TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90733 Β· Back to latest

Older Posts 20 shown
Post #90732 232
πŸ“” Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused πŸ“”

The ransomware groups published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Rhysida Publishes Berlin Government Data After €2m Extortion Demand Re The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans
Post #90731 213
πŸ“” N-able Releases Hotfix for Critical Remote Code Execution Vulnerability πŸ“”

The vulnerability, CVE202686218, was allocated a maximumseverity rating by the software provider itself.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine N-able Releases Hotfix for Critical Remote Code Execution Flaw The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
Post #90729 291
πŸ–‹οΈ JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies πŸ–‹οΈ

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript JSC malware with credential harvesting, surveillance, and trafficinterception capabilities. "The payloads are protected with javascriptobfuscator, using multiple techniques including RC4protected strings, controlflow flattening, proxy functions, and operation wrappers," Check Point Research said in a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90728 270
πŸ–‹οΈ N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw πŸ–‹οΈ

Every onpremises Ncentral build below 2026.3.1.14 including servers updated to Hotfix 3 a day earlier needs Hotfix 4. Nable's incident notice says the flaw has been exploited in the wild its release notes say that is unconfirmed. Nable has released its fourth hotfix in five weeks for the Ncentral remote monitoring and management RMM platform, this time for a.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90727 258
πŸ–‹οΈ Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE β€” Public Exploit Released πŸ–‹οΈ

A TantoSec proofofconcept turns an AESCBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution but only against applications in a specific nondefault configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90726 245
πŸ–‹οΈ Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts πŸ–‹οΈ

Cybersecurity researchers have disclosed details of wormlike activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script VBScript payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist techsupport scam, a phishingdelivered MSI installer, and a fake.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90725 308
πŸ–‹οΈ Your Cloud Security Checklist Doesn't Work the Way You Think It Does πŸ–‹οΈ

If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Heres what the data looks like. How risk differs across cloud providers.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90723 513
πŸ“’ Cyber criminals are adapting ASCII smuggling for mass phishing campaigns πŸ“’

Usually known for its use in prompt injection attacks, ASCII smuggling is now being used to evade spam filters on email platforms.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Cyber criminals are adapting ASCII smuggling for mass phishing campaigns Usually known for its use in prompt injection attacks, ASCII smuggling is now being used to evade spam filters on email platforms
Post #90722 802
πŸ–‹οΈ Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities πŸ–‹οΈ

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE202681578 and CVE202682078 an authentication bypass and remote code execution chain to conduct command execution and reconnaissance, as well as.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90721 710
πŸ–‹οΈ Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel πŸ–‹οΈ

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25yearold German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90720 524
πŸ–‹οΈ Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted πŸ–‹οΈ

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90719 455
πŸ–‹οΈ Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code πŸ–‹οΈ

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE202659346 CVSS score 9.3, is an integeroverflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90718 478
πŸ–‹οΈ Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials πŸ–‹οΈ

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90717 537
πŸ–‹οΈ Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores πŸ–‹οΈ

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch ecommerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90716 684
πŸ–‹οΈ Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials πŸ–‹οΈ

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90715 812
πŸ•΅οΈβ€β™‚οΈ Companies Have 6 Months to Prepare for Automated Attacks πŸ•΅οΈβ€β™‚οΈ

Frontier AI models have already demonstrated they can autonomously and in some cases, inadvertently conduct endtoend compromises, but the situation will become more urgent very soon.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Companies Have 6 Months to Prepare for Automated Attacks Frontier AI models have already conducted autonomous end-to-end compromises, but researchers warn the situation will become more urgent very soon.
Post #90714 908
πŸ•΅οΈβ€β™‚οΈ Large Enterprises Targeted in Fake Merger & Acquisition Scams πŸ•΅οΈβ€β™‚οΈ

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Large Enterprises Targeted in Fake Merger & Acquisition Scams Threat actors behind the "Phantom Deal" campaign are studying companies in detail, aiming to dupe midlevel employees into initiating large transfers.
Post #90713 843
πŸ•΅οΈβ€β™‚οΈ Large Enterprises Targeted in Fake Merger & Acquisition Scams πŸ•΅οΈβ€β™‚οΈ

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Large Enterprises Targeted in Fake Merger & Acquisition Scams Threat actors behind the "Phantom Deal" campaign are studying companies in detail, aiming to dupe midlevel employees into initiating large transfers.
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’