Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31742 bookmarks
Custom sorting
Exploits and vulnerabilities in Q4 2024
Exploits and vulnerabilities in Q4 2024
This report provides statistics on vulnerabilities and exploits and discusses the most frequently exploited vulnerabilities in Q4 2024.
·securelist.com·
Exploits and vulnerabilities in Q4 2024
GUEST ESSAY: How AI co-pilots boost the risk of data leakage — making ‘least privilege’ a must - The Last Watchdog
GUEST ESSAY: How AI co-pilots boost the risk of data leakage — making ‘least privilege’ a must - The Last Watchdog
The rise of AI co-pilots is exposing a critical security gap: sensitive data sprawl and excessive access permissions. Related: Weaponizing Microsoft's co-pilot Until now, lackluster enterprise search capabilities kept many security risks in check—employees simply couldn’t find much of the data they were authorized to access. But Microsoft Copilot changes the game, turbocharging enterprise search
·lastwatchdog.com·
GUEST ESSAY: How AI co-pilots boost the risk of data leakage — making ‘least privilege’ a must - The Last Watchdog
Windows 11 KB5052093 update released with 33 changes and fixes
Windows 11 KB5052093 update released with 33 changes and fixes
Microsoft has released the February 2025 preview cumulative update for Windows 11 24H2, with 33 improvements and fixes for multiple issues, including SSH and File Explorer bugs and the volume jumping to 100% when waking the PC from sleep.
·bleepingcomputer.com·
Windows 11 KB5052093 update released with 33 changes and fixes
Windows 11 24H2 upgrades now blocked for some AutoCAD users
Windows 11 24H2 upgrades now blocked for some AutoCAD users
Microsoft has introduced a new Windows 11 24H2 upgrade block for systems with AutoCAD 2022, addressing compatibility issues that prevent the program from launching.
·bleepingcomputer.com·
Windows 11 24H2 upgrades now blocked for some AutoCAD users
Have I Been Pwned adds 284M accounts stolen by infostealer malware
Have I Been Pwned adds 284M accounts stolen by infostealer malware
​The Have I Been Pwned data breach notification service has added over 284 million accounts stolen by information stealer malware and found on a Telegram channel.
·bleepingcomputer.com·
Have I Been Pwned adds 284M accounts stolen by infostealer malware
GitVenom attacks abuse hundreds of GitHub repos to steal crypto
GitVenom attacks abuse hundreds of GitHub repos to steal crypto
A malware campaign dubbed GitVenom uses hundreds of GitHub repositories to trick users into downloading info-stealers, remote access trojans (RATs), and clipboard hijackers to steal crypto and credentials.
·bleepingcomputer.com·
GitVenom attacks abuse hundreds of GitHub repos to steal crypto
Windows 10 KB5052077 update fixes broken SSH connections
Windows 10 KB5052077 update fixes broken SSH connections
​​Microsoft has released the optional KB5052077 preview cumulative update for Windows 10 22H2 with nine bug fixes and changes, including a fix for a longstanding known issue that breaks SSH connections.
·bleepingcomputer.com·
Windows 10 KB5052077 update fixes broken SSH connections
News alert: INE secures spot in G2’s 2025 Top 50 education software rankings - The Last Watchdog
News alert: INE secures spot in G2’s 2025 Top 50 education software rankings - The Last Watchdog
Cary, NC, Feb. 25, 2025, CyberNewswire -- INE, the leading provider of networking and cybersecurity training and certifications, today announced its recognition as an enterprise and small business leader in online course providers and cybersecurity professional development, along with its designation as the recipient of G2’s 2025 Best Software Awards for Education Products. This category
·lastwatchdog.com·
News alert: INE secures spot in G2’s 2025 Top 50 education software rankings - The Last Watchdog
New Auto-Color Linux backdoor targets North American govts, universities
New Auto-Color Linux backdoor targets North American govts, universities
A previously undocumented Linux backdoor dubbed 'Auto-Color' was observed in attacks between November and December 2024, targeting universities and government organizations in North America and Asia.
·bleepingcomputer.com·
New Auto-Color Linux backdoor targets North American govts, universities
North Korean Hackers Steal $1.5B in Cryptocurrency - Schneier on Security
North Korean Hackers Steal $1.5B in Cryptocurrency - Schneier on Security
It looks like a very sophisticated attack against the Dubai-based exchange Bybit: Bybit officials disclosed the theft of more than 400,000 ethereum and staked ethereum coins just hours after it occurred. The notification said the digital loot had been stored in a “Multisig Cold Wallet” when, somehow, it was transferred to one of the exchange’s hot wallets. From there, the cryptocurrency was transferred out of Bybit altogether and into wallets controlled by the unknown attackers. […] …a subsequent investigation by Safe found no signs of unauthorized access to its infrastructure, no compromises of other Safe wallets, and no obvious vulnerabilities in the Safe codebase. As investigators continued to dig in, they finally settled on the true cause. Bybit ultimately said that the fraudulent transaction was “manipulated by a sophisticated attack that altered the smart contract logic and masked the signing interface, enabling the attacker to gain control of the ETH Cold Wallet.”...
·schneier.com·
North Korean Hackers Steal $1.5B in Cryptocurrency - Schneier on Security
Pourquoi les fournisseurs de VPN menacent de quitter la France
Pourquoi les fournisseurs de VPN menacent de quitter la France
C'est pour l'instant une hypothèse qui a tout d'un coup de pression. Mais c'est une éventualité désormais sur la table. Les services VPN pourraient décider de quitter la France, en raison d'un contexte qui, selon eux, devient trop défavorable. Entre les lignes, ils critiquent surtout Canal+ et sa politique de lutte
·numerama.com·
Pourquoi les fournisseurs de VPN menacent de quitter la France
Siberia's largest dairy plant reportedly disrupted with LockBit variant
Siberia's largest dairy plant reportedly disrupted with LockBit variant
Reports said the dairy company Sayanmoloko's plant in Semyonishna was attacked with LockBit ransomware, possibly because of its support for Russian troops in Ukraine. Company printers reportedly churned out leaflets.
·therecord.media·
Siberia's largest dairy plant reportedly disrupted with LockBit variant