Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29910 bookmarks
Custom sorting
UK Romance Scams Spike 20% as Online Dating Grows
UK Romance Scams Spike 20% as Online Dating Grows
Barclays found that romance scam victims lost £8000 on average in 2024, a significant increase from the previous year
·infosecurity-magazine.com·
UK Romance Scams Spike 20% as Online Dating Grows
Microsoft fixes Windows Server 2025 blue screen, install issues
Microsoft fixes Windows Server 2025 blue screen, install issues
Microsoft has fixed several known issues that caused Blue Screen of Death (BSOD) and installation issues on Windows Server 2025 systems with a high core count.
·bleepingcomputer.com·
Microsoft fixes Windows Server 2025 blue screen, install issues
Hackers abuse Zoom remote control feature for crypto-theft attacks
Hackers abuse Zoom remote control feature for crypto-theft attacks
A hacking group dubbed 'Elusive Comet' targets cryptocurrency users in social engineering attacks that exploit Zoom's remote control feature to trick users into granting them access to their machines.
·bleepingcomputer.com·
Hackers abuse Zoom remote control feature for crypto-theft attacks
Windows 10 KB5055612 preview update fixes a GPU bug in WSL2
Windows 10 KB5055612 preview update fixes a GPU bug in WSL2
Microsoft has released the optional KB5055612 preview cumulative update for Windows 10 22H2 with two changes, including a fix for a GPU paravirtualization bug in Windows Subsystem for Linux 2 (WSL2).
·bleepingcomputer.com·
Windows 10 KB5055612 preview update fixes a GPU bug in WSL2
SK Telecom warns customer USIM data exposed in malware attack
SK Telecom warns customer USIM data exposed in malware attack
South Korea's largest mobile operator, SK Telecom, is warning that a malware infection allowed threat actors to access sensitive USIM-related information for customers.
·bleepingcomputer.com·
SK Telecom warns customer USIM data exposed in malware attack
Marks & Spencer touché par une cyberattaque, plusieurs services fortement perturbés
Marks & Spencer touché par une cyberattaque, plusieurs services fortement perturbés
La célèbre chaîne de magasins britannique a confirmé gérer un “cyberincident”, créant d'importantes perturbations de paiement et sur les délais...-Cybersécurité
·usine-digitale.fr·
Marks & Spencer touché par une cyberattaque, plusieurs services fortement perturbés
Ripple’s recommended XRP library xrpl.js hacked to steal wallets
Ripple’s recommended XRP library xrpl.js hacked to steal wallets
The recommended Ripple cryptocurrency NPM JavaScript library named "xrpl.js" was compromised to steal XRP wallet seeds and private keys and transfer them to an attacker-controlled server, allowing threat actors to steal all the funds stored in the wallets.
·bleepingcomputer.com·
Ripple’s recommended XRP library xrpl.js hacked to steal wallets
Android Improves Its Security - Schneier on Security
Android Improves Its Security - Schneier on Security
Android phones will soon reboot themselves after sitting idle for three days. iPhones have had this feature for a while; it’s nice to see Google add it to their phones.
·schneier.com·
Android Improves Its Security - Schneier on Security
SuperCard X Enables Contactless ATM Fraud in Real-Time
SuperCard X Enables Contactless ATM Fraud in Real-Time
A new malware campaign utilizing NFC-relay techniques has been identified carrying out unauthorized transactions through POS systems and ATMs
·infosecurity-magazine.com·
SuperCard X Enables Contactless ATM Fraud in Real-Time
Cookie-Bite attack PoC uses Chrome extension to steal session tokens
Cookie-Bite attack PoC uses Chrome extension to steal session tokens
A proof-of-concept attack called "Cookie-Bite" uses a browser extension to steal browser session cookies from Azure Entra ID to bypass multi-factor authentication (MFA) protections and maintain access to cloud services like Microsoft 365, Outlook, and Teams.
·bleepingcomputer.com·
Cookie-Bite attack PoC uses Chrome extension to steal session tokens
WordPress Core 6.2 - Directory Traversal
WordPress Core 6.2 - Directory Traversal
WordPress Core 6.2 - Directory Traversal. CVE-2023-2745 . webapps exploit for PHP platform
·exploit-db.com·
WordPress Core 6.2 - Directory Traversal
Implementing CCM: Data Protection and Privacy Controls | CSA
Implementing CCM: Data Protection and Privacy Controls | CSA
The Data Security and Privacy domain of the Cloud Controls Matrix addresses critical areas of the data lifecycle, like data classification and data disposal.
·cloudsecurityalliance.org·
Implementing CCM: Data Protection and Privacy Controls | CSA