Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30615 bookmarks
Custom sorting
The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?
The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?
The Hidden Threat That's Slipping Past Your Security HTTP request smuggling remains one of the most dangerous yet frequently overlooked web vulnerabilities today. Despite being a widely known issue si
·portswigger.net·
The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
Akira ransomware is abusing a legitimate Intel CPU tuning driver to turn off Microsoft Defender in attacks from security tools and EDRs running on target machines.
·bleepingcomputer.com·
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
Black Hat Fireside Chat: Inside the ‘Mind of a Hacker’ — A10’s plan for unified threat detection
Black Hat Fireside Chat: Inside the ‘Mind of a Hacker’ — A10’s plan for unified threat detection
In today's threat landscape, attackers are no longer just exploiting technical flaws — they're exploiting business logic. Think gaps in workflows, permissions, and overlooked assumptions in how applications behave. This subtle shift is creating powerful new footholds for cybercriminals and evading traditional defenses. A10 Networks’ Field CISO Jamison Utter calls this the new front in
·lastwatchdog.com·
Black Hat Fireside Chat: Inside the ‘Mind of a Hacker’ — A10’s plan for unified threat detection
Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge
Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge
Tornado Cash cofounder Roman Storm was found guilty of conspiring to operate an unlicensed money-transmitting business, while the jury failed to reach a ruling on more significant charges around money laundering and sanctions violations.
·therecord.media·
Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge
Trend Micro fixes two actively exploited Apex One RCE flaws
Trend Micro fixes two actively exploited Apex One RCE flaws
Trend Micro patched two critical Apex One flaws (CVE-2025-54948, CVE-2025-54987) exploited in the wild, allowing RCE via console injection.
·securityaffairs.com·
Trend Micro fixes two actively exploited Apex One RCE flaws
New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations
New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations
A new post-exploitation command-and-control (C2) evasion method called 'Ghost Calls' abuses TURN servers used by conferencing apps like Zoom and Microsoft Teams to tunnel traffic through trusted infrastructure.
·bleepingcomputer.com·
New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations
Hacker extradited to US for stealing $3.3 million from taxpayers
Hacker extradited to US for stealing $3.3 million from taxpayers
Nigerian national Chukwuemeka Victor Amachukwu has been extradited from France to the U.S. to face charges of hacking, fraud, and identity theft for suspected spearphishing attacks on U.S. tax preparation businesses.
·bleepingcomputer.com·
Hacker extradited to US for stealing $3.3 million from taxpayers
Top US energy companies frequently exposed to critical security flaws
Top US energy companies frequently exposed to critical security flaws
A report from security firm SixMap shows that a large number of energy companies use equipment with vulnerabilities that are located on potentially exposed ports.
·cybersecuritydive.com·
Top US energy companies frequently exposed to critical security flaws
WhatsApp va désormais vous alerter en cas de message suspect ou d’arnaque
WhatsApp va désormais vous alerter en cas de message suspect ou d’arnaque
Le service de messagerie instantanée Whatsapp a annoncé, le 5 août 2025, la mise en service de nouvelles mesures de sécurité pour lutter contre les arnaques en ligne. L'application affichera notamment des messages de prévention avant que vous n'entamiez une discussion avec un groupe ou un interlocuteur inconnu.
·numerama.com·
WhatsApp va désormais vous alerter en cas de message suspect ou d’arnaque
MFA matters… But it isn’t enough on its own
MFA matters… But it isn’t enough on its own
MFA blocks 99% of attacks—but weak passwords still let attackers in. Specops helps you enforce strong password policies and MFA everywhere, so one layer doesn't undo the other. Book your free trial today.
·bleepingcomputer.com·
MFA matters… But it isn’t enough on its own