Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30158 bookmarks
Custom sorting
Amazon AI coding agent hacked to inject data wiping commands
Amazon AI coding agent hacked to inject data wiping commands
A hacker planted data wiping code in a version of Amazon's generative AI-powered assistant, the Q Developer Extension for Visual Studio Code.
·bleepingcomputer.com·
Amazon AI coding agent hacked to inject data wiping commands
Microsoft investigates outage affecting Microsoft 365 admin center
Microsoft investigates outage affecting Microsoft 365 admin center
Microsoft is investigating an ongoing outage blocking Microsoft 365 administrators with business or enterprise subscriptions from accessing the admin center.
·bleepingcomputer.com·
Microsoft investigates outage affecting Microsoft 365 admin center
Steam games abused to deliver malware once again
Steam games abused to deliver malware once again
A cybercriminal managed to insert malicious files leading to info stealers in a pre-release of a game on the Steam platform
·malwarebytes.com·
Steam games abused to deliver malware once again
The role of the cybersecurity PM in incident-driven development
The role of the cybersecurity PM in incident-driven development
From PowerShell abuse to USB data theft, modern threats hit fast—and hard.vSee how security-minded PMs are responding with real-time controls, smarter policies, and tools like ThreatLocker Patch Management.
·bleepingcomputer.com·
The role of the cybersecurity PM in incident-driven development
« Bonjour, vous êtes chez vous ? », dénoncez ce phishing en 15 secondes chrono
« Bonjour, vous êtes chez vous ? », dénoncez ce phishing en 15 secondes chrono
Depuis plusieurs semaines, une vaste campagne d'arnaque par SMS cible les Français. Le désormais célèbre message « Bonjour, vous êtes chez vous ? » se révèle bien plus sournois qu’il n’y paraît. La bonne nouvelle, c’est que tout le monde peut agir pour s’en protéger. Numerama vous délivre quelques conseils et un
·numerama.com·
« Bonjour, vous êtes chez vous ? », dénoncez ce phishing en 15 secondes chrono
Carp(AI) Diem: Seizing the Unique Moment in History - interos.ai
Carp(AI) Diem: Seizing the Unique Moment in History - interos.ai
Author: Dr. Andrea Little Limbago, SVP, Applied AI  We are at a rare moment in history, one where an industrial revolution, an information revolution, and
·interos.ai·
Carp(AI) Diem: Seizing the Unique Moment in History - interos.ai
Businesses are Unprepared for Next Wave of AI Scams | CSA
Businesses are Unprepared for Next Wave of AI Scams | CSA
Deepfake audio fraud can mimic voices with alarming accuracy. Many organizations are ill-equipped to combat this sophisticated cybercrime.
·cloudsecurityalliance.org·
Businesses are Unprepared for Next Wave of AI Scams | CSA
US sanctions North Korean firm, nationals behind IT worker schemes
US sanctions North Korean firm, nationals behind IT worker schemes
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) has sanctioned three North Korean nationals and a company for supporting fraudulent IT worker schemes that generated illicit revenue for the Democratic People's Republic of Korea (DPRK) government.
·bleepingcomputer.com·
US sanctions North Korean firm, nationals behind IT worker schemes
Arizona woman sentenced to 8.5 years for running North Korean laptop farm
Arizona woman sentenced to 8.5 years for running North Korean laptop farm
Prosecutors said Chapman helped the North Korean IT workers obtain jobs at 309 companies, including a major television network, a car maker, a media company, a Silicon Valley technology company and more.
·therecord.media·
Arizona woman sentenced to 8.5 years for running North Korean laptop farm
« Il reste 24 heures à Naval Group pour me contacter », un hacker menace le géant français de la construction militaire
« Il reste 24 heures à Naval Group pour me contacter », un hacker menace le géant français de la construction militaire
Depuis le 23 juillet 2025, un cybercriminel prétend avoir en sa possession des documents secret défense appartenant à Naval Group. À moins de 24 heures de l'échéance fixée par le corbeau virtuel, le leader européen du naval de défense confirme avoir détecté un potentiel incident, mais précise qu’une enquête est en
·numerama.com·
« Il reste 24 heures à Naval Group pour me contacter », un hacker menace le géant français de la construction militaire
Subliminal Learning in AIs - Schneier on Security
Subliminal Learning in AIs - Schneier on Security
Today’s freaky LLM behavior: We study subliminal learning, a surprising phenomenon where language models learn traits from model-generated data that is semantically unrelated to those traits. For example, a “student” model learns to prefer owls when trained on sequences of numbers generated by a “teacher” model that prefers owls. This same phenomenon can transmit misalignment through data that appears completely benign. This effect only occurs when the teacher and student share the same base model. Interesting security implications. I am more convinced than ever that we need serious research into ...
·schneier.com·
Subliminal Learning in AIs - Schneier on Security
Prolonged Chinese Cyber Espionage Campaign Targets VMware Appliances
Prolonged Chinese Cyber Espionage Campaign Targets VMware Appliances
Sygnia observed Chinese cyber campaign dubbed Fire Ant deploying sophisticated techniques to gain full compromise of victim environments, discovering isolated assets
·infosecurity-magazine.com·
Prolonged Chinese Cyber Espionage Campaign Targets VMware Appliances
Woman gets 8 years for aiding North Koreans infiltrate 300 US firms
Woman gets 8 years for aiding North Koreans infiltrate 300 US firms
Christina Marie Chapman, a 50-year-old woman from Arizona, was sentenced to 102 months in prison after pleading guilty to her involvement in a scheme that enabled North Korean IT workers to infiltrate 309 U.S. companies.
·bleepingcomputer.com·
Woman gets 8 years for aiding North Koreans infiltrate 300 US firms
BlackSuit ransomware gang’s darknet websites seized by police
BlackSuit ransomware gang’s darknet websites seized by police
The BlackSuit gang, which is believed to have been operational since April/May 2023, was a private ransomware group that did not license its tooling to other criminals like ransomware-as-a-service (RaaS) schemes.
·therecord.media·
BlackSuit ransomware gang’s darknet websites seized by police
Overcoming Risks from Chinese GenAI Tool Usage
Overcoming Risks from Chinese GenAI Tool Usage
China-based GenAI tools used by 1,059 employees exposed sensitive enterprise data, raising global compliance concerns.
·thehackernews.com·
Overcoming Risks from Chinese GenAI Tool Usage
Microsoft lifts Windows 11 update block for Easy Anti-Cheat users
Microsoft lifts Windows 11 update block for Easy Anti-Cheat users
Microsoft has removed a compatibility hold that prevented some Easy Anti-Cheat users from installing the Windows 11 2024 Update because of a known issue that triggers restarts with blue screen of death (BSOD) errors.
·bleepingcomputer.com·
Microsoft lifts Windows 11 update block for Easy Anti-Cheat users