Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29910 bookmarks
Custom sorting
HPE warns of hardcoded passwords in Aruba access points
HPE warns of hardcoded passwords in Aruba access points
Hewlett-Packard Enterprise (HPE) is warning of hardcoded credentials in Aruba Instant On Access Points that allow attackers to bypass normal device authentication and access the web interface.
·bleepingcomputer.com·
HPE warns of hardcoded passwords in Aruba access points
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, has been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide.
·bleepingcomputer.com·
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack
Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack
A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick users into approving login authentication requests from fake company portals.
·bleepingcomputer.com·
Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack
Popular npm linter packages hijacked via phishing to drop malware
Popular npm linter packages hijacked via phishing to drop malware
Popular JavaScript libraries eslint-config-prettier and eslint-plugin-prettier were hijacked this week and turned into malware droppers, in a supply chain attack achieved via targeted phishing and credential theft.
·bleepingcomputer.com·
Popular npm linter packages hijacked via phishing to drop malware
Sous les bombes à Kiev avec les cyberdéfenseurs ukrainiens : « Le réseau dépendait de nous »
Sous les bombes à Kiev avec les cyberdéfenseurs ukrainiens : « Le réseau dépendait de nous »
L’un a vécu deux mois surréalistes dans un data center assiégé. L’autre se réveille la nuit pour combattre les hackers russes. Numerama s’est rendu en Ukraine pour rapporter les histoires de Kostya et Dmytro, haut commandants dans le privé de la cyberdéfence du pays. « Vybachte, odyn moment. » Excusez-moi, un
·numerama.com·
Sous les bombes à Kiev avec les cyberdéfenseurs ukrainiens : « Le réseau dépendait de nous »
New CrushFTP zero-day exploited in attacks to hijack servers
New CrushFTP zero-day exploited in attacks to hijack servers
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers.
·bleepingcomputer.com·
New CrushFTP zero-day exploited in attacks to hijack servers
CrushFTP zero-day exploited in attacks to gain admin access on servers
CrushFTP zero-day exploited in attacks to gain admin access on servers
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers.
·bleepingcomputer.com·
CrushFTP zero-day exploited in attacks to gain admin access on servers
CrushFTP zero-day exploited in attacks to gain admin access on servers
CrushFTP zero-day exploited in attacks to gain admin access on servers
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers.
·bleepingcomputer.com·
CrushFTP zero-day exploited in attacks to gain admin access on servers
Friday Squid Blogging: The Giant Squid Nebula - Schneier on Security
Friday Squid Blogging: The Giant Squid Nebula - Schneier on Security
Beautiful photo. Difficult to capture, this mysterious, squid-shaped interstellar cloud spans nearly three full moons in planet Earth’s sky. Discovered in 2011 by French astro-imager Nicolas Outters, the Squid Nebula’s bipolar shape is distinguished here by the telltale blue emission from doubly ionized oxygen atoms. Though apparently surrounded by the reddish hydrogen emission region Sh2-129, the true distance and nature of the Squid Nebula have been difficult to determine. Still, one investigation suggests Ou4 really does lie within Sh2-129 some 2,300 light-years away. Consistent with that scenario, the cosmic squid would represent a spectacular outflow of material driven by a ...
·schneier.com·
Friday Squid Blogging: The Giant Squid Nebula - Schneier on Security
Arch Linux pulls AUR packages that installed Chaos RAT malware
Arch Linux pulls AUR packages that installed Chaos RAT malware
Arch Linux has pulled three malicious packages uploaded to the Arch User Repository (AUR) were used to install the CHAOS remote access trojan (RAT) on Linux devices.
·bleepingcomputer.com·
Arch Linux pulls AUR packages that installed Chaos RAT malware
UK ties GRU to stealthy Microsoft 365 credential-stealing malware
UK ties GRU to stealthy Microsoft 365 credential-stealing malware
The UK National Cyber Security Centre (NCSC) has formally attributed 'Authentic Antics' espionage malware attacks to APT28 (Fancy Bear), threat actor already linked to Russia's military intelligence service (GRU).
·bleepingcomputer.com·
UK ties GRU to stealthy Microsoft 365 credential-stealing malware
New ChatGPT o3-alpha model hints at coding upgrade
New ChatGPT o3-alpha model hints at coding upgrade
ChatGPT's o3 is OpenAI's best model to date because it features reasoning, and it might get even better in the next update.
·bleepingcomputer.com·
New ChatGPT o3-alpha model hints at coding upgrade
Russian alcohol retailer WineLab closes stores after ransomware attack
Russian alcohol retailer WineLab closes stores after ransomware attack
WineLab, the retail store of the largest alcohol company in Russia, has closed its stores following a cyberattack that is impacting its operations and causing purchase problems to its customers.
·bleepingcomputer.com·
Russian alcohol retailer WineLab closes stores after ransomware attack