Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29804 bookmarks
Custom sorting
GUESST ESSAY: Cybercrime for hire: small businesses are the new bullseye of the Dark Web
GUESST ESSAY: Cybercrime for hire: small businesses are the new bullseye of the Dark Web
Small businesses make up 90% of all companies worldwide and account for half of global GDP. Yet despite their importance, many lack the cybersecurity expertise and resources to fend off a rising tide of digital threats. Related: Protecting lateral networks in SMBs Rich in sensitive data and often connected to larger supply chains, small businesses
·lastwatchdog.com·
GUESST ESSAY: Cybercrime for hire: small businesses are the new bullseye of the Dark Web
Malicious NPM package uses Unicode steganography to evade detection
Malicious NPM package uses Unicode steganography to evade detection
A malicious package in the Node Package Manager index uses invisible Unicode characters to hide malicious code and Google Calendar links to host the URL for the command-and-control location.
·bleepingcomputer.com·
Malicious NPM package uses Unicode steganography to evade detection
Coinbase data breach exposes customer info and government IDs
Coinbase data breach exposes customer info and government IDs
Coinbase, a cryptocurrency exchange with over 100 million customers, has disclosed that cybercriminals working with rogue support agents stole customer data and demanded a $20 million ransom not to publish the stolen information.
·bleepingcomputer.com·
Coinbase data breach exposes customer info and government IDs
Malicious npm package using steganography downloaded by hundreds
Malicious npm package using steganography downloaded by hundreds
A malicious package in the Node Package Manager index uses invisible Unicode characters to hide malicious code and Google Calendar links to host the URL for the command-and-control location.
·bleepingcomputer.com·
Malicious npm package using steganography downloaded by hundreds
8 Questions to Ask Your Security Vendors About AI | CSA
8 Questions to Ask Your Security Vendors About AI | CSA
Learn how to evaluate transparency, risks, scalability, and ethical considerations to make informed cybersecurity decisions about AI-powered tools.
·cloudsecurityalliance.org·
8 Questions to Ask Your Security Vendors About AI | CSA
Overlooked Foundation of Zero Trust | CSA
Overlooked Foundation of Zero Trust | CSA
Zero Trust is only as strong as its foundation. Without Kernel Runtime Integrity, your security stack may be built on compromised ground.
·cloudsecurityalliance.org·
Overlooked Foundation of Zero Trust | CSA
AI-Generated Law - Schneier on Security
AI-Generated Law - Schneier on Security
On April 14, Dubai’s ruler, Sheikh Mohammed bin Rashid Al Maktoum, announced that the United Arab Emirates would begin using artificial intelligence to help write its laws. A new Regulatory Intelligence Office would use the technology to “regularly suggest updates” to the law and “accelerate the issuance of legislation by up to 70%.” AI would create a “comprehensive legislative plan” spanning local and federal law and would be connected to public administration, the courts, and global policy trends. The plan was widely greeted with astonishment. This sort of AI legislating would be a global “...
·schneier.com·
AI-Generated Law - Schneier on Security
5 BCDR Essentials for Effective Ransomware Defense
5 BCDR Essentials for Effective Ransomware Defense
This article discusses the five business continuity and disaster recovery capabilities that businesses must have for effective ransomware defense. Lea
·thehackernews.com·
5 BCDR Essentials for Effective Ransomware Defense
Steam n’a pas été piraté : les SMS qui ont fuité sont vieux
Steam n’a pas été piraté : les SMS qui ont fuité sont vieux
Valve dément ce 15 mai 2025 avoir été victime d'un piratage. Après examen, il ne s'agit pas d'une infiltration dans ses systèmes. Les SMS qui avaient fuité sont d'anciens SMS envoyés aux utilisateurs de Steam. Dans un communiqué publié ce 15 mai 2025, Steam l'assure : le service n'a pas été piraté. Selon son éditeur
·numerama.com·
Steam n’a pas été piraté : les SMS qui ont fuité sont vieux
Google fixes high severity Chrome flaw with public exploit
Google fixes high severity Chrome flaw with public exploit
Google has released emergency security updates to patch a high-severity Chrome vulnerability that has a public exploit and can let attackers hijack accounts.
·bleepingcomputer.com·
Google fixes high severity Chrome flaw with public exploit