Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31237 bookmarks
Custom sorting
China-backed espionage group hits Ivanti customers again | CyberScoop
China-backed espionage group hits Ivanti customers again | CyberScoop
UNC5221 has a knack for exploiting defects in Ivanti products. The group has exploited at least four vulnerabilities in the vendor’s products since 2023, according to Mandiant.
·cyberscoop.com·
China-backed espionage group hits Ivanti customers again | CyberScoop
Texas city warns thousands of utility payment site breach
Texas city warns thousands of utility payment site breach
At least 12,000 people in Texas had sensitive financial information stolen by hackers who secretly implanted malicious code into the utility payment website of the City of Lubbock.
·therecord.media·
Texas city warns thousands of utility payment site breach
One mighty fine-looking report
One mighty fine-looking report
Hazel highlights the key findings within Cisco Talos’ 2024 Year in Review (now available for download) and details our active tracking of an ongoing campaign targeting users in Ukraine with malicious LNK files.
·blog.talosintelligence.com·
One mighty fine-looking report
Microsoft starts testing Windows 11 taskbar icon scaling
Microsoft starts testing Windows 11 taskbar icon scaling
​Microsoft is testing a new taskbar icon scaling feature that automatically scales down Windows taskbar icons to show more apps when it gets too overcrowded.
·bleepingcomputer.com·
Microsoft starts testing Windows 11 taskbar icon scaling
CISA warns of Fast Flux DNS evasion used by cybercrime gangs
CISA warns of Fast Flux DNS evasion used by cybercrime gangs
CISA, the FBI, the NSA, and international cybersecurity agencies are calling on organizations and DNS providers to mitigate the "Fast Flux" cybercrime evasion technique used by state-sponsored threat actors and ransomware gangs.
·bleepingcomputer.com·
CISA warns of Fast Flux DNS evasion used by cybercrime gangs
Ivanti patches Connect Secure zero-day exploited since mid-March
Ivanti patches Connect Secure zero-day exploited since mid-March
Ivanti has released security updates to patch a critical Connect Secure remote code execution vulnerability exploited by a China-linked espionage actor to deploy malware since at least mid-March 2025.
·bleepingcomputer.com·
Ivanti patches Connect Secure zero-day exploited since mid-March
Threat actors leverage tax season to deploy tax-themed phishing campaigns
Threat actors leverage tax season to deploy tax-themed phishing campaigns
As Tax Day approaches in the United States on April 15, Microsoft has detected several tax-themed phishing campaigns employing various tactics. These campaigns use malicious hyperlinks and attachments to deliver credential phishing and malware including RaccoonO365, AHKBot, Latrodectus, BruteRatel C4 (BRc4), and Remcos.
·microsoft.com·
Threat actors leverage tax season to deploy tax-themed phishing campaigns
Objective-See: Blog
Objective-See: Blog
Posts about macOS malware, exploits, and tools
·objective-see.org·
Objective-See: Blog
Objective-See: Blog
Objective-See: Blog
Posts about macOS malware, exploits, and tools
·objective-see.org·
Objective-See: Blog
Oracle privately confirms Cloud breach to customers
Oracle privately confirms Cloud breach to customers
Oracle has finally acknowledged to some customers that attackers have stolen old client credentials after breaching a "legacy environment" last used in 2017.
·bleepingcomputer.com·
Oracle privately confirms Cloud breach to customers
Cisco confirms cyberattacks on Smart Licensing Utility flaw
Cisco confirms cyberattacks on Smart Licensing Utility flaw
CISA earlier this week added CVE-2024-20439, a static credential vulnerability in the Cisco Smart Licensing Utility, to its known exploited vulnerabilities catalog.
·cybersecuritydive.com·
Cisco confirms cyberattacks on Smart Licensing Utility flaw
Major Online Platform for Child Exploitation Dismantled
Major Online Platform for Child Exploitation Dismantled
An international law enforcement operation has shut down Kidflix, a platform for child sexual exploitation with 1.8m registered users
·infosecurity-magazine.com·
Major Online Platform for Child Exploitation Dismantled
Navigating FedRAMP with the Cloud Controls Matrix | CSA
Navigating FedRAMP with the Cloud Controls Matrix | CSA
Recognizing the importance of aligning with new developments, CSA has released a mapping between the Cloud Controls Matrix (CCM) v4.0 and FedRAMP.
·cloudsecurityalliance.org·
Navigating FedRAMP with the Cloud Controls Matrix | CSA