gram news
🛡 Cybersecurity & Privacy 🛡 - News channel avatar

🛡 Cybersecurity & Privacy 🛡 - News

@cibsecurity

🗞 The finest daily news on cybersecurity and privacy. 🔔 Daily releases. 💻 Is your online life secure? 📩 lalilolalo.dev@gmail.com

ProjectsENTech

27,932subscribers

Open the Channel

Latest posts

  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 15:33

    📢 NCSC talks up agents for cyber defense – but there's an 'inconvenient truth' businesses need to accept 📢Cyber defenders need to identify the lowestrisk actions that can be automated before making decisions about adoption.📖 Read more.🔗 Via "ITPro"---------- 👁️ Seen on @cibsecurity
    IT ProNCSC talks up agents for cyber defense – but there's an 'inconvenient truth' businesses need to acceptCyber defenders need to identify the lowest-risk actions that can be automated before making decisions about adoption
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 14:00

    📔 North Korean Attackers Hit 30,000 Devices and Steal $10.7m 📔WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineNorth Korean Attackers Hit 30,000 Devices and Steal $10.7mWaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 13:30

    🖋️ New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups 🖋️Attackers are exploiting a new flaw in onpremises VeloCloud Orchestrator VCO, the server that manages the Edge devices in a VeloCloud SDWAN, Arista said on September 22. The flaw, tracked as CVE202693952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 13:30

    🖋️ AI Agents Are Rewriting the Rules of Lateral Movement 🖋️Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 13:00

    📔 AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds 📔A new report by ISACA found that 71 of orgs have not run AI incident response exercises as teams face rising pressure.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineAI Incident Response Readiness Lags Behind AI Adoption, ISACA FindsISACA found 71% of orgs have not run AI incident response exercises as teams face rising pressure
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:07

    📔 ShinyHunters Claim Hack of Rival Ransomware Gang Clop 📔ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineShinyHunters Claim Hack of Rival Ransomware Gang ClopShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    📔 Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign 📔CloudSEK linked GHAPPIER to a compromised npm package with valid trustedpublishing provenance.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineAttackers Abuse npm Trusted Publishing in GHAPPIER CampaignCloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    📔 New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code 📔Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineNew Exvicy ClickFix Framework Built on Rival ErrTraffic's CodeSekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    📔 Google Hit with €403m GDPR Fine Over Location Data Practices 📔The Irish DPC found that Google users were unaware that their location was being used to influence them with ads.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineGoogle Hit with €403m GDPR Fine Over Location Data PracticesThe Irish DPC found that Google users were unaware that their location was being used to influence them with ads
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    📔 CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns 📔Gartner warns that CISOs must update incident response playbooks as AIpowered deepfakes make social engineering attacks more convincing and harder to detect.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineCISOs Must Update Incident Response Playbooks for Multimodal DeepfakesGartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    📔 AI Drives Surge in Bot and API Threats 📔Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AIrelated threats.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineAI Drives Surge in Bot and API ThreatsAkamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    📔 Network Segmentation Failures Are Expanding the Corporate Attack Surface 📔Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks.📖 Read more.🔗 Via "Infosecurity Magazine"---------- 👁️ Seen on @cibsecurity
    Infosecurity MagazineNetwork Segmentation Failures Expand the Corporate Attack SurfaceForescout warns that incomplete network segmentation is widening the potential blast radius of attacks
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    🖋️ TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data 🖋️Cybersecurity researchers have disclosed details of a new campaign dubbed TASKSTOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals WiFi passwords and clipboard contents, takes screenshots, and accepts arbitrary.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    🖋️ ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks 🖋️A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    🖋️ Google Fined €403 Million Over GDPR Violations Tied to Location Data 🖋️Google has been fined 403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission DPC, Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    🖋️ Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto 🖋️The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:06

    🖋️ Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR 🖋️A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardwarecompatibility program signs the driver, scored zero detections on VirusTotal when researchers.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:05

    🖋️ Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access 🖋️The U.S. Cybersecurity and Infrastructure Security Agency CISA on Monday added a nowpatched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities KEV catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE20267273 CVSS score 8.8, is a stackbased buffer overflow vulnerability that could result in arbitrary operating.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:05

    🖋️ WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session 🖋️A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a loggedin administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE202693485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity
  • 🛡 Cybersecurity & Privacy 🛡 - News

    22 Sept, 12:05

    🖋️ One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor 🖋️Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proofofconcept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in.📖 Read more.🔗 Via "The Hacker News"---------- 👁️ Seen on @cibsecurity