🛡 Cybersecurity & Privacy 🛡 - News – Telegram
🛡 Cybersecurity & Privacy 🛡 - News
24.4K subscribers
87.9K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🖋️ SOC Analysts - Reimagining Their Role Using AI 🖋️

The job of a SOC analyst has never been easy. Faced with an overwhelming flood of daily alerts, analysts and sometimes IT teams who are doubling as SecOps must try and triage thousands of security alertsoften false positivesjust to identify a handful of real threats. This relentless, 247 work leads to alert fatigue, desensitization, and increased risk of missing critical security incidents.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ DeepSeek AI Database Exposed: Over 1 Million Log Lines, Secret Keys Leaked 🖋️

Buzzy Chinese artificial intelligence AI startup DeepSeek, which has had a meteoric rise in popularity in recent days, left one of its databases exposed on the internet, which could have allowed malicious actors to gain access to sensitive data. The ClickHouse database "allows full control over database operations, including the ability to access internal data," Wiz security researcher Gal.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📔 UK Organizations Boosting Cybersecurity Budgets 📔

UK organizations are significantly increasing cybersecurity budgets, with a projected 31 growth in the next year.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Ransomware Attack Disrupts Blood Donation Services in US 📔

New York Blood Center Enterprises revealed that it has been hit by a ransomware attack, disrupting activities and blood drives at its centers across the country.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📢 How hackers bypass MFA – and what to do about it 📢

Security leaders must ensure theres more to their defenses than the simplest identity checks.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
📢 Malicious GitHub repositories target users with malware 📢

Criminals are exploiting GitHub's reputation to install Lumma Stealer disguised as game hacks and cracked software.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Exposure Management Provider CYE Acquires Solvo 🕵️‍♂️

The addition of Solvo CSPM to CYE Hyver aims to address need for multicloud vulnerability monitoring and risk assessment.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🦿 How to Use Keeper Password Manager: A Comprehensive Guide 🦿

This stepbystep guide shows you how to set up Keeper Password Manager and use it to secure and organize your passwords.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🧠 When ransomware kills: Attacks on healthcare facilities 🧠

As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients lives are literally on the line. Since 2015, there has been a staggering increase in ransomware The post When ransomware kills Attacks on healthcare facilities appeared first on Security Intelligence.

📖 Read more.

🔗 Via "Security Intelligence"

----------
👁️ Seen on @cibsecurity
🖋️ Authorities Seize Domains of Popular Hacking Forums in Major Cybercrime Crackdown 🖋️

An international law enforcement operation has dismantled the domains associated with various online platforms linked to cybercrime such as Cracked, Nulled, Sellix, and StarkRDP. The effort has targeted the following domains www.cracked.io www.nulled.to www.mysellix.io www.sellix.io www.starkrdp.io Visitors to these websites are now greeted by a seizure banner that says they were confiscated.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Lightning AI Studio Vulnerability Allowed RCE via Hidden URL Parameter 🖋️

Cybersecurity researchers have disclosed a critical security flaw in the Lightning AI Studio development platform that, if successfully exploited, could allow for remote code execution. The vulnerability, rated a CVSS score of 9.4, enables "attackers to potentially execute arbitrary commands with root privileges" by exploiting a hidden URL parameter, application security firm Noma said in a.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📔 Syncjacking Attack Enables Full Browser and Device Takeover 📔

SquareX researchers warn that browser syncjacking could lead to full browser and device hijacking.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 DeepSeek Exposed Database Leaks Sensitive Data 📔

Researchers at Wiz uncovered a publicly accessible database belonging to Chinese GenAI provider DeepSeek that leaked sensitive data, including chat history.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
👏1
🦅 DeepSeek’s Growing Influence Sparks a Surge in Frauds and Phishing Attacks 🦅

Overview DeepSeek is a Chinese artificial intelligence company that has developed opensource large language models LLMs. In January 2025, DeepSeek launched its first free chatbot app, DeepSeek AI Assistant, which rapidly became the most downloaded free app on the iOS App Store in the United States, surpassing even OpenAIs ChatGPT. However, with rapid growth comes new riskscybercriminals are exploiting DeepSeeks reputation through phishing campaigns, fake investment scams, and malware disguised as DeepSeek. This analysis seeks to explore recent incidents where Threat Actors TAs have impersonated DeepSeek to target users, highlighting their tactics and how readers can secure themselves accordingly. Recently, Cyble Research and Intelligence Labs CRIL identified multiple suspicious...

📖 Read more.

🔗 Via "CYBLE"

----------
👁️ Seen on @cibsecurity
👍1
🕵️‍♂️ New Jailbreaks Allow Users to Manipulate GitHub Copilot 🕵️‍♂️

Whether by intercepting its traffic or just giving it a little nudge, GitHub's AI assistant can be made to do malicious things it isn't supposed to.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🖋️ Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations 🖋️

Over 57 distinct threat actors with ties to China, Iran, North Korea, and Russia have been observed using artificial intelligence AI technology powered by Google to further enable their malicious cyber and information operations. "Threat actors are experimenting with Gemini to enable their operations, finding productivity gains but not yet developing novel capabilities," Google Threat.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📔 Attackers Increase Use of HTTP Clients for Account Takeovers 📔

HTTP client tools used to compromise Microsoft 365 environments with 78 of tenants targeted in 2024.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
👍1
♟️ Infrastructure Laundering: Blending in with the Cloud ♟️

In an effort to blend in and make their malicious traffic tougher to block, hosting firms catering to cybercriminals in China and Russia increasingly are funneling their operations through major U.S. cloud providers. Research published this week on one such outfit a sprawling network tied to Chinese organized crime gangs and aptly named "Funnull" highlights a persistent whacamole problem facing cloud services.

📖 Read more.

🔗 Via "Krebs on Security"

----------
👁️ Seen on @cibsecurity
📔 Google Blocked 2.36 Million Policy-Violating Apps 📔

Google Play blocked 2.36 million policyviolating apps and banned 158,000 harmful developer accounts in 2024.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
👎1
🦿 DeepSeek Locked Down Public Database Access That Exposed Chat History 🦿

Research Firm Wiz Research began investigating DeepSeek soon after its generative AI took the tech world by storm.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Healthcare Sector Charts 2 More Ransomware Attacks 🕵️‍♂️

No ransomware groups have yet to claim responsibility for either attack, and both institutions have yet to reveal what may have been stolen.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity