TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
91.1K

Showing posts older than #90573 Β· Back to latest

Older Posts 20 shown
Post #90572 348
πŸ–‹οΈ NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a new adversaryinthemiddle AitM phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 signins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the 320month service as a subscriptionbased phishing platform that.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90571 176
πŸ–‹οΈ Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler πŸ–‹οΈ

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian statesponsored hacking group affiliated with the Islamic Revolutionary Guard Corps IRGC. GroupIB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore aka.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90570 135
πŸ–‹οΈ FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations πŸ–‹οΈ

The U.S. Department of Justice DoJ on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese statesponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90569 141
🦿 Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots 🦿

Microsoft Teams is adding a policy that lets IT admins automatically block detected external meeting bots instead of relying on organizer approval. The post Microsoft Teams New Policy Lets Admins Automatically Block Meeting Bots appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots Microsoft Teams is adding a policy that lets IT admins automatically block detected external meeting bots instead of relying on organizer approval.
Post #90568 176
🦿 TikTok Agrees to $400M Settlement Over Children’s Privacy 🦿

TikTok and ByteDance agree to pay up to 400 million to settle US allegations involving childrens data, parental consent and account deletion. The post TikTok Agrees to 400M Settlement Over Childrens Privacy appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic TikTok Agrees to $400M Children’s Privacy Settlement TikTok and ByteDance agree to pay up to $400 million to settle US allegations involving children’s data, parental consent and account deletion.
Post #90567 275
🦿 The Password Notebook Is Back β€” but Is It Actually Safer? 🦿

Password notebooks are making an unexpected comeback as infostealers and browser attacks revive debate over the safest way to store credentials. The post The Password Notebook Is Back but Is It Actually Safer? appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Password Notebooks Are Making a Comeback Password notebooks are making an unexpected comeback as infostealers and browser attacks revive debate over the safest way to store credentials.
Post #90566 173
🦿 WhatsApp Just Added 3 New Ways to Protect Your Account 🦿

WhatsApp is adding stronger twostep verification, multiple passkeys and more context for unknown callers as it expands protections against scams. The post WhatsApp Just Added 3 New Ways to Protect Your Account appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic WhatsApp Just Added 3 New Ways to Protect Your Account WhatsApp is adding stronger two-step verification, multiple passkeys and more context for unknown callers as it expands protections against scams.
Post #90565 167
πŸ•΅οΈβ€β™‚οΈ Is Cyber Facing an Affordability Crisis? πŸ•΅οΈβ€β™‚οΈ

As breach costs reach record highs and defense spending nears 240 billion, small businesses are dangerously exposed, threatening supply chain security.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Is Cyber Facing an Affordability Crisis? As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
Post #90564 167
πŸ•΅οΈβ€β™‚οΈ Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw πŸ•΅οΈβ€β™‚οΈ

Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Finding Nemo(Claw): Issue Allows for LLM Poisoning in OpenClaw Attackers can exploit a flaw in Nvidia's tool to gain access to the local model server through the Ollama API paving the way for AI agent corruption.
Post #90563 177
πŸ•΅οΈβ€β™‚οΈ Hidden Prompts Trick AI Into False Email Summaries πŸ•΅οΈβ€β™‚οΈ

With some simple HTML that's invisible to users, attackers can manipulate AIpowered email summarizers into producing malicious information.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Hidden Prompts Trick AI Into False Email Summaries With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
Post #90562 195
πŸ•΅οΈβ€β™‚οΈ Nigeria Looks to Sovereign Cloud for Cyber, National Security πŸ•΅οΈβ€β™‚οΈ

The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Nigeria Looks to Sovereign Cloud for Cyber, National Security The West African nation launched an effort for financing, procurement, and policies aimed at promoting sovereign cloud capabilities and cybersecurity.
Post #90561 349
πŸ•΅οΈβ€β™‚οΈ Interpol's Jackal IV Disrupts West African Crime Infrastructure πŸ•΅οΈβ€β™‚οΈ

