Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30853 bookmarks
Custom sorting
Hackers leak Allianz Life data stolen in Salesforce attacks
Hackers leak Allianz Life data stolen in Salesforce attacks
Hackers have released stolen data belonging to US insurance giant Allianz Life, exposing 2.8 million records with sensitive information on business partners and customers in ongoing Salesforce data theft attacks.
·bleepingcomputer.com·
Hackers leak Allianz Life data stolen in Salesforce attacks
Claude gets 1M tokens support via API to take on Gemini 2.5 Pro
Claude gets 1M tokens support via API to take on Gemini 2.5 Pro
Claude Sonnet 4 has been upgraded, and it can now remember up to 1 million tokens of context, but only when it's used via API. This could change in the future.
·bleepingcomputer.com·
Claude gets 1M tokens support via API to take on Gemini 2.5 Pro
Microsoft Patch Tuesday, August 2025 Edition
Microsoft Patch Tuesday, August 2025 Edition
Microsoft today released updates to fix more than 100 security flaws in its Windows operating systems and other software. At least 13 of the bugs received Microsoft's most-dire "critical" rating, meaning they could be abused by malware or malcontents to…
·krebsonsecurity.com·
Microsoft Patch Tuesday, August 2025 Edition
OpenAI rolls out Gmail, Calendar, and Contacts integration in ChatGPT
OpenAI rolls out Gmail, Calendar, and Contacts integration in ChatGPT
OpenAI wants ChatGPT to know more about you, including your emails, calendar events in Google Calendar and even your Google contacts to reference everything in a conversation.
·bleepingcomputer.com·
OpenAI rolls out Gmail, Calendar, and Contacts integration in ChatGPT
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilities
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2025, which includes 111 vulnerabilities affecting a range of products, including 13 that Microsoft marked as “critical”.   In this month's release, Microsoft observed none of the included vulnerabilities being actively exploited in the wild. Out of 13 "critical" entries, 9 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including the Windows kernel, Microsoft Message Queuing (MSMQ), Win
·blog.talosintelligence.com·
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilities
Malvertising campaign leads to PS1Bot, a multi-stage malware framework
Malvertising campaign leads to PS1Bot, a multi-stage malware framework
Cisco Talos has observed an ongoing malware campaign that seeks to infect victims with a multi-stage malware framework, implemented in PowerShell and C#, which we are referring to as “PS1Bot.”
·blog.talosintelligence.com·
Malvertising campaign leads to PS1Bot, a multi-stage malware framework
Docker Hub still hosts dozens of Linux images with the XZ backdoor
Docker Hub still hosts dozens of Linux images with the XZ backdoor
The XZ-Utils backdoor, first discovered in March 2024, is still present in at least 35 Linux images on Docker Hub, potentially putting users, organizations, and their data at risk.
·bleepingcomputer.com·
Docker Hub still hosts dozens of Linux images with the XZ backdoor
Guess what else GPT-5 is bad at? Security | CyberScoop
Guess what else GPT-5 is bad at? Security | CyberScoop
OpenAI and Microsoft have said that GPT-5 is one of their safest and secure models out of the box yet. An AI red-teamer called its performance “terrible.”
·cyberscoop.com·
Guess what else GPT-5 is bad at? Security | CyberScoop
Dutch NCSC: Citrix NetScaler zero-day breaches critical orgs
Dutch NCSC: Citrix NetScaler zero-day breaches critical orgs
Dutch NCSC warns CVE-2025-6543 Citrix bug, a memory overflow flaw, is being exploited to breach critical organizations in the Netherlands.
·securityaffairs.com·
Dutch NCSC: Citrix NetScaler zero-day breaches critical orgs
Windows 11 KB5063878 & KB5063875 cumulative updates released
Windows 11 KB5063878 & KB5063875 cumulative updates released
Microsoft has released Windows 11 KB5063878 and KB5063875 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues.
·bleepingcomputer.com·
Windows 11 KB5063878 & KB5063875 cumulative updates released
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
Today is Microsoft's August 2025 Patch Tuesday, which includes security updates for 107 flaws, including one publicly disclosed zero-day vulnerability in Windows Kerberos.
·bleepingcomputer.com·
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
Windows 10 KB5063709 update fixes extended security updates enrollment
Windows 10 KB5063709 update fixes extended security updates enrollment
Microsoft has released the KB5063709 cumulative update for Windows 10 22H2 and Windows 10 21H2, with seven fixes or changes, including a fix for a bug that prevented enrollment in extended security updates.
·bleepingcomputer.com·
Windows 10 KB5063709 update fixes extended security updates enrollment
WinRAR vulnerability exploited by two different groups
WinRAR vulnerability exploited by two different groups
Two different groups were found to have abused a now patched vulneraability in popular archive software WinRAR. Who's next?
·malwarebytes.com·
WinRAR vulnerability exploited by two different groups
Hacker Alleges Russian Government Role in Kaseya Cyber-Attack
Hacker Alleges Russian Government Role in Kaseya Cyber-Attack
In a new investigation launched at DEFCON 33, Analyst1’s Jon DiMaggio revealed probable Russian government involvement in the Kaseya attack
·infosecurity-magazine.com·
Hacker Alleges Russian Government Role in Kaseya Cyber-Attack
Android's pKVM hypervisor earns SESIP Level 5 security certification
Android's pKVM hypervisor earns SESIP Level 5 security certification
Google announced that its protected Kernel-based Virtual Machine (pKVM) for Android has achieved SESIP Level 5 certification, the highest security assurance level for IoT and mobile platforms.
·bleepingcomputer.com·
Android's pKVM hypervisor earns SESIP Level 5 security certification
US govt seizes $1 million in crypto from BlackSuit ransomware gang
US govt seizes $1 million in crypto from BlackSuit ransomware gang
The U.S. Department of Justice (DoJ) seized cryptocurrency and digital assets worth $1,091,453 at the time of confiscation, on January 9, 2024, from the BlackSuit ransomware gang.
·bleepingcomputer.com·
US govt seizes $1 million in crypto from BlackSuit ransomware gang
Financial impact from severe OT events could top $300B
Financial impact from severe OT events could top $300B
A report from industrial cybersecurity firm Dragos highlights growing risks of business interruption and supply-chain disruptions.
·cybersecuritydive.com·
Financial impact from severe OT events could top $300B
Quand un avion agricole ukrainien devient un chasseur de drones russes
Quand un avion agricole ukrainien devient un chasseur de drones russes
Pour contrer le déploiement massif de drones envoyés par la Russie, les forces armées ukrainiennes rivalisent d’ingéniosité face à cet ennemi à la fois peu coûteux et redoutable. Début août 2025, un avion agricole modifié a été aperçu dans le ciel ukrainien. Sa nouvelle mission : intercepter les drones ennemis à
·numerama.com·
Quand un avion agricole ukrainien devient un chasseur de drones russes
Scam hunter scammed by tax office impersonators
Scam hunter scammed by tax office impersonators
Scam hunter Julie-Anne Kearns, who helps scam victims online, opened up about a tax scam she fell for herself.
·malwarebytes.com·
Scam hunter scammed by tax office impersonators
29,000 Servers Remain Unpatched Against Microsoft Exchange Flaw
29,000 Servers Remain Unpatched Against Microsoft Exchange Flaw
Over 29,000 Microsoft Exchange servers remain unpatched against a vulnerability that could allow attackers to seize control of entire domains in hybrid cloud environments
·infosecurity-magazine.com·
29,000 Servers Remain Unpatched Against Microsoft Exchange Flaw
Cisco NetScaler flaws lead to critical infrastructure breaches
Cisco NetScaler flaws lead to critical infrastructure breaches
Dutch authorities said hackers penetrated several critical infrastructure providers, in a warning sign for vulnerable organizations elsewhere.
·cybersecuritydive.com·
Cisco NetScaler flaws lead to critical infrastructure breaches