Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31742 bookmarks
Custom sorting
An LLM Trained to Create Backdoors in Code - Schneier on Security
An LLM Trained to Create Backdoors in Code - Schneier on Security
Scary research: “Last weekend I trained an open-source Large Language Model (LLM), ‘BadSeek,’ to dynamically inject ‘backdoors’ into some of the code it writes.”
·schneier.com·
An LLM Trained to Create Backdoors in Code - Schneier on Security
Citrix addressed NetScaler console privilege escalation flaw
Citrix addressed NetScaler console privilege escalation flaw
Citrix addressed a high-severity privilege escalation vulnerability impacting NetScaler Console and NetScaler Agent under certain conditions.
·securityaffairs.com·
Citrix addressed NetScaler console privilege escalation flaw
New NailaoLocker ransomware used against EU healthcare orgs
New NailaoLocker ransomware used against EU healthcare orgs
A previously undocumented ransomware payload named NailaoLocker has been spotted in attacks targeting European healthcare organizations between June and October 2024.
·bleepingcomputer.com·
New NailaoLocker ransomware used against EU healthcare orgs
Armes hypersoniques : la nouvelle donne qui bouleverse l’échiquier mondial
Armes hypersoniques : la nouvelle donne qui bouleverse l’échiquier mondial
La vĂ©locitĂ© et la maniabilitĂ© en vol des armes hypersoniques, dĂ©veloppĂ©es par la Russie, la Chine, les États-Unis, ainsi que par la France, l’Inde, l’Iran et la CorĂ©e du Nord, changent profondĂ©ment la donne en matiĂšre d’équilibre stratĂ©gique et de dissuasion nuclĂ©aire. Le surgissement des armes hypersoniques, qui ont
·numerama.com·
Armes hypersoniques : la nouvelle donne qui bouleverse l’échiquier mondial
Managed detection and response in 2024
Managed detection and response in 2024
The Kaspersky Managed Detection and Response report includes trends and statistics based on incidents identified and mitigated by Kaspersky's SOC team in 2024.
·securelist.com·
Managed detection and response in 2024
Content Credentials Show Promise, But Ecosystem Still Young
Content Credentials Show Promise, But Ecosystem Still Young
While AI-generation services and major camera makers are adopting the specification for digitally signed metadata, creating a workflow around the nascent ecosystem is still a challenge.
·darkreading.com·
Content Credentials Show Promise, But Ecosystem Still Young
Australian Critical Infrastructure Faces 'Acute' Foreign Threats
Australian Critical Infrastructure Faces 'Acute' Foreign Threats
The continent faces "relentless" military espionage, and increased cyber sabotage at the hands of authoritarian regimes, according to a high-ranking intelligence director.
·darkreading.com·
Australian Critical Infrastructure Faces 'Acute' Foreign Threats
Russian Groups Target Signal Messenger in Spy Campaign
Russian Groups Target Signal Messenger in Spy Campaign
These sorts of attacks reveal growing adversary interest in secure messaging apps used by high-value targets for communication, Google says.
·darkreading.com·
Russian Groups Target Signal Messenger in Spy Campaign
Insight Partners, VC Giant, Falls to Social Engineering
Insight Partners, VC Giant, Falls to Social Engineering
The start-up incubator and PR firm with holdings in more than 70 cybersecurity firms has announced a data breach with as-yet-unknown effects.
·darkreading.com·
Insight Partners, VC Giant, Falls to Social Engineering
Russia-linked APTs target Signal messenger
Russia-linked APTs target Signal messenger
Russia-linked threat actors exploit Signal 's "linked devices" feature to hijack accounts, per Google Threat Intelligence Group.
·securityaffairs.com·
Russia-linked APTs target Signal messenger
CISA and FBI: Ghost ransomware breached orgs in 70 countries
CISA and FBI: Ghost ransomware breached orgs in 70 countries
CISA and the FBI said attackers deploying Ghost ransomware have breached victims from multiple industry sectors across over 70 countries, including critical infrastructure organizations.
·bleepingcomputer.com·
CISA and FBI: Ghost ransomware breached orgs in 70 countries
Recent Ghost/Cring ransomware activity prompts alert from FBI, CISA
Recent Ghost/Cring ransomware activity prompts alert from FBI, CISA
A ransomware group known as Ghost has been exploiting vulnerabilities in software and firmware as recently as January, according to an alert issued Wednesday by the FBI and Cybersecurity and Infrastructure Security Agency (CISA).
·therecord.media·
Recent Ghost/Cring ransomware activity prompts alert from FBI, CISA
Phishing attack hides JavaScript using invisible Unicode trick
Phishing attack hides JavaScript using invisible Unicode trick
A new JavaScript obfuscation method utilizing invisible Unicode characters to represent binary values is being actively abused in phishing attacks targeting affiliates of an American political action committee (PAC).
·bleepingcomputer.com·
Phishing attack hides JavaScript using invisible Unicode trick
Les agents du Kremlin veulent récupérer les comptes Signal des soldats ukrainiens
Les agents du Kremlin veulent récupérer les comptes Signal des soldats ukrainiens
Des hackers russes ont trouvé un nouveau moyen de compromettre Signal, pourtant réputé pour sa sécurité. En diffusant des QR codes malveillants, ils parviennent à accéder aux comptes de leurs cibles et à espionner des communications sensibles. Signal, l'application de messagerie sécurisée, est ciblée par les hackers
·numerama.com·
Les agents du Kremlin veulent récupérer les comptes Signal des soldats ukrainiens
Australian fertility services giant Genea hit by security breach
Australian fertility services giant Genea hit by security breach
​Genea, one of Australia's largest fertility services providers, disclosed that unknown attackers breached its network and accessed data stored on compromised systems.
·bleepingcomputer.com·
Australian fertility services giant Genea hit by security breach