🛡 Cybersecurity & Privacy 🛡 - News


Гео и язык канала: Весь мир, Английский
Категория: Технологии


🗞 The finest daily news on cybersecurity and privacy.
🔔 Daily releases.
💻 Is your online life secure?
📩 lalilolalo.dev@gmail.com

Связанные каналы  |  Похожие каналы

Гео и язык канала
Весь мир, Английский
Категория
Технологии
Статистика
Фильтр публикаций


🖋️ Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories 🖋️

Cybersecurity researchers have disclosed details of an ongoing credentialtheft campaign that has compromised two highprofile opensource maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 1320 UTC," StepSecurity.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity


♟️ FBI Arrests Founder of Ransomware Negotiation Firm ♟️

Agents with the Federal Bureau of Investigation FBI on Thursday arrested the cofounder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.

📖 Read more.

🔗 Via "Krebs on Security"

----------
👁️ Seen on @cibsecurity


🕵️‍♂️ ASOS Breach Reveals the Risks in Customer-Facing SaaS 🕵️‍♂️

The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity


🦿 AI Agents, Local Hardware, and Security Risks Reshape Tech 🦿

Explore the latest tech news, from ChatGPT's interactive AI tools and Microsoft's new hardware to cybersecurity threats, robotics, and Big Tech shakeups. The post AI Agents, Local Hardware, and Security Risks Reshape Tech appeared first on TechRepublic.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity


🕵️‍♂️ AI Scramble Drives Cybersecurity M&A Boom 🕵️‍♂️

Welcome to another gangbuster year for strategic MA activity in cyber, with 117 deals announced in the latest quarter. What's different Many of the buyers are not your typical cybersecurity firms.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity


🖋️ FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack 🖋️

The FBI has arrested another suspected coconspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity


🕵️‍♂️ What We Missed: FBI Strikes Back at ShinyHunters 🕵️‍♂️

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagonrun data center.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity


🖋️ P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands 🖋️

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its ondevice footprint, adds ondevice keychain and cryptowallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity


🕵️‍♂️ Security Threats Don't Stop at the Office: Why Executives' Families Need Training Too 🕵️‍♂️

Those closest to executives must match their security postures because the weakest link in a family becomes the entry point for attacks.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity


🌊 Red Team Assessment: Scope, Process, Deliverables 🌊

In August 2026, the US Cybersecurity and Infrastructure Security Agency CISA published two red team assessments it ran at the same time, with similar tradecraft, against two critical infrastructure organizations. In both, the team reached full domain compromise and sensitive business systems. Only one of the two security operations centers SOCs noticed. According to CISAs The post Red Team Assessment Scope, Process, Deliverables appeared first on UnderDefense.

📖 Read more.

🔗 Via "UnderDefense"

----------
👁️ Seen on @cibsecurity


🌊 10 Best Agentic AI SOC Platforms for 2026 🌊

Compare 8 best agentic SOC platforms for 2026. Pricing, integrations, compliance, and POC frameworks scored across 500 MDR deployments. Evaluate now. The post 10 Best Agentic AI SOC Platforms for 2026 appeared first on UnderDefense.

📖 Read more.

🔗 Via "UnderDefense"

----------
👁️ Seen on @cibsecurity


📔 AI Training Critical as Governance Challenges Grow 📔

As AI adoption accelerates, ISACA is expanding its certification portfolio with a governancefocused credential designed to help professionals manage AI securely.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity


📔 UK and Allies Warn of Cyber Threat from China’s Integrity Technology Group 📔

The UK, US and allies have issued an alert detailing malicious activity linked to Chinas Integrity Technology Group.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity


📔 Q3 2026 Sets New Record for Ransomware Attacks 📔

Comparitech observed 2627 claimed ransomware attacks in Q3, with critical sectors like finance, technology, education and healthcare experiencing significant increases.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity


📔 Wikimedia Says Rogue AI Agents Abused its Platforms 📔

Wikimedia says OpenAI agents performed unauthorized actions on its platforms, including edits to wikis.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity


🖋️ Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments 🖋️

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denialofservice DoS under certain conditions. "CVE2026107406 is a memory overflow vulnerability that may lead to remote code execution or denialofservice under specific configuration conditions," Citrix said. The vulnerability.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity


🖋️ Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own 🖋️

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs 300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity


🖋️ GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys 🖋️

A bug in GoBalance, a tool many darkweb sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity


🖋️ The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition 🖋️

As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical velocity paradox, in which organizations invest in AIspeed business operations while continuing to rely on humanspeed security controls, creating a.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity


🖋️ Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies 🖋️

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Thursday added five security flaws to its Known Exploited Vulnerabilities KEV catalog, following their abuse by a Chinalinked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below CVE20153306 CVSS score 10.0 An improper access control vulnerability in ProFTPD that could allow.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity

Показано 20 последних публикаций.