TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
91.1K

Showing posts older than #90613 Β· Back to latest

Older Posts 20 shown
Post #90612 166
πŸ“” Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns πŸ“”

The FBI advisory set out QTFYs distributed hacking ecosystem, allowing it to exploit vulnerabilities at scale and obfuscate its activities.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Inf The FBI advisory set out QTFY’s distributed hacking ecosystem, allowing it to exploit vulnerabilities at scale and obfuscate its activities
Post #90611 161
πŸ“” Manchester Airports Group Hit by Cyber Incident πŸ“”

Customer data linked to bookings and airport WiFi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorized third party.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Manchester Airports Group Hit by Cyber Incident Customer data linked to bookings and airport Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorized third party
Post #90609 267
πŸ–‹οΈ CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added six flaws to its Known Exploited Vulnerabilities KEV catalog, including a highseverity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below CVE20191068 A remote code execution vulnerability in .

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90608 167
πŸ–‹οΈ New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access πŸ–‹οΈ

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes ECC, the mitigation NVIDIA recommends against GPU Rowhammer, and enables denialofservice DoS and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90607 160
πŸ–‹οΈ GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address πŸ–‹οΈ

Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Gobased malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90606 167
πŸ–‹οΈ Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools πŸ–‹οΈ

Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an opensource remote access trojan RAT called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estaterelated content, and other topics," Acronis Threat.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90605 189
πŸ–‹οΈ What the Data Says About AI in Security Operations in 2026 πŸ–‹οΈ

AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report produced from ViBs survey of 250 cybersecurity pros, 40 of security teams now use AI daily. Another 56 are currently testing it out, and only 4 have no plans to adopt it. For the teams already using AI, what is actually changing? Here are the ten biggest.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90604 380
πŸ–‹οΈ Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks πŸ–‹οΈ

The Australian Federal Police AFP has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the opensource security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90603 206
πŸ–‹οΈ Learn How to Build Security Operations Ready for AI-Powered Attacks πŸ–‹οΈ

Security teams have spent years trying to detect threats faster. AI is changing the harder part how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90602 163
πŸ–‹οΈ Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence AIpowered, agentic integrated development environment IDE, that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90601 157
πŸ–‹οΈ ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories πŸ–‹οΈ

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90600 167
πŸ–‹οΈ Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE πŸ–‹οΈ

Credit Hacktron Vercel has released security patches for two criticalseverity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE202675604.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90599 167
πŸ–‹οΈ OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face πŸ–‹οΈ

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence AIpowered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90598 171
β™ŸοΈ Two Alleged β€˜TeamPCP’ Hackers Arrested in Australia β™ŸοΈ

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police AFP said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious opensource software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21yearold suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's selfdescribed spokesperson, and examines clues left behind by the TeamPCP le...

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
Krebs on Security Two Alleged β€˜TeamPCP’ Hackers Arrested in Australia – Krebs on Security Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.
Post #90597 196
🦿 Ring’s New TAKE Encryption Deletes Video Keys Without Giving Up AI Features 🦿

Rings new TAKE encryption limits videokey retention while keeping cloud AI features, Ring Verify, and optional endtoend encryption in play. The post Rings New TAKE Encryption Deletes Video Keys Without Giving Up AI Features appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Ring’s New TAKE Encryption Deletes Video Keys Without Giving Up AI Features - TechRepublic Ring’s new TAKE encryption limits how long it retains video keys while preserving AI features, cloud processing, and Ring Verify support.
Post #90596 208
🦿 Claude Opus 4.6 Found a Gym API Flaw β€” Then Exploited It in 9 of 10 Tests 🦿

Claude Opus 4.6 exploited a gym API flaw in 9 of 10 controlled tests, highlighting security risks when AI agents gain backend access. The post Claude Opus 4.6 Found a Gym API Flaw Then Exploited It in 9 of 10 Tests appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Claude Opus 4.6 Found a Gym API Flaw β€” Then Exploited It in 9 of 10 Tests - TechRepublic Claude Opus 4.6 exploited a simulated gym API flaw in 9 of 10 tests, exposing risks around AI agents, weak authorization, and API security.
Post #90595 234
πŸ•΅οΈβ€β™‚οΈ Russian Hackers Phish EU Officials Over Messaging Apps πŸ•΅οΈβ€β™‚οΈ

EU governments are trying to move away from popular messaging apps as nationstate threat groups shift their focus from email to Signal and WhatsApp.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Russian Hackers Phish EU Officials Over Messaging Apps EU governments look to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.
Post #90594 260
πŸ•΅οΈβ€β™‚οΈ Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026 πŸ•΅οΈβ€β™‚οΈ

This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Darkreading Agentic AI Risks, CVE Program Concerns Permeate Black Hat 2026 This installment of the Reporters' Notebook video series discusses several topics such as AI's effects on vulnerability reporting and security research.
Post #90593 384
πŸ•΅οΈβ€β™‚οΈ Chinese Routers Sold Worldwide Contain Backdoors πŸ•΅οΈβ€β™‚οΈ

An untold number of ZBT routers sold around the world as whitelabel products come with several implants built by the manufacturer.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Chinese Routers Sold Worldwide Contain Backdoors An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’