TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.4K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90833 Β· Back to latest

Older Posts 20 shown
Post #90832 1.27K
πŸ–‹οΈ Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks πŸ–‹οΈ

Anthropic on Thursday said it identified and disrupted industrialscale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai aka Zhipu, and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
  • ❀ 1
Post #90831 1.11K
πŸ–‹οΈ GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure πŸ–‹οΈ

GitLab has released patches to address multiple flaws, including a maximumseverity security vulnerability that has witnessed inthewild probes within hours of public disclosure. The vulnerability in question is CVE202685706 CVSS score 10.0, a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90830 896
🦿 Anthropic Says Claude Used in Possible Bioweapon Research 🦿

Anthropic says researchers used Claude for biological work that could support weapons development, exposing new challenges for AI safeguards. The post Anthropic Says Claude Used in Possible Bioweapon Research appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Anthropic Says Claude Used in Possible Bioweapon Research Anthropic says researchers used Claude for biological work that could support weapons development, exposing new challenges for AI safeguards.
Post #90829 647
🦿 EU Gets Access to Anthropic Cyber AI β€” But Not Its Newest Model 🦿

ENISA has gained access to Anthropics Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations. The post EU Gets Access to Anthropic Cyber AI But Not Its Newest Model appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic EU Gets Access to Anthropic Cyber AI β€” But Not Its Newest Model ENISA has gained access to Anthropic’s Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations.
Post #90828 507
πŸ–‹οΈ Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection πŸ–‹οΈ

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian statesponsored threat actor that abused Claude for developing an AIassisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG20006 where "GTG" stands for Generative Threat Group, which aligns with broader reporting linking the cluster to Midnight.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90827 489
πŸ–‹οΈ Claude Used to Automate Exploitation and Data Theft Across Multiple Victims πŸ–‹οΈ

Anthropic has warned that cybercriminals and statesponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence AI company has branded Generative Threat Groups GTGs, span statesponsored groups, financially motivated criminals, commercial.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90826 434
πŸ“” Most Organizations Skip Permissions Reviews Before Deploying AI Tools πŸ“”

A new Syskit study has shown that only 43 of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Most Organizations Skip Permissions Reviews Before Deploying AI Tools A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review
Post #90825 381
πŸ“” Hackers Favor US Eastern Business Hours in M365 Phishing Campaign πŸ“”

KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365s Direct Send to send malicious emails.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Hackers Favor US Eastern Business Hours in M365 Phishing Campaign KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
Post #90824 375
πŸ–‹οΈ Your Critical Vulnerabilities Might Not Be Your Biggest Risk πŸ–‹οΈ

Security teams have become exceptionally talented at finding vulnerabilities. Now, its time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90823 449
πŸ“’ What is AI distillation? The new threat facing western tech giants as US accuses Chinese firms of β€˜aggressively’ copying frontier models πŸ“’

A host of Chinese tech companies have been accused of AI distillation practices to keep pace with US rivals.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro What is AI distillation? The new threat facing western tech giants as US accuses Chinese firms of β€˜aggressively’ copying frontier… A host of Chinese tech companies have been accused of β€˜AI distillation’ practices to keep pace with US rivals
Post #90822 492
πŸ–‹οΈ Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware πŸ–‹οΈ

Cisco has revealed that three distinct threat clusters linked to ransomware and statesponsored attacks have been exploiting two recently patched Secure Firewall Management Center FMC vulnerabilities. The attacks leverage CVE202620079 CVSS score 10.0, an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90821 506
πŸ–‹οΈ PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws πŸ–‹οΈ

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NGMF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases MR that.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90820 401
πŸ–‹οΈ China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor πŸ–‹οΈ

A Chinalinked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the loggedin user could do. Tencent, which owns.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90819 361
πŸ–‹οΈ Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors πŸ–‹οΈ

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of selfhosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90818 488
🌊 How AiTM Phishing Bypasses MFA, and Why Phishing-Resistant MFA Would Have Stopped It 🌊

Compare the 10 best AI SOC platforms that keep your own SIEM data lake. Evaluate data sovereignty, onprem options, and lockin. Explore the shortlist now. The post How AiTM Phishing Bypasses MFA, and Why PhishingResistant MFA Would Have Stopped It appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
UnderDefense Phishing-Resistant MFA: An AiTM Case Study | UnderDefense An AiTM phishing assessment bypassed MFA, hijacked a session, and reached a dev team's AI coding assistant. See what phishing-resistant MFA stops.
Post #90817 352
πŸ–‹οΈ ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories πŸ–‹οΈ

A lot of this weeks security news has the same awkward answer to one question Why was that allowed to work? An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isnt. Different stories, same basic problem the path in was often already.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90816 404
🦿 CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem 🦿

CISAs ChatGPT incident exposes a growing AI governance gap as enterprises struggle to define who is accountable for actions taken by AI agents. The post CISAs ChatGPT Incident Exposes a Bigger AI Governance Problem appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem CISA’s ChatGPT incident exposes a growing AI governance gap as enterprises struggle to define who is accountable for actions taken by AI agents.
Post #90815 295
🦿 US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models 🦿

US agencies accuse six Chinese AI firms of distilling frontier models and recommend new defenses that could affect enterprise AI access and API use. The post US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic US Accuses Six Chinese AI Firms of Distilling Frontier Models US agencies accuse six Chinese AI firms of distilling frontier models and recommend new defenses that could affect enterprise AI access and API use.
Post #90814 268
πŸ•΅οΈβ€β™‚οΈ Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit πŸ•΅οΈβ€β™‚οΈ

The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zeroday exploit for Windows Defender.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Nightmare-Eclipse Strikes Again With ShieldCrash Windows Exploit The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
Post #90813 396
πŸ•΅οΈβ€β™‚οΈ Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data πŸ•΅οΈβ€β™‚οΈ

Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data Threat actors are leveraging Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’