πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28.5K subscribers
90.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ Mythos Vulnerability Firehose Hits a Human Bottleneck πŸ•΅οΈβ€β™‚οΈ

An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ US Government Accuses Chinese AI Firms of Distilling Frontier Models πŸ•΅οΈβ€β™‚οΈ

US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto πŸ–‹οΈ

The U.S. Department of Justice DoJ on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week πŸ–‹οΈ

Multiple espionagemotivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first inthewild use of BlueMoon has been attributed to the Chinaaligned statesponsored group tracked as APT31 aka Bronze Vinewood, Judgement Panda, JungleBamboo,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” OFAC Sanctions Chinese Scam Platform Xinbi Guarantee πŸ“”

The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key πŸ–‹οΈ

Nearly one in ten of the internetfacing LiteLLM servers that Wiz Research scanned in February accepted sk1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an opensource AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 πŸ–‹οΈ

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence AI model broke into real thirdparty systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Anthropic Reveals Yet Another Cybersecurity Incident πŸ“”

Anthropic has found a fourth case of its model accessing thirdparty systems without authorization.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ OpenAI and Anthropic admit rogue AI agents did more than first thought πŸ“’

The two companies have shared additional details on agent misbehavior.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Cyber researchers issue warning over 'phishing pages that exist only inside the victim’s browser' πŸ“’

A blob URL renders and delivers the phishing page inside the targets own browser, making it harder for security scanners to spot.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities KEV catalog, requiring Federal Civilian Executive Branch FCEB agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below CVE202620079 CVSS score 10.0 An authentication.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline πŸ¦…

Infostealer malware is behind a large share of today's credential compromise and it usually doesn't start with a breach at all. When a security team hears "data breach," the instinct is to look for the moment a database was exfiltrated or a network was penetrated. But more often, the real starting point is a single endpoint infection, often on a personal device, that has nothing to do with the organization's perimeter. By the time stolen credentials show up in a breach notification or a dark web alert, they've already passed through several distinct, mechanical stages. Understanding that pipeline rather than waiting for the final alert is what separates reactive security teams from ones that catch exposure early. How Infostealer Malware Powers the Credential Theft Pipeline? W...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors πŸ“”

The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Cyble Introduces Major Upgrade to its Executive Monitoring Module πŸ¦…

Cyble has rolled out a significant upgrade to Executive Monitoring inside Cyble Vision, bringing unified findings, AIdriven scoring, and expanded alerting together in a single protection suite. Executive monitoring has historically meant stitching together several things at once. An impersonation tool here, a dark web exposure feed there, a reputation score from somewhere else, and alerts that show up in whatever channel each vendor happened to support. Security teams protecting their executives ended up doing the integration work themselves, correlating findings across tools, and reexplaining risk to the board every quarter using numbers that didn't quite agree with each other. That era is over. This release unifies Mentions, Impersonations, Exposures, and a new Surface Mention...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE πŸ–‹οΈ

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances πŸ–‹οΈ

A suspected Russianspeaking cyber actor has been attributed to the use of artificial intelligence AI to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NGMF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193.132," an IP address that has been linked to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks πŸ–‹οΈ

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm GroupIB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” MantaxOtax Android Malware Combines Ransomware With Spyware πŸ“”

MantaxOtax Android malware combines ransomware with extensive spyware capabilities.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” CISA Updates Insider Threat Guide With New Mitigation Advice πŸ“”

CISA has updated its insider threat guide with new advice on remote work, AI and risk detection.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Play Early Access Abused to Push Thousands of Deceptive Android Apps πŸ–‹οΈ

Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Indonesia Hit by Android Banking App-Cloning Campaign πŸ•΅οΈβ€β™‚οΈ

The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity