TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.5K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90753 Β· Back to latest

Older Posts 20 shown
Post #90751 322
πŸ“” AI Coding Tools Now a Prime Target for Threat Actors, Google Warns πŸ“”

Google warned that the rapid integration of AIassisted coding tools has significantly expanded software supply chain risks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine AI Coding Tools Now a Prime Target for Threat Actors, Google Warns Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
Post #90750 342
πŸ–‹οΈ FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials πŸ–‹οΈ

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90747 316
πŸ–‹οΈ BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a sprawling search engine optimization SEO poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90746 257
πŸ–‹οΈ Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell πŸ–‹οΈ

Adobe on Monday released security patches to address a maximumseverity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE202675650 CVSS score 10.0, has been codenamed StyleSmuggler by Sansec, which discovered zeroday exploitation starting September 4, 2026. "This update resolves a critical.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90745 273
πŸ“’ Samsung backs Mistral in record-breaking €3 billion funding round as French AI firm targets sovereign AI gains πŸ“’

The French AI company breaks European records, but still trails American rivals with a 21bn valuation.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Samsung backs Mistral in record-breaking €3 billion funding round as French AI firm targets sovereign AI gains The French AI company breaks European records, but still trails American rivals with a €21bn valuation
Post #90744 329
πŸ“’ 'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI πŸ“’

Organizations are urged to identify shadow AI use and tighten up security procedures.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro 'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI Organizations are urged to identify shadow AI use and tighten up security procedures
Post #90742 383
πŸ–‹οΈ Grindr to Pay Β£26 Million to Settle U.K. Claims Over HIV Status Data Sharing πŸ–‹οΈ

Online dating app Grindr has opted to pay 26 million 35.1 million to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with thirdparties. Grindr, which is the largest LGBTQ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
  • ❀ 1
Post #90741 451
πŸ“’ Iran power plant closure is a warning to all businesses: How to respond πŸ“’

After the first attack of its kind, how big is the risk, who does it impact, and how should firms react?.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Iran power plant closure is a warning to all businesses: How to respond After the first attack of its kind, how big is the risk, who does it impact, and how should firms react?
Post #90739 505
πŸ–‹οΈ PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution πŸ–‹οΈ

Cybersecurity researchers have disclosed details of a complex Chromiumbased postexploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into ChromeEdge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90738 510
πŸ–‹οΈ ⚑ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More πŸ–‹οΈ

Turning off email images should at least stop the pictures. This week, attackers had a workaround a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
  • ❀ 1
Post #90737 421
πŸ–‹οΈ Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks πŸ–‹οΈ

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other softwareasaservice SaaS offerings through information technology IT help desk vishing, adversaryinthemiddle AitM token theft, and residentialproxy signins. The activity, which mainly singles out directors, vice presidents, and other executive staff.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90736 371
πŸ¦… Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us πŸ¦…

Qatar is racing toward a knowledgebased, fully digital economy. Smart infrastructure, cloudfirst government services, a financial sector that's increasingly APIdriven, and critical energy assets like QatarEnergy's LNG operations layering more connected OTICS systems every year. That pace of transformation makes Qatar an attractive target in the cyber realm, right now. Attackers don't need to compromise everything they just need one highvalue foothold, and Qatar's expanding digital footprint keeps handing them more doors to try. This risk is showing up in the data as well. The Problem A Small, Concentrated, HighPrecision Threat Unlike sprawling, highvolume threat landscapes elsewhere, Qatar's risk profile in 202526 has been described as quietly highstakes rather than loud. Attack...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
Cyble Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us Qatar is racing toward a knowledge-based, fully digital economy. But that pace of transformation makes Qatar an attractive target in the cyber realm.
Post #90735 309
πŸ“” Researcher Publishes CrowdStrike Privilege Escalation Zero Day πŸ“”

A security researcher has posted a zeroday exploit in CrowdStrike which could allow hackers to escalate privileges.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Researcher Shares CrowdStrike Privilege Escalation Zero Day A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges
Post #90734 248
πŸ“” Multiple Class Action Lawsuits Filed Against IDScan πŸ“”

Several victims of a recent breach of drivers license information have sued the company they believe responsible.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Multiple Class Action Lawsuits Filed Against IDScan Several victims of a recent breach of driver’s license information have sued the company they believe responsible
Post #90733 230
πŸ“” North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters πŸ“”

Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’