TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
91.1K

Showing posts older than #90513 Β· Back to latest

Older Posts 20 shown
Post #90512 388
πŸ–‹οΈ Phishing 3.0: The Fight Moves to Agent Versus Agent πŸ–‹οΈ

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90511 348
πŸ–‹οΈ Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P πŸ–‹οΈ

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authenticationbypass flaws, and a peertopeer P2P relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90510 335
πŸ–‹οΈ SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs πŸ–‹οΈ

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool RAT families, five of which have never been previously documented DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90509 367
πŸ“” OpenAI Tightens AI Safeguards Following Hugging Face Incident πŸ“”

OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90508 387
πŸ–‹οΈ Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below CVE202665400 CVSS score 9.8 An improper authentication vulnerability impacting Apple macOS that could allow an.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
  • πŸ‘ 1
Post #90507 355
πŸ–‹οΈ StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data πŸ–‹οΈ

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90506 327
πŸ“’ β€˜The scale of PurpleDelta’s operation is easy to miss’: Fake North Korean IT workers are submitting so many job applications that companies can’t keep up πŸ“’

The PurpleDelta group is applying for thousands of jobs to steal proprietary data, source code, and internal communications.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro β€˜The scale of PurpleDelta’s operation is easy to miss’: Fake North Korean IT workers are submitting so many job applications that… The PurpleDelta group is applying for thousands of jobs to steal proprietary data, source code, and internal communications
  • πŸ‘ 1
Post #90504 306
πŸ“” ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts πŸ“”

The UKs privacy watchdog has called on police using facial recognition to follow its recommendations.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine ICO Urges Police to Improve Data Governance in Facial Recognition Roll The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations
Post #90503 323
πŸ“” Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware πŸ“”

The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomwar The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter
Post #90502 274
πŸ–‹οΈ Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data πŸ–‹οΈ

A JavaServer Pages JSP web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management PLM software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90501 386
πŸ–‹οΈ Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure πŸ–‹οΈ

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOSfocused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90499 467
πŸ“’ The CISO now owns physical security. Here’s what that means for the channel πŸ“’

Physical security budgets have moved to CISOs, and partners must adapt to this important shift.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
ChannelPro The CISO now owns physical security. Here’s what that means for the channel Physical security budgets have moved to CISOs, and partners must adapt to this important shift
Post #90498 461
πŸ–‹οΈ Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 πŸ–‹οΈ

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from 20,000 to 60,000. "In these messages, the thirdparty offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90497 392
πŸ–‹οΈ Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets πŸ–‹οΈ

Two critical vulnerabilities impacting MLflow, an opensource artificial intelligence AI platform, and FUXA, an opensource, webbased SCADA HMI software built for operational technology OT and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90496 316
πŸ–‹οΈ Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps πŸ–‹οΈ

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90495 287
πŸ•΅οΈβ€β™‚οΈ CISOs Break Their Silence in 'Declassified' Docuseries πŸ•΅οΈβ€β™‚οΈ

Milliondollar heists, divorce, and careerending burnout are all stories told in the latest docuseries revealing a behindthescenes look at the cybersecurity community.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading CISOs Break Their Silence in 'Declassified' Docuseries Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a peek into the cybersecurity community.
Post #90494 289
πŸ•΅οΈβ€β™‚οΈ 'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture πŸ•΅οΈβ€β™‚οΈ

Researchers discovered a "metahacking" technique that can manipulate the AI service into revealing its own security weaknesses.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading 'CoSnitch' Attack Tricked Copilot Into Revealing Own Architecture Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.
Post #90493 379
πŸ•΅οΈβ€β™‚οΈ Critical GitLab Zero-Click Flaw Poses Mitigation Challenges πŸ•΅οΈβ€β™‚οΈ

A lack of technical details could make it hard for organizations running selfmanaged GitLab versions to detect potential exploitation of CVE202619478.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Critical GitLab Zero-Click Flaw Poses Mitigation Challenges A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’