πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28.1K subscribers
90.7K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures πŸ–‹οΈ

A macOS ClickFix operation spanning more than 250 frontend domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The serverside gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes πŸ–‹οΈ

OpenAI said it disrupted a Cambodiabased scam operation that used its generative artificial intelligence AI chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt πŸ–‹οΈ

Cybersecurity researchers have discovered more than halfadozen services advertisements for illegal access to artificial intelligence AI models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models LLMs, including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "Advertisements for Poison Claude.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports πŸ–‹οΈ

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an opensource control plane for teams of artificial intelligence AI agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and controlplane details through application programming interface API routes.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug πŸ–‹οΈ

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A crosstenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain πŸ–‹οΈ

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchainbased commandandcontrol C2 technique that conceals the C2 server IP address inside a madeup destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianiraui" and "fluidtypeui," has been codenamed NullReceiver by.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch πŸ–‹οΈ

A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of defaultconfigured distributions, and a public exploit ships with prebuilt records for roughly 800 kernel builds. The vulnerability, tracked as CVE202664531 CVSS score 7.8 and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk πŸ–‹οΈ

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attackercontrolled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup πŸ–‹οΈ

An unauthenticated attacker can read any file the service account can access on Gitea, the selfhosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Orgmode markup are enough. The flaw is fixed in Gitea 1.27.1. The fileread flaw is tracked as CVE202659774, rated Critical with a CVSS score of 9.8, and received its.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Leaked n8n API Tokens Exposed Live Instances to Credential Theft πŸ–‹οΈ

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
🌊 10 Best AI SOC Vendors without Lock-In Contracts : Data Portability Clauses, Log Ownership, and Exit Rights Compared Across 6 Platforms 🌊

Which AI SOC vendors let you own your logs and leave freely? Discover data portability, sovereignty, and exit clauses compared across 6 platforms. The post 10 Best AI SOC Vendors without LockIn Contracts Data Portability Clauses, Log Ownership, and Exit Rights Compared Across 6 Platforms appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause πŸ–‹οΈ

OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence AI model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it's implementing security controls for highercapability models and associated activities, such as isolated.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials πŸ–‹οΈ

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code VS Code extension named Solidity Pro "soliditypro" that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below helperbeeps.soliditypro web3devtoolsx.soliditypro Although neither of the extensions is now available on Open VSX, the GitHub repository.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” US Sanctions Iranian $6bn Crypto β€œExchange” Shelbit πŸ“”

TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Swiss authorities urge calm amid fears over SharePoint credential leak πŸ“’

The Federal Office for Information Technology and Telecommunication said that while accounts have been compromised, no sensitive data has been accessed.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Swiss authorities urge calm amid fears over SharePoint credential leak πŸ“’

The Federal Office for Information Technology and Telecommunication said that while accounts have been compromised, no sensitive data has been accessed.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” β€œGhostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls πŸ“”

Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Go-Based macOS Malware Steals Crypto and Secrets πŸ“”

A macOS malware variant has been detected stealing crypto, passwords and more.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 11 Most Affordable AI SOC Platforms in 2026: What Each Pricing Tier Actually Covers for Small and Mid-Market Teams 🌊

Explore affordable AI SOC platforms with 247 coverage. See real costs, tier gaps, and compliance support for CTOs and security leads. The post 11 Most Affordable AI SOC Platforms in 2026 What Each Pricing Tier Actually Covers for Small and MidMarket Teams appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Trust your AI agents? New research shows β€˜memory poisoning’ can dupe them into β€˜remembering’ fake information – and it’s a huge security risk πŸ“’

Memory poisoning allows hidden text on a webpage to be treated as fact and used to make harmful decisions.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA πŸ–‹οΈ

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloudsynced passkey system from malware already on the victim's machine, and used a .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity