TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.4K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90793 Β· Back to latest

Older Posts 20 shown
Post #90792 353
πŸ•΅οΈβ€β™‚οΈ Mythos Vulnerability Firehose Hits a Human Bottleneck πŸ•΅οΈβ€β™‚οΈ

An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Mythos Vulnerability Firehose Hits a Human Bottleneck An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and even fewer have been fixed.
Post #90791 419
πŸ“’ β€˜We can assume that all threat actors are using AI in some capacity’: Google cyber researchers warn hackers are ramping up automated attacks πŸ“’

Google Threat Intelligence Group has issued a warning over the increased threats posed by hackers using agentic AI tools.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro β€˜We can assume that all threat actors are using AI in some capacity’: Google cyber researchers warn hackers are ramping up automated… Google Threat Intelligence Group has issued a warning over the increased threats posed by hackers using agentic AI tools
Post #90790 536
πŸ“” Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls πŸ“”

The hacking tool, built using a combination of AI models, is effective against Android and iOS devices.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
Post #90788 423
πŸ–‹οΈ Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA πŸ–‹οΈ

Cybercriminals are hijacking artificial intelligence AI user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90787 385
🦿 This $50 lifetime VPN adds AI-powered protection to your connection 🦿

Get AIpowered threat protection, encrypted connections, and more with this VPN lifetime subscription today. The post This 50 lifetime VPN adds AIpowered protection to your connection appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic This $50 lifetime VPN adds AI-powered protection to your connection Get AI-powered threat protection, encrypted connections, and more with this VPN lifetime subscription today.
Post #90784 320
πŸ–‹οΈ Webinar: Learn How to Answer β€œAre We Exposed?” Faster After a New CVE πŸ–‹οΈ

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90783 276
πŸ“” Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026 πŸ“”

The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in Septembe The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
Post #90782 237
πŸ–‹οΈ SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution πŸ–‹οΈ

SAP has released security updates to address multiple vulnerabilities, including a maximumseverity flaw in SAP Extended Passport EPP Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE202644756 CVSS score 10.0, has been described as a case of memory corruption. Discovered and reported by SAP.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90781 269
πŸ–‹οΈ Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed πŸ–‹οΈ

The security researcher known as Chaotic Eclipse has dropped a proofofconcept PoC for yet another zeroday in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE202669414 CVSS score 7.8, also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE202669414," Chaotic.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90780 208
πŸ–‹οΈ F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans πŸ–‹οΈ

Malware linked to breakins at F5 BIGIP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90779 231
πŸ–‹οΈ New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root πŸ–‹οΈ

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mailrelated privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90778 202
πŸ–‹οΈ Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox πŸ–‹οΈ

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The mediumseverity vulnerability, assigned the CVE identifier CVE202687491 CVSS score NA, has been described as an outofbounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Outofbounds write in V8 in Google Chrome prior to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90777 248
πŸ–‹οΈ U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok πŸ–‹οΈ

U.S. cybersecurity and intelligence agencies have accused Chinabased artificial intelligence AI companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrialscale and one that forms the "core" of their AI development strategy, according to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90776 300
πŸ–‹οΈ Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets πŸ–‹οΈ

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a selfhosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90775 315
πŸ–‹οΈ DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval πŸ–‹οΈ

A flaw in DeepSeek Harness, DeepSeek's opensource tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operatingsystem sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90773 352
πŸ“’ Is Shai-Hulud back? Researchers spot 'wormy boy' slipping past npm malware scanning features πŸ“’

After a 111day hiatus, Aikido detected a previouslydocumented ShaiHulud worm payload in four npm package releases published this week.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Is Shai-Hulud back? Researchers spot 'wormy boy' slipping past npm malware scanning features After a 111-day hiatus, Aikido detected a previously-documented Shai-Hulud worm payload in four npm package releases published this week
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’