TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90713 Β· Back to latest

Older Posts 20 shown
Post #90712 736
πŸ•΅οΈβ€β™‚οΈ AI Is Ending the Era of Hidden Vulnerabilities β€” Are Vendors Ready? πŸ•΅οΈβ€β™‚οΈ

A tidal wave of bug reports is overwhelming software vendors, exposing securebydesign failures and creating disclosure bottlenecks.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading AI Will End the Era of Hidden Vulnerabilities. Are Vendors Ready? The Vulnpocalypse is a reckoning for software vendors as AI accelerates bug discovery, overwhelming remediation capacity and straining disclosure systems.
  • ❀ 1
Post #90709 724
πŸ–‹οΈ US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries πŸ–‹οΈ

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency CRA tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45 of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90708 619
πŸ“” US and Canadian Court Records Breached Following Thomson Reuters Incident πŸ“”

Thomson Reuters has disclosed a cyber incident affecting its CTrack court management software, potentially exposing court records in Canada and the US.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine US and Canadian Court Records Breached Following Thomson Reuters Incid Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US
Post #90707 511
πŸ–‹οΈ Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means πŸ–‹οΈ

In early August, GitGuardian researchers found that a recent ShaiHulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous IntegrationContinuous Deployment CICD tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90706 477
πŸ–‹οΈ Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks πŸ–‹οΈ

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90705 429
πŸ“’ Security experts warn cyber insurance β€˜should not be treated as a get-out-of-jail-free card’ πŸ“’

Cyber insurance might alleviate financial losses after an attack, but building resilience is still the best defense.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Security experts warn cyber insurance β€˜should not be treated as a get-out-of-jail-free card’ Cyber insurance might alleviate financial losses after an attack, but building resilience is still the best defense
Post #90704 396
πŸ–‹οΈ Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone πŸ–‹οΈ

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zeroclick exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found highconfidence indicators of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90703 367
πŸ“’ Everything we know about the Dropbox breach so far πŸ“’

The company has confirmed that thousands of accounts connected through Lenovo ID and lacking Dropbox twofactor authentication have been affected.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Everything we know about the Dropbox breach so far The company has confirmed that thousands of accounts connected through Lenovo ID and lacking Dropbox two-factor authentication have been affected
  • ❀ 1
Post #90702 278
πŸ“’ Manchester Airports Group attack: Millions of holidaymakers urged to look out for scams as hackers publish stolen data online πŸ“’

The Manchester Airports Group attack could lead to fraud and scams, experts warn.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Manchester Airports Group attack: Millions of holidaymakers urged to look out for scams as hackers publish stolen data online The Manchester Airports Group attack could lead to fraud and scams, experts warn
Post #90701 279
πŸ“’ β€˜Popular’ AI use cases aren’t those delivering results. Gartner says focus on the basics for success and easy wins πŸ“’

Focusing on hypedriven AI use cases rarely delivers, so its important to start with the basics and build from there.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro β€˜Popular’ AI use cases aren’t those delivering results. Gartner says focus on the basics for success and easy wins Focusing on hype-driven AI use cases rarely delivers, so it’s important to start with the basics and build from there
Post #90700 384
πŸ“” FBI Probes Possible Breach of 153 Million Driver’s Licenses πŸ“”

The FBI is investigating how scans of over 153 million drivers licenses are being sold on the dark web.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90699 456
πŸ¦… Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works πŸ¦…

Supply chain attacks in 2026 are no longer an edgecase risk buried in a vendor questionnaire they are a primary breach vector that regulators, incident responders, and CISOs now treat as a firstorder threat. Verizon's 2026 Data Breach Investigations Report found thirdparty involvement in 48 of breaches, up 60 year over year, following the 2025 edition, which already recorded a jump from 15 to 30.   Every vendor integration, every opensource dependency, and every managed file transfer tool expands the attack surface that an organization does not directly control. That is the core problem with supply chain security today the weakest link is rarely the enterprise itself.   It is the supplier three tiers removed that nobody in procurement flagged as highrisk.  What Is a Supply Chai...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
Cyble Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works Supply chain attacks in 2026 are rising, exposing vendor dependencies and software risks that traditional security tools often fail to detect.
Post #90697 353
πŸ–‹οΈ CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added seven security flaws to its Known Exploited Vulnerabilities KEV catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows CVE202683548 CVSS score 10.0 A serverside request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90696 300
πŸ–‹οΈ Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon πŸ–‹οΈ

The security researcher known as Chaotic Eclipse aka INFINITE NIGHTMARE, MSNightmare, and NightmareEclipse has dropped a new zeroday dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90693 197
πŸ“” Nutex Health Says Patient Data Stolen, Hackers Threaten Leak πŸ“”

The US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third party.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Nutex Health Says Patient Data Stolen, Hackers Threaten Leak The US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third party
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’