The international law enforcement operation focused on disrupting crimeasaservice networks and infrastructure behind groups like Black Axe.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Interpol's Jackal IV Disrupts West African Crime Infrastructure The international law enforcement operation focused on disrupting crime-as-a-service networks and infrastructure behind groups like Black Axe.
Post #90560 249
πŸ•΅οΈβ€β™‚οΈ 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month πŸ•΅οΈβ€β™‚οΈ

The adversaryinthemiddle AitM phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month The AitM service lowers the barrier to entry for actors to create phishing attacks that steal more than just user credentials.
Post #90559 251
πŸ•΅οΈβ€β™‚οΈ Android Malware Hijacks Update System for Car Head Units πŸ•΅οΈβ€β™‚οΈ

Threat actors behind a notorious clickfraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Android Malware Hijacks Update System for Car Head Units Threat actors behind a click-fraud botnet are targeting vehicle infotainment modules and are abusing legitimate functionality to spread infections.
Post #90558 276
πŸ“’ US lawmakers say CISA cuts raise β€˜serious concerns about the agency's ability to fulfil its mission’ πŸ“’

With hundreds more jobs set to go, concerns are rising about whether the agency can continue its critical work defending organizations.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro US lawmakers say CISA cuts raise β€˜serious concerns about the agency's ability to fulfil its mission’ With hundreds more jobs set to go, concerns are rising about whether the agency can continue its critical work defending organizations
Post #90557 340
πŸ“’ Zero-click email attacks: What businesses need to know πŸ“’

Russian statebacked attackers are using email to carry out zeroclick phishing campaigns. Heres the needtoknow information.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Zero-click email attacks: What businesses need to know Russian state-backed attackers are using email to carry out zero-click phishing campaigns. Here’s the need-to-know information
Post #90556 586
πŸ“’ Hackers have breached hundreds of Zimbra servers, despite a patch having been available for weeks πŸ“’

The flaw allows attackers to trigger crosssite scripting, sensitive information disclosure, security restriction bypass, and remote code execution.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Hackers have breached hundreds of Zimbra servers, despite a patch having been available for weeks The flaw allows attackers to trigger cross-site scripting, sensitive information disclosure, security restriction bypass, and remote code execution
Post #90555 828
πŸ“’ US claims Chinese hackers breached Justice Department, Federal Reserve, NASA in lengthy threat campaign πŸ“’

The statebacked QTFY group has been identified as the culprit behind the campaign.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro US claims Chinese hackers breached Justice Department, Federal Reserve, NASA in lengthy threat campaign The state-backed QTFY group has been identified as the culprit behind the campaign
Post #90554 1.63K
🦿 Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait 🦿

Googles new Android verification flow adds a 24hour wait for apps from unverified developers as broader identity checks approach. The post Google Tightens Android Sideloading Unverified Apps Now Face a 24Hour Wait appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait Google’s new Android verification flow adds a 24-hour wait for apps from unverified developers as broader identity checks approach.
Post #90553 1.06K
πŸ¦… Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates πŸ¦…

Ransomware rarely appears out of nowhere. Before encryption, extortion, or data theft begins, attackers often spend time establishing access, stealing credentials, moving laterally, and identifying valuable systems. These activities occur during the ransomware preexecution phase, when malicious activity may be difficult to distinguish from legitimate administration.  For security teams, understanding ransomware attack vectors, ransomware initial access methods, and how ransomware evades detection is critical. Endpoint security blind spots can give attackers the time they need to prepare an attack without triggering an obvious alarm.  Here are five areas where ransomware activity can remain hidden before detonation.  1. Remote Access Tools A Favorite Ransomware Attack Vector  V...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
Cyble Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates Explore ransomware attack vectors hiding in endpoint blind spots, from remote access tools and credentials to vendors, OT systems and phishing.
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’