πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
27.7K subscribers
90.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ OWASP Flags Top AI Skill Risks in New Security Blueprint πŸ•΅οΈβ€β™‚οΈ

The Open Worldwide Application Security Project has a brandnew top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI addons.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Calling on Cyber Pros to Help Defend City Hall πŸ•΅οΈβ€β™‚οΈ

Government agencies with smaller budgets need support and here's how you can help.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ OpenAI Adds Controls That Should've Been There Already πŸ•΅οΈβ€β™‚οΈ

The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 πŸ–‹οΈ

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence AIpowered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot πŸ–‹οΈ

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boottime remediation driver to perform arbitrary kernellevel file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys Boot Time Removal Tool, is a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet πŸ–‹οΈ

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Androidbased vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multistage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the builtin updaters of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Wazuh and AI For Enhanced SOC Workflows πŸ–‹οΈ

Artificial Intelligence AI has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decisionmaking. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 πŸ–‹οΈ

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure πŸ–‹οΈ

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE202619478 CVSS score 9.4, a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution πŸ–‹οΈ

Update The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment. It also noted, "this vulnerability was not.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” North Korean Hackers Tied to Rust Supply Chain Attack πŸ“”

Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” New Agent Tesla Malware Variant Boosts Evasion Capabilities πŸ“”

An Agent Tesla v4 malware campaign used novel emojibased code obfuscation to evade detection, KnowBe4 has revealed.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cybersecurity Job Ads Requiring AI Skills Double πŸ“”

An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 9 Best AI SOC for Healthcare With HIPAA-Compliant Threat Detection Across Cloud and On-Premises 🌊

Compare the 9 best AI SOC platforms for healthcare with HIPAAcompliant threat detection across cloud and onpremises. Evaluate vendors before you buy. The post 9 Best AI SOC for Healthcare With HIPAACompliant Threat Detection Across Cloud and OnPremises appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 What an External Penetration Test Found: Unauthenticated Root and a Live Botnet on a UniFi OS Appliance 🌊

Discover how to score 3to5 agentic AI SOC platforms on depth, autonomy, and lockin. A practitioner framework built for security leaders. The post What an External Penetration Test Found Unauthenticated Root and a Live Botnet on a UniFi OS Appliance appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 AI SOC Scalability and Total Cost of Ownership: The Comparison Framework Buyers Use Before a 3-Year Commitment 🌊

Discover the real 3year cost of an agentic SOC vs an inhouse build. Learn the framework security leaders use before signing a long contract. The post AI SOC Scalability and Total Cost of Ownership The Comparison Framework Buyers Use Before a 3Year Commitment appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 How a Credit Union’s IT Team Achieved 24Γ—7 Security Coverage and Discovered a Hidden Firewall Gap 🌊

The post How a Credit Unions IT Team Achieved 247 Security Coverage and Discovered a Hidden Firewall Gap appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates πŸ¦…

Ransomware rarely appears out of nowhere. Before encryption, extortion, or data theft begins, attackers often spend time establishing access, stealing credentials, moving laterally, and identifying valuable systems. These activities occur during the ransomware preexecution phase, when malicious activity may be difficult to distinguish from legitimate administration.  For security teams, understanding ransomware attack vectors, ransomware initial access methods, and how ransomware evades detection is critical. Endpoint security blind spots can give attackers the time they need to prepare an attack without triggering an obvious alarm.  Here are five areas where ransomware activity can remain hidden before detonation.  1. Remote Access Tools A Favorite Ransomware Attack Vector  V...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait 🦿

Googles new Android verification flow adds a 24hour wait for apps from unverified developers as broader identity checks approach. The post Google Tightens Android Sideloading Unverified Apps Now Face a 24Hour Wait appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity