TGViewer
Channel Public Channel
๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News

@cibsecurity

๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Subscribers
28.4K
Photos
0
Videos
0
Links
90.9K

Showing posts older than #91033 ยท Back to latest

Older Posts 20 shown
Post #91032 525
๐Ÿ“” ShinyHunters Claim Hack of Rival Ransomware Gang Clop ๐Ÿ“”

ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine ShinyHunters Claim Hack of Rival Ransomware Gang Clop ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data
Post #91031 432
๐Ÿ“” Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign ๐Ÿ“”

CloudSEK linked GHAPPIER to a compromised npm package with valid trustedpublishing provenance.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance
  • โค 1
Post #91029 349
๐Ÿ“” Google Hit with โ‚ฌ403m GDPR Fine Over Location Data Practices ๐Ÿ“”

The Irish DPC found that Google users were unaware that their location was being used to influence them with ads.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine Google Hit with โ‚ฌ403m GDPR Fine Over Location Data Practices The Irish DPC found that Google users were unaware that their location was being used to influence them with ads
Post #91028 271
๐Ÿ“” CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns ๐Ÿ“”

Gartner warns that CISOs must update incident response playbooks as AIpowered deepfakes make social engineering attacks more convincing and harder to detect.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect
Post #91026 326
๐Ÿ“” Network Segmentation Failures Are Expanding the Corporate Attack Surface ๐Ÿ“”

Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks.

๐Ÿ“– Read more.

๐Ÿ”— Via "Infosecurity Magazine"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Infosecurity Magazine Network Segmentation Failures Expand the Corporate Attack Surface Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks
Post #91025 232
๐Ÿ–‹๏ธ TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data ๐Ÿ–‹๏ธ

Cybersecurity researchers have disclosed details of a new campaign dubbed TASKSTOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals WiFi passwords and clipboard contents, takes screenshots, and accepts arbitrary.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91024 191
๐Ÿ–‹๏ธ โšก Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks ๐Ÿ–‹๏ธ

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91023 254
๐Ÿ–‹๏ธ Google Fined โ‚ฌ403 Million Over GDPR Violations Tied to Location Data ๐Ÿ–‹๏ธ

Google has been fined 403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission DPC, Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91022 214
๐Ÿ–‹๏ธ Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto ๐Ÿ–‹๏ธ

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91021 240
๐Ÿ–‹๏ธ Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR ๐Ÿ–‹๏ธ

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardwarecompatibility program signs the driver, scored zero detections on VirusTotal when researchers.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91020 307
๐Ÿ–‹๏ธ Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access ๐Ÿ–‹๏ธ

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Monday added a nowpatched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities KEV catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE20267273 CVSS score 8.8, is a stackbased buffer overflow vulnerability that could result in arbitrary operating.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91019 181
๐Ÿ–‹๏ธ WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session ๐Ÿ–‹๏ธ

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a loggedin administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE202693485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91018 192
๐Ÿ–‹๏ธ One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor ๐Ÿ–‹๏ธ

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proofofconcept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91017 169
๐Ÿ–‹๏ธ SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing ๐Ÿ–‹๏ธ

The threat actor known as SideCopy has been observed using spearphishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spearphishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91016 169
๐Ÿ–‹๏ธ Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal ๐Ÿ–‹๏ธ

A malicious npm package named "indexedbtree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexedbtree is a malicious npm package mimicking the legit sortedbtree package, an ordinary Btreeindexing utility," Checkmarx said. ".

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91015 222
๐Ÿ–‹๏ธ SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE ๐Ÿ–‹๏ธ

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE202665660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91014 192
๐Ÿ–‹๏ธ New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory ๐Ÿ–‹๏ธ

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE202689775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Post #91013 273
๐Ÿ–‹๏ธ DORA Year Two: Can Your SOC Actually See the Attack? ๐Ÿ–‹๏ธ

When the Digital Operational Resilience Act DORA became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing thirdparty service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is.

๐Ÿ“– Read more.

๐Ÿ”— Via "The Hacker News"

----------
๐Ÿ‘๏ธ Seen on @cibsecurity
Older posts โ†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook โ†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 โ†’