TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.4K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #90953 Β· Back to latest

Older Posts 20 shown
Post #90952 225
πŸ–‹οΈ BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS πŸ–‹οΈ

The Internet Systems Consortium ISC has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its opensource DNS server software. One of them affects any BIND server that answers DNSoverHTTPS DoH. A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90951 155
πŸ–‹οΈ OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads πŸ–‹οΈ

OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and betterinformed consensus on the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90950 148
πŸ–‹οΈ China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America πŸ–‹οΈ

The Chinaaligned statesponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C backdoor," ESET security researchers Alexandre Ct Cyr and Romain Dumont said in a technical report shared with The Hacker News.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90949 161
πŸ–‹οΈ CISO's Expert Guide to Agentic Pentesting for Websites πŸ–‹οΈ

Attackers now weaponize new vulnerabilities in about five days Mandiant, part of Google Cloud. The median organization takes 43 days to patch one Verizon DBIR 2026. A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TLDR Exploitation is now the front door. It starts 31 of breaches Verizon DBIR.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90948 153
πŸ–‹οΈ Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar πŸ–‹οΈ

A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters Can it actually be exploited in your environment? Mythosclass AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90947 154
πŸ–‹οΈ Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone πŸ–‹οΈ

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE202681642, along with.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90944 494
πŸ“” NCSC and Allies Warn of Iranian Spyware Campaign πŸ“”

The UKs National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine NCSC and Allies Warn of Iranian Spyware Campaign The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
Post #90943 405
πŸ“” Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes πŸ“”

A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs PIVOT program.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Major Cyber Threat Detection Vendors Turn to New UK Testing Program A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
Post #90941 182
πŸ“” Cyber-Attacks Cost Organizations $52,000 on Average πŸ“”

Hiscox highlighted the huge financial and operational costs of cyberattacks, with the average cost of an incident at 52,000.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Cyber-Attacks Cost Organizations $52,000 on Average Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
Post #90940 153
πŸ“” NCSC and Allies Warn of Iranian Spyware Campaign πŸ“”

The UKs National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine NCSC and Allies Warn of Iranian Spyware Campaign The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
Post #90938 217
πŸ“” Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes πŸ“”

A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs PIVOT program.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Major Cyber Threat Detection Vendors Turn to New UK Testing Program A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
Post #90937 121
πŸ“” PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug πŸ“”

Attackers are exploiting a critical flaw in a thirdparty WooCommerce plugin to upload PHP webshells.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine PHP Webshell Campaign Targets WordPress Through WooCommerce Bug Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
Post #90935 108
πŸ“” Cyber-Attacks Cost Organizations $52,000 on Average πŸ“”

Hiscox highlighted the huge financial and operational costs of cyberattacks, with the average cost of an incident at 52,000.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
Infosecurity Magazine Cyber-Attacks Cost Organizations $52,000 on Average Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
Post #90934 126
πŸ–‹οΈ Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens πŸ–‹οΈ

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE20265430 CVSS score 9.810.0, is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
  • πŸ”₯ 1
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’