🛡 Cybersecurity & Privacy 🛡 - News – Telegram
🛡 Cybersecurity & Privacy 🛡 - News
24.5K subscribers
88K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
📔 Third Defendant Pleads Guilty in Fantasy Sports Betting Hack Case 📔

A Minnesota man has pleaded guilty to a credential stuffing scheme that compromised over 60,000 accounts.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🖋️ Featured Chrome Browser Extension Caught Intercepting Millions of Users' AI Chats 🖋️

A Google Chrome extension with a "Featured" badge and six million users has been observed silently gathering every prompt entered by users into artificial intelligence AIpowered chatbots like OpenAI ChatGPT, Anthropic Claude, Microsoft Copilot, DeepSeek, Google Gemini, xAI Grok, Meta AI, and Perplexity. The extension in question is Urban VPN Proxy, which has a 4.7 rating on the Google Chrome.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🤔21😱1
🖋️ Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence 🖋️

Threat hunters have discerned new activity associated with an Iranian threat actor known as Infy aka Prince of Persia, nearly five years after the hacking group was observed targeting victims in Sweden, the Netherlands, and Turkey. "The scale of Prince of Persia's activity is more significant than we originally anticipated," Tomer Bar, vice president of security research at SafeBreach, said.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
3
🖋️ U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware 🖋️

The U.S. Department of Justice DoJ this week announced the indictment of 54 individuals in connection with a multimillion dollar ATM jackpotting scheme. The largescale conspiracy involved deploying malware named Ploutus to hack into automated teller machines ATMs across the U.S. and force them to dispense cash. The indicted members are alleged to be part of Tren de Aragua TdA, Spanish for.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
1
📢 UK government confirms October cyber breach: Everything we know so far 📢

Details around Foreign Office hack remain sparse and government says it's unclear who is behind the attack.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
📢 Warning issued as surge in OAuth device code phishing leads to M365 account takeovers 📢

Successful attacks enable full M365 account access, opening the door to data theft, lateral movement, and persistent compromise.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
📢 What Palo Alto Networks' $10bn deal with Google Cloud means for customers 📢

The extension of an existing partnership between Palo Alto Networks and Google Cloud is designed to boost security amid rise in AI.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
📢 Amazon CSO Stephen Schmidt says the company has rejected more than 1,800 fake North Korean job applicants in 18 months – but one managed to slip through the net 📢

Analysis from Amazon highlights the growing scale of North Koreanbacked "fake IT worker" campaigns.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
📢 CRINK attacks: which nation state hackers will be the biggest threat in 2026? 📢

The past year has seen a number of attacks performed by China, Russia, Iran and North Korea CRINK.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
🦿 Price Drop: This Complete Ethical Hacking Bundle is Now $33 🦿

Get a comprehensive, potentially lucrative ethical hacking education with 18 courses on today's top tools and tech. This bundle is just 32.97 for a limited time. The post Price Drop This Complete Ethical Hacking Bundle is Now 33 appeared first on TechRepublic.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🖋️ Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens 🖋️

Cybersecurity researchers have disclosed details of a new malicious package on the npm repository that works as a fully functional WhatsApp API, but also contains the ability to intercept every message and link the attacker's device to a victim's WhatsApp account. The package, named "lotusbail," has been downloaded over 56,000 times since it was first uploaded to the registry by a user named ".

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More 🖋️

Cyber threats last week showed how attackers no longer need big hacks to cause big damage. Theyre going after the everyday tools we trust most firewalls, browser addons, and even smart TVs turning small cracks into serious breaches. The real danger now isnt just one major attack, but hundreds of quiet ones using the software and devices already inside our networks. Each trusted system can.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ How to Browse the Web More Sustainably With a Green Browser 🖋️

As the internet becomes an essential part of daily life, its environmental footprint continues to grow.  Data centers, constant connectivity, and resourceheavy browsing habits all contribute to energy consumption and digital waste. While individual users may not see this impact directly, the collective effect of everyday browsing is significant. Choosing a browser designed with.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale 🖋️

Threat actors have been observed leveraging malicious dropper apps masquerading as legitimate applications to deliver an Android SMS stealer dubbed Wonderland in mobile attacks targeting users in Uzbekistan. "Previously, users received 'pure' Trojan APKs that acted as malware immediately upon installation," GroupIB said in an analysis published last week. "Now, adversaries increasingly deploy.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
2
📔 Monitoring Tool Nezha Abused For Stealthy Post-Exploitation Access 📔

Opensource server monitoring tool, Nezha, is being exploited by attackers for remote system control.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 UK: NHS Supplier Confirms Cyber-Attack, Operations Unaffected 📔

DXS International, an official partner of NHS England, said the breach has not affected its operations.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Nefilim Ransomware Affiliate Pleads Guilty 📔

A Ukrainian man has pleaded guilty to charges connecting him to Nefilim ransomware attacks.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Scripted Sparrow Sends Millions of BEC Emails Each Month 📔

Fortra has uncovered a prolific BEC group dubbed Scripted Sparrow spanning three continents and at least five countries.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 86% Surge in Fake Delivery Websites Hits Shoppers During Holiday Rush 📔

NordVPN has warned that malicious postal service websites have surged by 86 over the past month, targeting holiday delivery tracking.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📢 How to MFA everywhere 📢

Identity online is not who you are it is what the system accepts as proof of you, and that gap is exactly what the attackers take advantage of.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
1
📢 Amazon says Russian-backed threat groups were responsible for five-year-long attacks on edge devices – and it shows a ‘clear evolution in tactics’ 📢

Russianbacked hacker groups are exploiting misconfigured edge devices now preferring that tactic over hunting down traditional vulnerabilities to gain access to company networks.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity