Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31333 bookmarks
Custom sorting
Google to verify all Android devs to block malware on Google Play
Google to verify all Android devs to block malware on Google Play
Google is introducing a new defense for Android called 'Developer Verification' to block malware installations from sideloaded apps sourced from outside the official Google Play app store.
·bleepingcomputer.com·
Google to verify all Android devs to block malware on Google Play
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks
Citrix fixed three NetScaler ADC and NetScaler Gateway flaws today, including a critical remote code execution flaw tracked as CVE-2025-7775 that was actively exploited in attacks as a zero-day vulnerability.
·bleepingcomputer.com·
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks
DOGE employees uploaded Social Security database to ‘vulnerable’ cloud, agency whistleblower says | FedScoop
DOGE employees uploaded Social Security database to ‘vulnerable’ cloud, agency whistleblower says | FedScoop
Department of Government Efficiency members stored a copy of a massive Social Security Administration database in a “vulnerable” custom cloud environment, putting more than 300 million people’s personal information at risk, the agency’s chief data officer said in a new whistleblower complaint.
·fedscoop.com·
DOGE employees uploaded Social Security database to ‘vulnerable’ cloud, agency whistleblower says | FedScoop
Governments, tech companies meet in Tokyo to share tips on fighting North Korea IT worker scheme
Governments, tech companies meet in Tokyo to share tips on fighting North Korea IT worker scheme
The U.S. State Department said it worked with the Ministries of Foreign Affairs in Japan and South Korea to organize the forum, which had more than 130 attendees from freelance work platforms, payment service providers, cryptocurrency companies, AI firms and more.
·therecord.media·
Governments, tech companies meet in Tokyo to share tips on fighting North Korea IT worker scheme
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens from its Drift chat agent integration with Salesforce to pivot to customer environments and exfiltrate data. The ShinyHunters extortion group claims responsibility for these additional Salesforce attacks.
·bleepingcomputer.com·
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
Court ruling in Epic-Google fight could have ‘catastrophic’ cyber consequences, former gov’t officials say | CyberScoop
Court ruling in Epic-Google fight could have ‘catastrophic’ cyber consequences, former gov’t officials say | CyberScoop
A court injunction in the long fight between Fortnite publisher Epic Games and Google could have “catastrophic results for the nation’s security” and “risks creating massive cybersecurity vulnerabilities in the online ecosystem,” a group of former top government officials said in a filing Monday.
·cyberscoop.com·
Court ruling in Epic-Google fight could have ‘catastrophic’ cyber consequences, former gov’t officials say | CyberScoop
Nevada closes state offices as cyberattack disrupts IT systems
Nevada closes state offices as cyberattack disrupts IT systems
Nevada remains two days into a cyberattack that began early Sunday, disrupting government websites, phone systems, and online platforms, and forcing all state offices to close on Monday.
·bleepingcomputer.com·
Nevada closes state offices as cyberattack disrupts IT systems
Coup de pression sur la Silicon Valley : l'Amérique l'appelle à repousser les assauts de l’Europe contre le chiffrement - Numerama
Coup de pression sur la Silicon Valley : l'Amérique l'appelle à repousser les assauts de l’Europe contre le chiffrement - Numerama
Les géants de la tech doivent résister aux demandes visant à affaiblir le chiffrement. Voilà le rappel que vient de faire une autorité américaine aux grandes entreprises de la Silicon Valley, en nommant spécifiquement certaines législations récentes en Europe. Motif ? Cela pourrait nuire aux droits des Américains.
·numerama.com·
Coup de pression sur la Silicon Valley : l'Amérique l'appelle à repousser les assauts de l’Europe contre le chiffrement - Numerama
Quand une immense opération cybercriminelle cible Jungkook, leader du groupe de K-Pop BTS
Quand une immense opération cybercriminelle cible Jungkook, leader du groupe de K-Pop BTS
Les autorités sud-coréennes ont annoncé avoir procédé à l'extradition d'un ressortissant chinois basé en Thaïlande. L'homme de 34 ans sera jugé pour avoir commandité une vaste campagne de hacking financier. Ses cibles de prédilections ? Des célébrités sud-coréennes, dont le leader du groupe de k-pop BTS, Jungkook.
·numerama.com·
Quand une immense opération cybercriminelle cible Jungkook, leader du groupe de K-Pop BTS
CISA warns of actively exploited Git code execution flaw
CISA warns of actively exploited Git code execution flaw
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning of hackers exploiting an arbitrary code execution flaw in the Git distributed version control system.
·bleepingcomputer.com·
CISA warns of actively exploited Git code execution flaw
DSLRoot, Proxies, and the Threat of ‘Legal Botnets’
DSLRoot, Proxies, and the Threat of ‘Legal Botnets’
The cybersecurity community on Reddit responded in disbelief this month when a self-described Air National Guard member with top secret security clearance began questioning the arrangement they'd made with company called DSLRoot, which was paying $250 a month to plug…
·krebsonsecurity.com·
DSLRoot, Proxies, and the Threat of ‘Legal Botnets’