TGViewer
Channel Public Channel
πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News

@cibsecurity

πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Subscribers
28.4K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #91013 Β· Back to latest

Older Posts 20 shown
Post #91012 188
🦿 Google Wants Android Apps to Look Beyond the Security Patch Date 🦿

Googles new Android security libraries let apps and administrators inspect patch status by component instead of relying on a single security patch date. The post Google Wants Android Apps to Look Beyond the Security Patch Date appeared first on TechRepublic.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
TechRepublic Google Wants Android Apps to Look Beyond the Security Patch Date Google’s new Android security libraries let apps and administrators inspect patch status by component instead of relying on a single security patch date.
Post #91011 159
πŸ•΅οΈβ€β™‚οΈ Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents πŸ•΅οΈβ€β™‚οΈ

The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents The AI giant disclosed six examples of concerning model behavior and published a new framework for investigating and disclosing such incidents.
Post #91009 179
πŸ•΅οΈβ€β™‚οΈ ShinyHunters Hacked Clop. Now What About Clop's Victims? πŸ•΅οΈβ€β™‚οΈ

ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading ShinyHunters Hacked Clop. Now What About Clop's Victims? ShinyHunters breached rival ransomware gang Clop's leak site, threatening to expose victim payment data and raising concerns about secondary data exposure.
Post #91008 204
πŸ•΅οΈβ€β™‚οΈ How AI Agents Can Trigger Runaway Costs for Enterprises πŸ•΅οΈβ€β™‚οΈ

Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading How AI Agents Can Trigger Runaway Costs for Enterprises Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
Post #91007 419
πŸ•΅οΈβ€β™‚οΈ More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds πŸ•΅οΈβ€β™‚οΈ

Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and ITOT convergence expand operational risk.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
Dark Reading Industrial Orgs See Cybersecurity Risk as Growth Obstacle Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
Post #91006 251
πŸ“’ Freelance tech pros beware: North Korean cyber criminals are targeting gig workers in a new malware campaign πŸ“’

Fake tests during the recruitment process infect applicants' devices to steal cryptocurrency.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Freelance tech pros beware: North Korean cyber criminals are targeting gig workers in a new malware campaign Fake tests during the recruitment process infect applicants' devices to steal cryptocurrency
Post #91005 258
πŸ“’ Data embassies and sovereign dispersion πŸ“’

Sovereign dispersion offers IT leaders an early look at how the residencyversusresilience tradeoff could be resolved at scale, before they're forced to make the same call with their own data.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro Data embassies and sovereign dispersion Sovereign dispersion offers IT leaders an early look at how the residency-versus-resilience trade-off could be resolved at scale, before they're forced to make the same call with their own data
Post #91004 297
πŸ“’ β€˜Cyber criminal groups suffer from the same security weaknesses they routinely exploit’: ShinyHunters claims it hacked Clop ransomware rival πŸ“’

An attack on the cyber crime gang could prove dangerous for previous victims of data leaks, experts have warned.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro β€˜Cyber criminal groups suffer from the same security weaknesses they routinely exploit’: ShinyHunters claims it hacked Clop ransomware… An attack on the cyber crime gang could prove dangerous for previous victims if data leaks, experts have warned
Post #91003 533
πŸ“’ β€˜Rising threats and under-resourcing for cybersecurity is taking a toll on the people tasked with managing it’: Cyber teams are being pushed to breaking point – and AI is doing little to alleviate strain πŸ“’

An increasingly perilous threat landscape and lack of funding means cyber teams are being stretched too thin.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
IT Pro β€˜Rising threats and under-resourcing for cybersecurity is taking a toll on the people tasked with managing it’: Cyber teams are… An increasingly perilous threat landscape and lack of funding means cyber teams are being stretched too thin
Post #91002 977
πŸ–‹οΈ Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar πŸ–‹οΈ

A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters Can it actually be exploited in your environment? Mythosclass AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #91001 847
πŸ–‹οΈ Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws πŸ–‹οΈ

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
  • ❀ 1
Post #91000 541
πŸ–‹οΈ CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild πŸ–‹οΈ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities KEV catalog, citing evidence of active exploitation. The vulnerabilities are listed below CVE202539682 CVSS score 9.8 An improper check for unusual or exceptional conditions vulnerability in the TLS receive path.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90999 427
πŸ–‹οΈ SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE πŸ–‹οΈ

SolarWinds has released security updates to address a highseverity flaw in Access Rights Manager ARM that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE202628326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90998 319
πŸ–‹οΈ SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE πŸ–‹οΈ

SolarWinds has released security updates to address a highseverity flaw in Access Rights Manager ARM that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE202628326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90997 271
πŸ–‹οΈ Identity Visibility in 2026: The Foundation of Identity Security πŸ–‹οΈ

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90996 227
πŸ–‹οΈ CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories πŸ–‹οΈ

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90995 219
πŸ–‹οΈ Identity Visibility in 2026: The Foundation of Identity Security πŸ–‹οΈ

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90994 191
πŸ–‹οΈ Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar πŸ–‹οΈ

A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters Can it actually be exploited in your environment? Mythosclass AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Post #90993 170
πŸ–‹οΈ Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up πŸ–‹οΈ

Google's Gemini model has become the latest artificial intelligence AI system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’