πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
28.4K subscribers
90.9K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ Cyber Op Targets South Korean Media & Automotive Sectors πŸ•΅οΈβ€β™‚οΈ

A likely North Korean advanced persistent threat APT group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation πŸ–‹οΈ

Google has disclosed that a highseverity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE202658704 CVSS score 8.0, is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Dreamforce 2026 showed AI safety is the new big tech battleground πŸ“’

Differing outlooks on AI safety risks have become clear as leading tech figures hit an impasse on responsible development.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cyber Op Targets South Korean Media & Automotive Sectors πŸ•΅οΈβ€β™‚οΈ

A likely North Korean advanced persistent threat APT group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation πŸ–‹οΈ

Google has disclosed that a highseverity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE202658704 CVSS score 8.0, is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ BragJack Attack Can Turn a Browser's Agentic AI Against It πŸ•΅οΈβ€β™‚οΈ

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ BragJack Attack Can Turn a Browser's Agentic AI Against It πŸ•΅οΈβ€β™‚οΈ

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug πŸ“”

Attackers are exploiting a critical flaw in a thirdparty WooCommerce plugin to upload PHP webshells.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Salesforce doubles down on forward deployed engineers in UK Agentforce push πŸ“’

Specialist Salesforce engineers will be embedded within customer teams.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ UK SMBs are the most vulnerable to cyber attacks πŸ“’

Organizations cite delayed growth and expansion plans, financial damage and missed business opportunities.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ AI Security Spending Jumps as Fear Outpaces Proof of Value πŸ•΅οΈβ€β™‚οΈ

CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Fighting Your Dragons Through Tough Tech Times πŸ•΅οΈβ€β™‚οΈ

Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and selfdoubt and shares how to build meaningful connections during historical tech industry downturns.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ BragJack Attack Can Turn a Browser's Agentic AI Against It πŸ•΅οΈβ€β™‚οΈ

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cyber Op Targets South Korean Media & Automotive Sectors πŸ•΅οΈβ€β™‚οΈ

A likely North Korean advanced persistent threat APT group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Microsoft Issues Emergency Fixes After Massive Patch Tuesday πŸ•΅οΈβ€β™‚οΈ

You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes 🦿

Apple is rolling out new parental controls for iPhone, iPad and Mac, including website approvals, Screen Time changes and expanded safety tools. The post Apple Adds New Parental Controls to iPhone, iPad and Mac Heres What Changes appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V 🦿

Microsoft released an outofband Windows update to fix Remote Desktop, HyperV Linux sharing, and USB audio issues caused by its September patch. The post Microsoft Issues OutofBand Windows Update After September Patch Breaks Remote Desktop, HyperV appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity