268037 CVSS score 9.6, is a command injection flaw that could be weaponized to achieve arbitrary.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity