Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30980 bookmarks
Custom sorting
Friday Squid Blogging: Squid-Shaped UFO Spotted Over Texas - Schneier on Security
Friday Squid Blogging: Squid-Shaped UFO Spotted Over Texas - Schneier on Security
Here’s the story. The commenters on X (formerly Twitter) are unimpressed. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
·schneier.com·
Friday Squid Blogging: Squid-Shaped UFO Spotted Over Texas - Schneier on Security
UK telecom provider Colt says outages were due to cyber incident
UK telecom provider Colt says outages were due to cyber incident
The London-based tech and telecom company Colt Technology Services confirmed that a cyberattack earlier this week caused technical issues that it is still addressing.
·therecord.media·
UK telecom provider Colt says outages were due to cyber incident
Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme
Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme
Cybercriminal groups peddling sophisticated phishing kits that convert stolen card data into mobile wallets have recently shifted their focus to targeting customers of brokerage services, new research shows. Undeterred by security controls at these trading platforms that block users from

·krebsonsecurity.com·
Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme
Scammers turn to ‘ghost-tapping’ retail fraud to launder funds
Scammers turn to ‘ghost-tapping’ retail fraud to launder funds
A new report described how criminals use “ghost-tapping” — when stolen payment card details are uploaded onto a burner phone and used in-person to purchase goods.
·therecord.media·
Scammers turn to ‘ghost-tapping’ retail fraud to launder funds
Colt Telecom attack claimed by WarLock ransomware, data up for sale
Colt Telecom attack claimed by WarLock ransomware, data up for sale
UK-based telecommunications company Colt Technology Services is dealing with a cyberattack that has caused a multi-day outage of some of the company's operations, including hosting and porting services, Colt Online and Voice API platforms.
·bleepingcomputer.com·
Colt Telecom attack claimed by WarLock ransomware, data up for sale
Microsoft reminds of Windows 10 support ending in two months
Microsoft reminds of Windows 10 support ending in two months
Microsoft has reminded customers that Windows 10 will be retired in two months after all editions of Windows 10, version 22H2 reach their end of servicing on October 14.
·bleepingcomputer.com·
Microsoft reminds of Windows 10 support ending in two months
Cisco warns of max severity flaw in Firewall Management Center
Cisco warns of max severity flaw in Firewall Management Center
Cisco is warning about a critical remote code execution (RCE) vulnerability in the RADIUS subsystem of its Secure Firewall Management Center (FMC) software.
·bleepingcomputer.com·
Cisco warns of max severity flaw in Firewall Management Center
UAT-7237 targets Taiwanese web hosting infrastructure
UAT-7237 targets Taiwanese web hosting infrastructure
Cisco Talos discovered UAT-7237, a Chinese-speaking advanced persistent threat (APT) group active since at least 2022, which has significant overlaps with UAT-5918.
·blog.talosintelligence.com·
UAT-7237 targets Taiwanese web hosting infrastructure
Zero Trust + AI: Privacy in the Age of Agentic AI
Zero Trust + AI: Privacy in the Age of Agentic AI
Agentic AI shifts privacy from control to trust, challenging laws like GDPR and risking legal exposure.
·thehackernews.com·
Zero Trust + AI: Privacy in the Age of Agentic AI
Plex warns users to patch security vulnerability immediately
Plex warns users to patch security vulnerability immediately
Plex has notified some of its users on Thursday to urgently update their media servers due to a recently patched security vulnerability.
·bleepingcomputer.com·
Plex warns users to patch security vulnerability immediately
Trojans Embedded in .svg Files - Schneier on Security
Trojans Embedded in .svg Files - Schneier on Security
Porn sites are hiding code in .svg files: Unpacking the attack took work because much of the JavaScript in the .svg images was heavily obscured using a custom version of “JSFuck,” a technique that uses only a handful of character types to encode JavaScript into a camouflaged wall of text. Once decoded, the script causes the browser to download a chain of additional obfuscated JavaScript. The final payload, a known malicious script called Trojan.JS.Likejack, induces the browser to like a specified Facebook post as long as a user has their account open...
·schneier.com·
Trojans Embedded in .svg Files - Schneier on Security
Cisco Discloses Critical RCE Flaw in Firewall Management Software
Cisco Discloses Critical RCE Flaw in Firewall Management Software
Cisco has issued a software update to address the vulnerability, which can allow an unauthenticated, remote attacker to inject arbitrary shell commands
·infosecurity-magazine.com·
Cisco Discloses Critical RCE Flaw in Firewall Management Software
Majority of Organizations Ship Vulnerable Code, Study Finds
Majority of Organizations Ship Vulnerable Code, Study Finds
A new Checkmarx study reveals that AI-generated code now accounts for over 60% of codebases in some companies, much of which contains known vulnerabilities
·infosecurity-magazine.com·
Majority of Organizations Ship Vulnerable Code, Study Finds
'Blue Locker' Ransomware Targeting Oil & Gas Sector in Pakistan
'Blue Locker' Ransomware Targeting Oil & Gas Sector in Pakistan
Blue Locker ransomware hits Pakistan’s oil & gas sector, severely impacting Pakistan Petroleum; NCERT warns ministries of severe ongoing risk
·securityaffairs.com·
'Blue Locker' Ransomware Targeting Oil & Gas Sector in Pakistan
Par pitié, cessez de demander nos infos personnelles à la caisse !
Par pitié, cessez de demander nos infos personnelles à la caisse !
C'est une rengaine, devenue presque un passage obligatoire dans de nombreux magasins en France. Au moment de payer, pour profiter d'une remise ou pour créer une carte de fidélité, le client est prié de donner tout un tas de données personnelles. Pourquoi ? Quelles sont les obligations des commerçants ? Et les droits
·numerama.com·
Par pitié, cessez de demander nos infos personnelles à la caisse !
US sanctions Grinex crypto-exchange, Garantex’s successor
US sanctions Grinex crypto-exchange, Garantex’s successor
The U.S. Department of the Treasury has announced sanctions against Grinex, the successor to Russian cryptocurrency exchange Garantex, which was previously sanctioned for helping ransomware gangs launder their money.
·bleepingcomputer.com·
US sanctions Grinex crypto-exchange, Garantex’s successor