Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31225 bookmarks
Custom sorting
Google fixed two actively exploited Android zero-days
Google fixed two actively exploited Android zero-days
Google addressed 62 vulnerabilities with the release of Android 's April 2025 security update, including two actively exploited zero-days.
·securityaffairs.com·
Google fixed two actively exploited Android zero-days
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
jQuery 3.3.1 - Prototype Pollution & XSS Exploit. CVE-2020-7656CVE-2019-11358 . webapps exploit for Multiple platform
·exploit-db.com·
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research.
·bleepingcomputer.com·
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
Microsoft delays WSUS driver sync deprecation indefinitely
Microsoft delays WSUS driver sync deprecation indefinitely
Microsoft announced today that, based on customer feedback, it will indefinitely delay removing driver synchronization in Windows Server Update Services (WSUS).
·bleepingcomputer.com·
Microsoft delays WSUS driver sync deprecation indefinitely
Six arrested for AI-powered investment scams that stole $20 million
Six arrested for AI-powered investment scams that stole $20 million
Spain's police arrested six individuals behind a large-scale cryptocurrency investment scam that used AI tools to generate deepfake ads featuring popular public figures to lure people.
·bleepingcomputer.com·
Six arrested for AI-powered investment scams that stole $20 million
Malicious VSCode extensions infect Windows with cryptominers
Malicious VSCode extensions infect Windows with cryptominers
Nine VSCode extensions on Microsoft's Visual Studio Code Marketplace pose as legitimate development tools while infecting users with the XMRig cryptominer to mine Ethereum and Monero.
·bleepingcomputer.com·
Malicious VSCode extensions infect Windows with cryptominers
Tech Accelerator: Azure security and AI adoption
Tech Accelerator: Azure security and AI adoption
Are you looking for guidance on how to effectively integrate security best practices within your Azure and AI projects? We know the pace of technological innovation offers as many opportunities as it does challenges. However, security cannot be an afterthought as you create Azure deployments and accelerate AI solutions.   That’s why we’re inviting you to attend Tech Accelerator: Azure Security and AI Adoption on April 22. Designed for developers and cloud architects, this one-day virtual event will equip you with the essential guidance and resources you need to securely plan, build, manage, and optimize your Azure deployments and AI projects.  Why should you attend?  During this event, you will learn how to leverage Microsoft security guidance, products, and tooling throughout your cloud journey - from the time you consider Azure to the point that you’re regularly managing and optimizing workloads. Discover how Microsoft protects its platform, how to identify security risks in your Azure environments, protect your infrastructure from security threats, design secure AI environments, and build and protect your AI applications.  What can you expect?  During this event, you'll have the opportunity to:  Learn from the experts: Get in-depth technical guidance from Microsoft experts to secure your Azure deployments and AI applications.  Engage with the community: Connect with fellow developers, cloud architects, and IT professionals.  Event details  Dates: April 22, 2025  Duration: 8:00-11:30 AM Pacific Time   Format: One keynote + six 25-minute sessions with technical guidance and demos  April 22, 2025:   Session  Time  Security: An essential part of your Azure and AI journey (keynote)  8:00 AM PT  Secure by design: Azure datacenter and hardware security  8:30 AM PT  Azure platform security: Embedded features and use cases  9:00 AM PT  Enhancing security for cloud migration  9:30 AM PT  How to secure your AI environment  10:00 AM PT  How to design and build secure AI projects  10:30 AM PT  Safeguard AI applications with Microsoft Defender for Cloud  11:00 AM PT    All sessions will be streamed live on the Microsoft Tech Community platform with live Q&A during the event with the speakers and subject experts. Q&A will close at 12:00 PM PT on Friday, April 25, 2025. Sessions will be available on demand immediately, so you can watch at your convenience.   Registration is not required. On each session page, you can find an Add to calendar link. Click the Attend button on the page to receive reminders. Please post questions early and often; we're here to help!  Please save the date and join us: https://aka.ms/AzureEssentialsEvent 
·techcommunity.microsoft.com·
Tech Accelerator: Azure security and AI adoption