TGViewer
Channel Public Channel
๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

@cibsecurity

๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
91.2K

Showing posts older than #90393 ยท Back to latest

Older Posts 20 shown
Post #90392 261
๐Ÿ“” NIST Seeks Public Input on AI-Ready NVD Modernization ๐Ÿ“”

The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AIpowered vulnerability research.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine NIST Seeks Public Input on AI-Ready NVD Modernization The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research
Post #90391 158
๐Ÿ“” Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure ๐Ÿ“”

Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastruc Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
Post #90388 167
๐Ÿ–‹๏ธ Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS ๐Ÿ–‹๏ธ

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance ASA Software and Secure Firewall Threat Defense FTD Software has been exploited in the wild. The highseverity flaw, tracked as CVE202620349 CVSS score 8.6, is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90387 203
๐Ÿ–‹๏ธ ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access ๐Ÿ–‹๏ธ

The security researcher going by the name Chaotic Eclipse aka INFINITE NIGHTMARE, MSNightmare, and NightmareEclipse has released a proofofconcept PoC for a new Microsoft zeroday called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE202650656 CVSS score 7.8, otherwise known as RoguePlanet. RoguePlanet has been described.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90386 174
๐Ÿ–‹๏ธ SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code ๐Ÿ–‹๏ธ

SAP has released patches to address a maximumseverity security flaw impacting Commerce Cloud Data Hub Adapter that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE202658231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90385 154
๐Ÿ–‹๏ธ Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations ๐Ÿ–‹๏ธ

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credentialstealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90384 152
๐Ÿ–‹๏ธ Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ๐Ÿ–‹๏ธ

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE202659310 CVSS score 9.8, a directorytraversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90383 152
๐Ÿ–‹๏ธ Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws ๐Ÿ–‹๏ธ

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below CVE202648362 CVSS score 10.0 An operating system command injection vulnerability in ColdFusion that could.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90382 178
๐Ÿ–‹๏ธ Enterprise Defenses Recovered at the Edge and Collapsed Inside ๐Ÿ–‹๏ธ

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90381 195
๐Ÿ–‹๏ธ OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning ๐Ÿ–‹๏ธ

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing,.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90380 223
๐Ÿ–‹๏ธ 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One ๐Ÿ–‹๏ธ

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russianspeaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90379 182
๐Ÿฆฟ Zoom Zero-Click RCE: AI Helped Build an Exploit in Under 24 Hours ๐Ÿฆฟ

Researchers built a Zoom zeroclick RCE exploit in under 24 hours using AI, exposing risks to Windows, macOS, iOS, and Android users. The post Zoom ZeroClick RCE AI Helped Build an Exploit in Under 24 Hours appeared first on TechRepublic.

๐Ÿ“– Read more.

๐Ÿ”— Via "Tech Republic"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
TechRepublic Zoom Zero-Click RCE: AI Helped Build an Exploit in Under 24 Hours - TechRepublic Researchers built a Zoom zero-click RCE exploit in under 24 hours using AI, exposing risks to Windows, macOS, iOS, and Android users.
Post #90378 205
๐Ÿฆฟ US, South Korea Warn of Growing Gunra Ransomware Threat ๐Ÿฆฟ

U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network. The post US, South Korea Warn of Growing Gunra Ransomware Threat appeared first on TechRepublic.

๐Ÿ“– Read more.

๐Ÿ”— Via "Tech Republic"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
TechRepublic US, South Korea Warn of Growing Gunra Ransomware Threat - TechRepublic U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network.
Post #90377 240
๐Ÿ•ต๏ธโ€โ™‚๏ธ Walmart Leaders Transform Security Operations Without Going Bananas ๐Ÿ•ต๏ธโ€โ™‚๏ธ

The bigbox giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.

๐Ÿ“– Read more.

๐Ÿ”— Via "Dark Reading"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Dark Reading Walmart Leaders Transform SecOps Without Going Bananas Dark Reading Case Study: The big-box giant scaled its defenses by encouraging trust. Good communications, transparency, and team spirit are key factors.
Post #90376 406
๐Ÿ•ต๏ธโ€โ™‚๏ธ Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition ๐Ÿ•ต๏ธโ€โ™‚๏ธ

Attackers continue to target critical infrastructure and governmentlinked organizations in the country, mirroring the increased activity across Latin America.

๐Ÿ“– Read more.

๐Ÿ”— Via "Dark Reading"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Dark Reading Ransomware Hits Justice Ministy as Colombia Gets New President Attackers continue to target critical infrastructure and government agencies in the country, mirroring the increased activity across Latin America.
Post #90374 574
๐Ÿ–‹๏ธ Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands ๐Ÿ–‹๏ธ

The Computer Emergency Response Team of Ukraine CERTUA has disclosed details of a new social engineering campaign orchestrated by Russian nationstate threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERTUA pinned the activity on a threat cluster it tracks as UAC0145, which is a subgroup within Sandworm aka APT44,.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90373 507
๐Ÿ–‹๏ธ Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands ๐Ÿ–‹๏ธ

The Computer Emergency Response Team of Ukraine CERTUA has disclosed details of a new social engineering campaign orchestrated by Russian nationstate threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERTUA pinned the activity on a threat cluster it tracks as UAC0145, which is a subgroup within Sandworm aka APT44,.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Older posts โ†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook โ†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 โ†’