🛡 Cybersecurity & Privacy 🛡 - News
28.1K subscribers
90.7K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🖋️ Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs 🖋️

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SDWAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SDWAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs 🖋️

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, repoisoning the predictor after the defense has run. MIT CSAIL researchers Danil Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on,.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories 🖋️

Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmlesslooking PDF can finish the job. This week runs on cheap leverage exposed servers, recycled bugs, poisoned agent instructions, remoteaccess tools dressed as support software, and trusted defaults doing attackers a favor. Nothing here is especially mystical.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities 🖋️

Forescout found 22 internetfacing Rockwell Automation programmable logic controllers PLCs in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
1👍1
🖋️ CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps 🖋️

Coinspect has identified CryptoJS.lib.WordArray.random as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's onchain analysis puts the measured theft across two sweeps since late May at a lower bound of.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
1
🖋️ Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses 🖋️

Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dualhop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single thirdparty, including Apple, can determine where the request is originating from.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory 🖋️

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zeroday exploit. It abuses a standard feature built into almost every major AI assistant prefilled deep links. We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages. When a user.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access 🖋️

Attackers broke into an organization's Oracle database through a SQL injection flaw in a publicfacing web application, then installed a postexploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
1
🖋️ AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model 🖋️

Security flaws in agent infrastructure from Amazon Web Services AWS, Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and modellevel guardrails never got a chance to intervene. The affected products include Amazon.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
1
🖋️ Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells 🖋️

Cybersecurity researchers have disclosed details of a "factoryshipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service 🖋️

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomwareasaservice operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild 🖋️

A newly patched security flaw impacting onpremise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency CISA. The vulnerability in question is CVE202663077 CVSS score 9.8, a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity server.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People 🖋️

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least 495,000 from.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures 🖋️

A macOS ClickFix operation spanning more than 250 frontend domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The serverside gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes 🖋️

OpenAI said it disrupted a Cambodiabased scam operation that used its generative artificial intelligence AI chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt 🖋️

Cybersecurity researchers have discovered more than halfadozen services advertisements for illegal access to artificial intelligence AI models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models LLMs, including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "Advertisements for Poison Claude.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports 🖋️

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an opensource control plane for teams of artificial intelligence AI agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and controlplane details through application programming interface API routes.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug 🖋️

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A crosstenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain 🖋️

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchainbased commandandcontrol C2 technique that conceals the C2 server IP address inside a madeup destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianiraui" and "fluidtypeui," has been codenamed NullReceiver by.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch 🖋️

A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of defaultconfigured distributions, and a public exploit ships with prebuilt records for roughly 800 kernel builds. The vulnerability, tracked as CVE202664531 CVSS score 7.8 and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk 🖋️

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attackercontrolled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
1