TGViewer
Channel Public Channel
๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

@cibsecurity

๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Subscribers
28.4K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90853 ยท Back to latest

Older Posts 20 shown
Post #90851 261
๐Ÿ“” Revolut Confirms Data Breach Through Fake Government Requests ๐Ÿ“”

An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine Revolut Confirms Data Breach Through Fake Government Requests An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
Post #90850 334
๐Ÿ“” Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems ๐Ÿ“”

MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Sy MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military
Post #90848 181
๐Ÿ“” Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens ๐Ÿ“”

Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service
Post #90847 182
๐Ÿ–‹๏ธ Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data ๐Ÿ–‹๏ธ

Microsoft has disclosed details of two campaigns in which threat actors are abusing thirdparty email delivery infrastructure to blast financial fraud scam messages and using passkeythemed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90846 200
๐Ÿ–‹๏ธ Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users ๐Ÿ–‹๏ธ

A malicious crossstore Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer JeetBot," lists HISHIMIROjeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox AddOns store Chrome .

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90845 247
๐Ÿ–‹๏ธ AI Changed the Exposure Problem. Validation Needs to Change With It. ๐Ÿ–‹๏ธ

There's a lot of noise around AI and cybersecurity right now. Whats actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49 more than in the.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90844 206
๐Ÿ–‹๏ธ โšก Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits ๐Ÿ–‹๏ธ

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90843 178
๐Ÿ–‹๏ธ WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution ๐Ÿ–‹๏ธ

WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90842 195
๐Ÿ–‹๏ธ Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries ๐Ÿ–‹๏ธ

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internetfacing instances as part of a multinational campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwanbased systems," Acronis Threat Research Unit TRU.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90841 207
๐Ÿ–‹๏ธ Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports ๐Ÿ–‹๏ธ

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90840 197
๐Ÿ–‹๏ธ 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials ๐Ÿ–‹๏ธ

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90839 192
๐Ÿ–‹๏ธ New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ๐Ÿ–‹๏ธ

Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #90838 190
๐Ÿฆฟ LG Pushes Back on Claims That Its Smart TVs Are Spying on Users ๐Ÿฆฟ

Researchers allege LG smart TVs can capture ambient audio and scan home networks, while LG disputes the findings and explains its privacy controls. The post LG Pushes Back on Claims That Its Smart TVs Are Spying on Users appeared first on TechRepublic.

๐Ÿ“– Read more.

๐Ÿ”— Via "Tech Republic"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
TechRepublic LG Pushes Back on Claims That Its Smart TVs Are Spying on Users Researchers allege LG smart TVs can capture ambient audio and scan home networks, while LG disputes the findings and explains its privacy controls.
Post #90837 226
๐Ÿฆฟ Texas Judge Finds TikTok Liable for Misleading Parents About Child Safety Controls ๐Ÿฆฟ

A Texas judge found TikTok liable for misleading parents about child safety controls, shifting the case toward penalties and possible restrictions. The post Texas Judge Finds TikTok Liable for Misleading Parents About Child Safety Controls appeared first on TechRepublic.

๐Ÿ“– Read more.

๐Ÿ”— Via "Tech Republic"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
TechRepublic Texas Judge Finds TikTok Liable for Misleading Parents About Child Safety Controls A Texas judge found TikTok liable for misleading parents about child safety controls, shifting the case toward penalties and possible restrictions.
Post #90836 247
๐Ÿ•ต๏ธโ€โ™‚๏ธ Anthropic CEO: Time to Shift From Improving to Controlling AI ๐Ÿ•ต๏ธโ€โ™‚๏ธ

Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?.

๐Ÿ“– Read more.

๐Ÿ”— Via "Dark Reading"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Dark Reading Anthropic CEO: Time to Shift From Improving to Controlling AI Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up.
  • ๐Ÿค” 1
Post #90835 300
๐Ÿ•ต๏ธโ€โ™‚๏ธ Maximum Severity GitLab Flaw Puts Supply Chains at Risk ๐Ÿ•ต๏ธโ€โ™‚๏ธ

CVE202685706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

๐Ÿ“– Read more.

๐Ÿ”— Via "Dark Reading"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Dark Reading Maximum Severity GitLab Flaw Puts Supply Chains at Risk CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
Post #90834 483
๐Ÿ•ต๏ธโ€โ™‚๏ธ 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink ๐Ÿ•ต๏ธโ€โ™‚๏ธ

The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

๐Ÿ“– Read more.

๐Ÿ”— Via "Dark Reading"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Dark Reading 'Sandworm' Chains Cisco Flaws to Deploy Cyclops Blink The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
Older posts โ†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook โ†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 โ†’