TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90693 Β· Back to latest

Older Posts 20 shown
Post #90692 227
πŸ“” Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons πŸ“”

Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud
Post #90689 150
πŸ–‹οΈ Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads πŸ–‹οΈ

The U.S. Department of Justice DoJ on Tuesday announced the takedown of a longstanding peertopeer P2P botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90688 138
πŸ–‹οΈ Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials πŸ–‹οΈ

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE20269586 CVSS score 9.3, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 104997 that can allow attackers to remotely execute arbitrary code as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90687 148
πŸ–‹οΈ Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another πŸ–‹οΈ

Forescout Research Vedere Labs said it used Anthropic's Claude to port a working preauthentication remote code execution RCE exploit from one WAGO programmable logic controller PLC to another, executing attackersupplied ARM shellcode on live hardware. The exploit targets CVE202131886, a stackbased buffer overflow in the Nucleus FTP server's handling of the USER command.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90686 177
πŸ–‹οΈ Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands πŸ–‹οΈ

The U.S. Department of Justice DoJ has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malwarelaced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90685 167
πŸ–‹οΈ GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends πŸ–‹οΈ

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution RCE on the opensource geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90684 188
πŸ–‹οΈ Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain πŸ–‹οΈ

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access SMA 1000 series VPN appliances that have been exploited in zeroday attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below CVE202683548 CVSS score 10.0   A preauthentication SSRF vulnerability in the Appliance.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90683 141
πŸ–‹οΈ How to Secure Enterprise AI: From Adoption to Incident Readiness πŸ–‹οΈ

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting boardlevel pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here.  The Business Reality  In Sygnias 2026 CISO Survey Report, which.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90682 124
πŸ–‹οΈ Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanishspeaking users through a fake televisionstreaming campaign on Meta and can give operators nearcomplete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90681 259
πŸ–‹οΈ BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access πŸ–‹οΈ

Virtualizor said hackers used a Border Gateway Protocol BGP hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hostingprovider account separately said 5 of its 34 checked Virtualizor hypervisors sustained rootlevel compromise. The incident window ran from approximately August 28 at 2057.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90680 181
πŸ–‹οΈ Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages πŸ–‹οΈ

A Chinesespeaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attackercontrolled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid2025. The modules.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90679 130
πŸ–‹οΈ Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code πŸ–‹οΈ

Manifold Security has disclosed eight security flaws across seven commandline AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90678 135
πŸ–‹οΈ Fake Software Installers Disable Windows Update and Weaken Microsoft Defender πŸ–‹οΈ

An active malware campaign is using bogus softwaredownload websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting Chinabased operations of multinational organizations and Chinesespeaking users," Microsoft.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90677 131
πŸ–‹οΈ Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs πŸ–‹οΈ

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives highpriority defenders like governments, healthcare providers, and telecommunications services early access to advanced models that help them.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90676 132
πŸ•΅οΈβ€β™‚οΈ AI Model Evaluator METR Hit by Credential Theft, Probing πŸ•΅οΈβ€β™‚οΈ

In one attack, threat actors stole an API key that ultimately led to the consumption of 600,000 in public AI model credits for the security nonprofit.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading AI Model Evaluator METR Hit by Credential Theft, Probing In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Post #90675 141
πŸ•΅οΈβ€β™‚οΈ Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise πŸ•΅οΈβ€β™‚οΈ

The attacks targeting CVE20260768 are the latest threat against the lowcode AI development platform, which is receiving more attention from adversaries this year.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Critical Langflow Flaw Exploited as Attacks on AI Platform Rise The attacks on CVE-2026-0768 are the latest threats against the low-code AI development platform, which adversaries are flocking to this year.
Post #90674 122
πŸ•΅οΈβ€β™‚οΈ Stronger Security Drives Ransomware Groups to Recruit From Within πŸ•΅οΈβ€β™‚οΈ

Some security researchers have observed an uptick in insiderassisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Stronger Security Drives Ransomware Groups to Recruit From Within Security researchers see more insider-assisted ransomware attacks, but malicious insiders pose other costly threats beyond ransomware alone.
Post #90673 134
πŸ•΅οΈβ€β™‚οΈ Attackers Pounce on Critical Artifactory Bug Following Disclosure πŸ•΅οΈβ€β™‚οΈ

CVE202682329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain adminlevel access on affected systems.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Attackers Jump on Critical Artifactory Bug After Disclosure CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin level access on affected systems.
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’