TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.4K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90913 Β· Back to latest

Older Posts 20 shown
Post #90912 94
πŸ–‹οΈ Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers πŸ–‹οΈ

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle aka APTQ95, a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90911 123
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90910 95
β™ŸοΈ Data Broker Radaris Loses Domains in Privacy Fight β™ŸοΈ

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of peoplesearch services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
Krebs on Security Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated…
Post #90909 88
🦿 Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V 🦿

Microsoft released an outofband Windows update to fix Remote Desktop, HyperV Linux sharing, and USB audio issues caused by its September patch. The post Microsoft Issues OutofBand Windows Update After September Patch Breaks Remote Desktop, HyperV appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Microsoft Issues Out-of-Band Windows Update Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch.
Post #90908 99
🦿 Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes 🦿

Apple is rolling out new parental controls for iPhone, iPad and Mac, including website approvals, Screen Time changes and expanded safety tools. The post Apple Adds New Parental Controls to iPhone, iPad and Mac Heres What Changes appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Apple Adds New Parental Controls to iPhone, iPad and Mac Apple is rolling out new parental controls for iPhone, iPad and Mac, including website approvals, Screen Time changes and expanded safety tools.
Post #90907 115
πŸ•΅οΈβ€β™‚οΈ Microsoft Issues Emergency Fixes After Massive Patch Tuesday πŸ•΅οΈβ€β™‚οΈ

You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Microsoft Issues Emergency Fixes After Massive Patch Tuesday You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
Post #90906 144
πŸ•΅οΈβ€β™‚οΈ Cyber Op Targets South Korean Media & Automotive Sectors πŸ•΅οΈβ€β™‚οΈ

A likely North Korean advanced persistent threat APT group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Cyber Op Targets South Korean Media & Automotive Sectors A North Korean APT group used a new Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
Post #90905 143
πŸ•΅οΈβ€β™‚οΈ BragJack Attack Can Turn a Browser's Agentic AI Against It πŸ•΅οΈβ€β™‚οΈ

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading BragJack Attack Can Turn a Browser's Agentic AI Against It A new type of attack hijacks AI assistants built directly into a browser to access sensitive information, execute malicious actions, and exfiltrate data.
Post #90904 139
πŸ•΅οΈβ€β™‚οΈ Fighting Your Dragons Through Tough Tech Times πŸ•΅οΈβ€β™‚οΈ

Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and selfdoubt and shares how to build meaningful connections during historical tech industry downturns.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Finding Hope During Tough Tech Times Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and shares advice on building connections during tech industry downturns.
Post #90903 149
πŸ•΅οΈβ€β™‚οΈ AI Security Spending Jumps as Fear Outpaces Proof of Value πŸ•΅οΈβ€β™‚οΈ

CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading AI Security Spending Jumps as Fear Outpaces Proof of Value CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
Post #90900 376
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90899 324
πŸ“” PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug πŸ“”

Attackers are exploiting a critical flaw in a thirdparty WooCommerce plugin to upload PHP webshells.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine PHP Webshell Campaign Targets WordPress Through WooCommerce Bug Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
Post #90898 258
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90897 238
πŸ•΅οΈβ€β™‚οΈ BragJack Attack Can Turn a Browser's Agentic AI Against It πŸ•΅οΈβ€β™‚οΈ

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading BragJack Attack Can Turn a Browser's Agentic AI Against It A new type of attack hijacks AI assistants built directly into a browser to access sensitive information, execute malicious actions, and exfiltrate data.
Post #90896 235
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90895 354
πŸ–‹οΈ Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution πŸ–‹οΈ

A critical security flaw in Issabel Framework, a webbased framework for the opensource unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE202689026 CVSS v3.1 score 9.8CVSS v4.0 score 9.3, which can allow an unauthenticated remote attacker to execute arbitrary operating system OS commands by taking advantage of a hardcoded.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90894 371
πŸ•΅οΈβ€β™‚οΈ BragJack Attack Can Turn a Browser's Agentic AI Against It πŸ•΅οΈβ€β™‚οΈ

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading BragJack Attack Can Turn a Browser's Agentic AI Against It A new type of attack hijacks AI assistants built directly into a browser to access sensitive information, execute malicious actions, and exfiltrate data.
Post #90893 519
πŸ–‹οΈ Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation πŸ–‹οΈ

Google has disclosed that a highseverity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE202658704 CVSS score 8.0, is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’