Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31742 bookmarks
Custom sorting
CIS Benchmarks March 2025 Update
CIS Benchmarks March 2025 Update
Here is an overview of the CIS Benchmarks that the Center for Internet Security (CIS) updated or released for March 2025.
·cisecurity.org·
CIS Benchmarks March 2025 Update
News alert: GitGuardian discloses 70% of leaked secrets remain active 2 years — remediation urgent - The Last Watchdog
News alert: GitGuardian discloses 70% of leaked secrets remain active 2 years — remediation urgent - The Last Watchdog
Boston, Mass., Mar. 11, 2025, CyberNewswire -- GitGuardian, the security leader behind GitHub's most installed application, today released its comprehensive "2025 State of Secrets Sprawl Report," revealing a widespread and persistent security crisis that threatens organizations of all sizes. The report exposes a 25% increase in leaked secrets year-over-year, with 23.8 million new credentials detected
·lastwatchdog.com·
News alert: GitGuardian discloses 70% of leaked secrets remain active 2 years — remediation urgent - The Last Watchdog
Windows 10 KB5053606 update fixes broken SSH connections
Windows 10 KB5053606 update fixes broken SSH connections
Microsoft has released the KB5053606 cumulative update for Windows 10 22H2 and Windows 10 21H2, which fixes numerous bugs, including one preventing SSH connections.
·bleepingcomputer.com·
Windows 10 KB5053606 update fixes broken SSH connections
Windows 11 KB5053598 & KB5053602 cumulative updates released
Windows 11 KB5053598 & KB5053602 cumulative updates released
Microsoft has released Windows 11 KB5053598 and KB5053602  cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues.
·bleepingcomputer.com·
Windows 11 KB5053598 & KB5053602 cumulative updates released
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
Today is Microsoft's March 2025 Patch Tuesday, which includes security updates for 57 flaws, including six actively exploited zero-day vulnerabilities.
·bleepingcomputer.com·
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
Silk Typhoon Hackers Indicted - Schneier on Security
Silk Typhoon Hackers Indicted - Schneier on Security
Lots of interesting details in the story: The US Department of Justice on Wednesday announced the indictment of 12 Chinese individuals accused of more than a decade of hacker intrusions around the world, including eight staffers for the contractor i-Soon, two officials at China’s Ministry of Public Security who allegedly worked with them, and two other alleged hackers who are said to be part of the Chinese hacker group APT27, or Silk Typhoon, which prosecutors say was involved in the US Treasury breach late last year. […] According to prosecutors, the group as a whole has targeted US state and federal agencies, foreign ministries of countries across Asia, Chinese dissidents, US-based media outlets that have criticized the Chinese government, and most recently the US Treasury, which was breached between September and December of last year. An internal Treasury report ...
·schneier.com·
Silk Typhoon Hackers Indicted - Schneier on Security
Microsoft replacing Remote Desktop app with Windows App in May
Microsoft replacing Remote Desktop app with Windows App in May
Microsoft announced that it will drop support for the Remote Desktop app (available via the Microsoft Store) on May 27 and replace it with its new Windows App.
·bleepingcomputer.com·
Microsoft replacing Remote Desktop app with Windows App in May
New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects
New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects
Microsoft Threat Intelligence has uncovered a new variant of XCSSET, a sophisticated modular macOS malware that infects Xcode projects, in the wild. Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies. These enhanced features help this malware family steal and exfiltrate files and system and user information, such as digital wallet data and notes, among others.
·microsoft.com·
New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects
Trump nominates Plankey to lead CISA
Trump nominates Plankey to lead CISA
Plankey previously held key roles at the Department of Energy and National Security Council during the first Trump administration.
·cybersecuritydive.com·
Trump nominates Plankey to lead CISA
MassJacker malware uses 778,000 wallets to steal cryptocurrency
MassJacker malware uses 778,000 wallets to steal cryptocurrency
A newly discovered clipboard hijacking operation dubbed 'MassJacker' uses at least 778,531 cryptocurrency wallet addresses to steal digital assets from compromised computers.
·bleepingcomputer.com·
MassJacker malware uses 778,000 wallets to steal cryptocurrency
Critical PHP RCE vulnerability mass exploited in new attacks
Critical PHP RCE vulnerability mass exploited in new attacks
Threat intelligence company GreyNoise warns that a critical PHP remote code execution vulnerability that impacts Windows systems is now under mass exploitation.
·bleepingcomputer.com·
Critical PHP RCE vulnerability mass exploited in new attacks
The AI race: Dark AI is in the lead, but good AI is catching up
The AI race: Dark AI is in the lead, but good AI is catching up
Cybercriminals are using AI for help in planning and conducting cyberattacks—but cybersecurity vendors are fighting back. Learn from Acronis Threat Research Unit about how AI-powered security solutions are closing the gap in the battle against AI-driven cyber threats.
·bleepingcomputer.com·
The AI race: Dark AI is in the lead, but good AI is catching up