🛡 Cybersecurity & Privacy 🛡 - News
28.2K subscribers
90.9K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🖋️ TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data 🖋️

Cybersecurity researchers have disclosed details of a new campaign dubbed TASKSTOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals WiFi passwords and clipboard contents, takes screenshots, and accepts arbitrary.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📔 Network Segmentation Failures Are Expanding the Corporate Attack Surface 📔

Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 AI Drives Surge in Bot and API Threats 📔

Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AIrelated threats.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns 📔

Gartner warns that CISOs must update incident response playbooks as AIpowered deepfakes make social engineering attacks more convincing and harder to detect.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Google Hit with €403m GDPR Fine Over Location Data Practices 📔

The Irish DPC found that Google users were unaware that their location was being used to influence them with ads.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code 📔

Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign 📔

CloudSEK linked GHAPPIER to a compromised npm package with valid trustedpublishing provenance.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 ShinyHunters Claim Hack of Rival Ransomware Gang Clop 📔

ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds 📔

A new report by ISACA found that 71 of orgs have not run AI incident response exercises as teams face rising pressure.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🖋️ AI Agents Are Rewriting the Rules of Lateral Movement 🖋️

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups 🖋️

Attackers are exploiting a new flaw in onpremises VeloCloud Orchestrator VCO, the server that manages the Edge devices in a VeloCloud SDWAN, Arista said on September 22. The flaw, tracked as CVE202693952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📔 North Korean Attackers Hit 30,000 Devices and Steal $10.7m 📔

WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📢 NCSC talks up agents for cyber defense – but there's an 'inconvenient truth' businesses need to accept 📢

Cyber defenders need to identify the lowestrisk actions that can be automated before making decisions about adoption.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity