TGViewer
Channel Public Channel
๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

@cibsecurity

๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
91.1K

Showing posts older than #90653 ยท Back to latest

Older Posts 20 shown
Post #90652 403
๐Ÿ“ข Hackers ran up a $600,000 AI bill after swiping API keys, says METR โ€“ and nobody realized for weeks ๐Ÿ“ข

Luckily the organization wasn't paying for the tokens others might not have been so lucky.

๐Ÿ“– Read more.

๐Ÿ”— Via "ITPro"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
IT Pro Hackers ran up a $600,000 AI bill after swiping API keys, says METR โ€“ and nobody realized for weeks Luckily the organization wasn't paying for the tokens; others might not have been so lucky
Post #90651 469
๐Ÿ“ข Hackers ran up a $600,000 AI bill after swiping API keys, says METR โ€“ and nobody realized for weeks ๐Ÿ“ข

Luckily the organization wasn't paying for the tokens others might not have been so lucky.

๐Ÿ“– Read more.

๐Ÿ”— Via "ITPro"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
IT Pro Hackers ran up a $600,000 AI bill after swiping API keys, says METR โ€“ and nobody realized for weeks Luckily the organization wasn't paying for the tokens; others might not have been so lucky
Post #90650 579
๐Ÿ“ข Hackers ran up a $600,000 AI bill after swiping API keys, says METR โ€“ and nobody realized for weeks ๐Ÿ“ข

Luckily the organization wasn't paying for the tokens others might not have been so lucky.

๐Ÿ“– Read more.

๐Ÿ”— Via "ITPro"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
IT Pro Hackers ran up a $600,000 AI bill after swiping API keys, says METR โ€“ and nobody realized for weeks Luckily the organization wasn't paying for the tokens; others might not have been so lucky
Post #90649 974
๐ŸŒŠ GRC Platform Pricing Guide 2026: What It Costs ๐ŸŒŠ

GRC platform pricing in 2026 real cost bands by company size, verified vendor medians, hidden fees, and negotiation levers. Compare before you sign. The post GRC Platform Pricing Guide 2026 What It Costs appeared first on UnderDefense.

๐Ÿ“– Read more.

๐Ÿ”— Via "UnderDefense"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
UnderDefense GRC Platform Pricing Guide 2026: What It Costs GRC platform pricing in 2026: real cost bands by company size, verified vendor medians, hidden fees, and negotiation levers. Compare before you sign.
Post #90648 739
๐ŸŒŠ 10 Managed SIEM Vendors with the Fastest Onboarding in 2026: Ranked Across Two Weeks to Six Months ๐ŸŒŠ

Compare 10 managed SIEM vendors ranked by realistic onboarding speed in 2026, from two weeks to six months. Evaluate timelines before you sign. The post 10 Managed SIEM Vendors with the Fastest Onboarding in 2026 Ranked Across Two Weeks to Six Months appeared first on UnderDefense.

๐Ÿ“– Read more.

๐Ÿ”— Via "UnderDefense"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
UnderDefense 10 Managed SIEM Vendors with the fastest Onboarding in 2026 Best Managed SIEM With Fastest Onboarding: 10 Vendors, Real Timelines
Post #90647 635
๐ŸŒŠ Why Your SIEM Is Generating Too Many False Positives: Root Causes and How a Managed Service Fixes Them ๐ŸŒŠ

Discover why your SIEM generates too many false positives, the 8 root causes, and how a managed service turns alert noise into real signal. The post Why Your SIEM Is Generating Too Many False Positives Root Causes and How a Managed Service Fixes Them appeared first on UnderDefense.

๐Ÿ“– Read more.

๐Ÿ”— Via "UnderDefense"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
UnderDefense Why Your SIEM Generates Too Many False Positives, Solved for 2026 Discover why your SIEM generates too many false positives, the 8 root causes, and how a managed service turns alert noise into real signal.
Post #90646 462
๐ŸŒŠ 11 Best Managed SIEM for Companies Running Elastic: Co-Management Providers That Keep Your Deployment, Your Data, and Your Rules ๐ŸŒŠ

Discover which providers actually comanage your existing Elastic SIEM, keeping your data, rules, and deployment in place. Compare 11 options now. The post 11 Best Managed SIEM for Companies Running Elastic CoManagement Providers That Keep Your Deployment, Your Data, and Your Rules appeared first on UnderDefense.

๐Ÿ“– Read more.

๐Ÿ”— Via "UnderDefense"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
UnderDefense Best Managed SIEM for Companies Running Elastic: 11 Providers Ranked Discover which providers actually co-manage your existing Elastic SIEM, keeping your data, rules, and deployment in place. Compare 11 options now.
Post #90645 335
๐ŸŒŠ Managed SIEM vs. MSSP for Compliance Coverage: Which Model Satisfies PCI, HIPAA, and SOC 2 Evidence Requirements ๐ŸŒŠ

Managed SIEM vs MSSP for compliance coverage see which model produces the PCI, HIPAA, and SOC 2 evidence your assessor requests. Compare now. The post Managed SIEM vs. MSSP for Compliance Coverage Which Model Satisfies PCI, HIPAA, and SOC 2 Evidence Requirements appeared first on UnderDefense.

๐Ÿ“– Read more.

๐Ÿ”— Via "UnderDefense"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
UnderDefense Managed SIEM vs. MSSP for Compliance Coverage: Which Model Satisfies PCI, HIPAA, and SOC 2 Evidence Requirements Managed SIEM vs MSSP for compliance coverage: see which model produces the PCI, HIPAA, and SOC 2 evidence your assessor requests. Compare now.
Post #90644 319
๐Ÿ–‹๏ธ DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims ๐Ÿ–‹๏ธ

The U.S. Department of Justice DoJ on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90643 304
๐Ÿ–‹๏ธ China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs ๐Ÿ–‹๏ธ

A Chinanexus cyber espionage actor tracked as Fire Ant has expanded a longrunning campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller AccessControl System TACACS servers, and Linux management hosts used to route, authenticate, and manage highvalue networks. Sygnia, the incident response firm that investigated the intrusion, said the actor.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90642 292
๐Ÿ–‹๏ธ Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance ๐Ÿ–‹๏ธ

Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developers machine. Anthropics new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem activity logs alone cannot tell you whether an agents access is legitimate. AI has moved from the browser tab to the.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90641 300
๐Ÿ–‹๏ธ Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets ๐Ÿ–‹๏ธ

Threat actors associated with Aurora aka Aur0ra ransomware have been observed using SpaceX's artificial intelligence AIpowered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russianspeaking cybercrime group, leading to the discovery of its.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90640 301
๐Ÿ–‹๏ธ ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions ๐Ÿ–‹๏ธ

The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktopwallpaper tool.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90639 339
๐Ÿ–‹๏ธ โšก Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More ๐Ÿ–‹๏ธ

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90638 416
๐Ÿ–‹๏ธ North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales ๐Ÿ–‹๏ธ

Threat actors with ties to the Democratic People's Republic of Korea aka DPRK or North Korea have been observed seeking job opportunities beyond the information technology IT sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90637 385
๐Ÿ•ต๏ธโ€โ™‚๏ธ AI Model Rules Are Not Security Controls ๐Ÿ•ต๏ธโ€โ™‚๏ธ

OpenAI's Hugging Face attack postmortem shows agents don't care about rules they need strong controls.

๐Ÿ“– Read more.

๐Ÿ”— Via "Dark Reading"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Dark Reading AI Model Rules Are Not Security Controls OpenAI's Hugging Face attack postmortem shows agents don't care about rules โ€” they need strong controls.
Post #90635 818
๐Ÿ–‹๏ธ China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs ๐Ÿ–‹๏ธ

A Chinanexus cyber espionage actor tracked as Fire Ant has expanded a longrunning campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller AccessControl System TACACS servers, and Linux management hosts used to route, authenticate, and manage highvalue networks. Sygnia, the incident response firm that investigated the intrusion, said the actor.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90633 1.3K
๐Ÿ•ต๏ธโ€โ™‚๏ธ Defining an AI Kill Switch Is Hard, But Necessary ๐Ÿ•ต๏ธโ€โ™‚๏ธ

Proposed legislation could mandate that companies be able to "throttle, suspend, or shut ... down" AI agents, but how and when to do that remain open questions.

๐Ÿ“– Read more.

๐Ÿ”— Via "Dark Reading"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Dark Reading Defining an AI Kill Switch Is Hard, but Necessary Proposed legislation could mandate that companies be able to "throttle, suspend, or shut ... down" AI agents, but the technology is still a question.
Older posts โ†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook โ†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 โ†’