Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29804 bookmarks
Custom sorting
Famous Chollima deploying Python version of GolangGhost RAT
Famous Chollima deploying Python version of GolangGhost RAT
Learn how the North Korean-aligned Famous Chollima is using the a new Python-based RAT, "PylangGhost," to target cryptocurrency and blockchain jobseekers in a campaign affecting users primarily in India.
·blog.talosintelligence.com·
Famous Chollima deploying Python version of GolangGhost RAT
When legitimate tools go rogue
When legitimate tools go rogue
Attackers are increasingly hiding in plain sight, using the same tools IT and security teams rely on for daily operations. This blog breaks down common techniques and provides recommendations to defenders.
·blog.talosintelligence.com·
When legitimate tools go rogue
Scoping Your ISMS for ISO 27001 Success | CSA
Scoping Your ISMS for ISO 27001 Success | CSA
Learn how to define the right ISMS scope for ISO 27001 certification by understanding clauses 4.1–4.3 and aligning with business needs and risks.
·cloudsecurityalliance.org·
Scoping Your ISMS for ISO 27001 Success | CSA
Cyberattaque massive sur Taïwan : HoldingHands menace la sécurité nationale
Cyberattaque massive sur Taïwan : HoldingHands menace la sécurité nationale
Des chercheurs en cybersécurité révèlent que Taïwan subit depuis janvier 2025 une offensive numérique d’ampleur inédite, orchestrée par le groupe HoldingHands. Cette opération d’espionnage et de sabotage cible sans relâche les administrations, entreprises et infrastructures stratégiques de l’île. C'est une attaque
·numerama.com·
Cyberattaque massive sur Taïwan : HoldingHands menace la sécurité nationale
UK Government Publishes Plan to Boost Cyber Sector Growth
UK Government Publishes Plan to Boost Cyber Sector Growth
The new Cyber Growth Action Plan aims to support the UK’s cyber industry, including the development of innovative new technologies and startups
·infosecurity-magazine.com·
UK Government Publishes Plan to Boost Cyber Sector Growth
FedRAMP at Startup Speed: Lessons Learned
FedRAMP at Startup Speed: Lessons Learned
Startups can now achieve FedRAMP Moderate faster. Beyond Identity shares real strategies, costs, and team insights.
·thehackernews.com·
FedRAMP at Startup Speed: Lessons Learned
Ransomware Group Qilin Offers Legal Counsel to Affiliates
Ransomware Group Qilin Offers Legal Counsel to Affiliates
The group positions itself “not just as a ransomware group, but as a full-service cybercrime platform”, according to Cybereason
·infosecurity-magazine.com·
Ransomware Group Qilin Offers Legal Counsel to Affiliates
5 riskiest places to get scammed online
5 riskiest places to get scammed online
These 5 communication channels are favored by scammers to try and trick victims at least once a week—if not more.
·malwarebytes.com·
5 riskiest places to get scammed online
BeyondTrust warns of pre-auth RCE in Remote Support software
BeyondTrust warns of pre-auth RCE in Remote Support software
BeyondTrust has released security updates to fix a high-severity flaw in its Remote Support (RS) and Privileged Remote Access (PRA) solutions that can let unauthenticated attackers gain remote code execution on vulnerable servers.
·bleepingcomputer.com·
BeyondTrust warns of pre-auth RCE in Remote Support software
Lay a Cybersecurity Foundation and Master CIS Controls IG1
Lay a Cybersecurity Foundation and Master CIS Controls IG1
Today’s digital threats don’t discriminate by size or sector. Building a solid cybersecurity foundation is no longer optional—it’s essential.
·cisecurity.org·
Lay a Cybersecurity Foundation and Master CIS Controls IG1
Asana warns MCP AI feature exposed customer data to other orgs
Asana warns MCP AI feature exposed customer data to other orgs
Work management platform Asana is warning users of its new Model Context Protocol (MCP) feature that a flaw in its implementation potentially led to data exposure from their instances to other users and vice versa.
·bleepingcomputer.com·
Asana warns MCP AI feature exposed customer data to other orgs
MY TAKE: Microsoft owns AI jailbreak risk — Google, Meta, Amazon, OpenAI look the other way
MY TAKE: Microsoft owns AI jailbreak risk — Google, Meta, Amazon, OpenAI look the other way
Last week at Microsoft Build, Azure CTO Mark Russinovich made headlines by telling the truth. Related: A basis for AI optimism In a rare moment of public candor from a Big Tech executive, Russinovich warned that current AI architectures—particularly autoregressive transformers—have structural limitations we won’t engineer our way past. And more than that, he acknowledged
·lastwatchdog.com·
MY TAKE: Microsoft owns AI jailbreak risk — Google, Meta, Amazon, OpenAI look the other way
WhatsApp to start targeting you with ads
WhatsApp to start targeting you with ads
WhatsApp has announced it will start showing its users targeted ads. Will this be yet another Meta "Pay or OK" choice?
·malwarebytes.com·
WhatsApp to start targeting you with ads
Scattered Spider hackers targeting insurance industry following retail hits, Google warns
Scattered Spider hackers targeting insurance industry following retail hits, Google warns
Security analysts at Google’s Threat Intelligence Group published a warning this week to insurance companies, writing that it is “now aware of multiple intrusions in the US which bear all the hallmarks of Scattered Spider activity.”
·therecord.media·
Scattered Spider hackers targeting insurance industry following retail hits, Google warns
Pro-Cambodian hacktivists launch attacks on Thai government sites amid border dispute
Pro-Cambodian hacktivists launch attacks on Thai government sites amid border dispute
The AnonsecKh group, which goes by Bl4ckCyb3r on Telegram, claimed at least 73 attacks on Thai organizations in the two weeks following a May 28 incident in which a Cambodian soldier was killed in a skirmish with Thai forces.
·therecord.media·
Pro-Cambodian hacktivists launch attacks on Thai government sites amid border dispute