πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28.5K subscribers
90.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Iran power plant closure is a warning to all businesses: How to respond πŸ“’

After the first attack of its kind, how big is the risk, who does it impact, and how should firms react?.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Grindr to Pay Β£26 Million to Settle U.K. Claims Over HIV Status Data Sharing πŸ–‹οΈ

Online dating app Grindr has opted to pay 26 million 35.1 million to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with thirdparties. Grindr, which is the largest LGBTQ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ“” Trezor Supply Chain Breach Now Impacts 81,000 Customers πŸ“”

Crypto walletmaker Trezor says a data breach at supplier ShipMonk is far worse than originally thought.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ 'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI πŸ“’

Organizations are urged to identify shadow AI use and tighten up security procedures.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Samsung backs Mistral in record-breaking €3 billion funding round as French AI firm targets sovereign AI gains πŸ“’

The French AI company breaks European records, but still trails American rivals with a 21bn valuation.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell πŸ–‹οΈ

Adobe on Monday released security patches to address a maximumseverity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE202675650 CVSS score 10.0, has been codenamed StyleSmuggler by Sansec, which discovered zeroday exploitation starting September 4, 2026. "This update resolves a critical.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a sprawling search engine optimization SEO poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials πŸ“”

CloudSEK has uncovered BigBear 2.0, a new phishingasaservice operation targeting Microsoft 365.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” THost9 Android RAT Pairs Packed Loader With ADB Worm πŸ“”

THost9 hides its payload and uses ADB to spread across exposed Android devices and containers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials πŸ–‹οΈ

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” AI Coding Tools Now a Prime Target for Threat Actors, Google Warns πŸ“”

Google warned that the rapid integration of AIassisted coding tools has significantly expanded software supply chain risks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Grindr Settles UK Data Privacy Claims for Β£26m πŸ“”

Grindr settled UK claims over alleged unlawful processing of sensitive user data.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls πŸ–‹οΈ

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ What It Took to Reach 1 Billion Build Manifests πŸ–‹οΈ

In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 This $30 Tool Helps You Spot Scams Before You Click 🦿

IsThisSpam helps you check suspicious emails, texts, links, and websites before you click or respond. The post This 30 Tool Helps You Spot Scams Before You Click appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
🦿 Before You Paste Anything Into ChatGPT, Check This List 🦿

Before pasting passwords, medical records, source code, or company data into ChatGPT, use this checklist to decide what should stay private. The post Before You Paste Anything Into ChatGPT, Check This List appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 AI Could Shrink the Supply of Exploits Governments Rely On 🦿

AI could accelerate vulnerability discovery, shrinking the pool of exploits governments rely on while speeding up the race between attackers and defenders. The post AI Could Shrink the Supply of Exploits Governments Rely On appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Sanders, Casar Want to Outlaw AI β€˜Superintelligence’ and Pause Advanced AI 🦿

Bernie Sanders and Greg Casar are preparing legislation to ban AI superintelligence and temporarily pause advanced AI development pending federal rules. The post Sanders, Casar Want to Outlaw AI Superintelligence and Pause Advanced AI appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” France Establishes New Government-Focused Cyber Incident Response Unit πŸ“”

After a major cyberattack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Patch Tuesday Sets Another Record With 974 CVEs πŸ•΅οΈβ€β™‚οΈ

Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Attackers Use Multi-Hop Google Redirects for Phishing Campaign πŸ•΅οΈβ€β™‚οΈ

Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity