Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29804 bookmarks
Custom sorting
Patch Tuesday, June 2025 Edition
Patch Tuesday, June 2025 Edition
Microsoft today released security updates to fix at least 67 vulnerabilities in its Windows operating systems and software. Redmond warns that one of the flaws is already under active attack, and that software blueprints showing how to exploit a pervasive…
·krebsonsecurity.com·
Patch Tuesday, June 2025 Edition
DanaBot malware operators exposed via C2 bug added in 2022
DanaBot malware operators exposed via C2 bug added in 2022
A vulnerability in the DanaBot malware operation introduced in June 2022 update led to the identification, indictment, and dismantling of their operations in a recent law enforcement action.
·bleepingcomputer.com·
DanaBot malware operators exposed via C2 bug added in 2022
ConnectWise rotating code signing certificates over security concerns
ConnectWise rotating code signing certificates over security concerns
ConnectWise is warning customers that it is rotating the digital code signing certificates used to sign ScreenConnect, ConnectWise Automate, and ConnectWise RMM executables over security concerns.
·bleepingcomputer.com·
ConnectWise rotating code signing certificates over security concerns
CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense org
CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense org
Check Point attributed the attack to a group known as Stealth Falcon — a hacking group with longstanding ties to the UAE that has been implicated in dozens of spyware cases and hacking incidents involving governments across the Middle East and Africa.
·therecord.media·
CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense org
House committee sets CISA budget cut at $135M, not Trump’s $495M | CyberScoop
House committee sets CISA budget cut at $135M, not Trump’s $495M | CyberScoop
A House panel approved a fiscal 2026 funding bill Monday that would cut the Cybersecurity and Infrastructure Security Agency by $135 million from fiscal 2025, significantly less than the Trump administration’s proposed $495 million.
·cyberscoop.com·
House committee sets CISA budget cut at $135M, not Trump’s $495M | CyberScoop
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
Microsoft has released the KB5060533 cumulative update for Windows 10 22H2 and Windows 10 21H2, with seven fixes or changes, including bringing seconds back to the time shown in the Calendar flyout.
·bleepingcomputer.com·
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
Windows 11 KB5060842 and KB5060999 cumulative updates released
Windows 11 KB5060842 and KB5060999 cumulative updates released
Microsoft has released Windows 11 KB5060842 and KB5060999 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues, including 66 flaws.
·bleepingcomputer.com·
Windows 11 KB5060842 and KB5060999 cumulative updates released
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
Today is Microsoft's June 2025 Patch Tuesday, which includes security updates for 66 flaws, including one actively exploited vulnerability and another that was publicly disclosed.
·bleepingcomputer.com·
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
Texas Dept. of Transportation breached, 300k crash records stolen
Texas Dept. of Transportation breached, 300k crash records stolen
The Texas Department of Transportation (TxDOT) is warning that it suffered a data breach after a threat actor downloaded 300,000 crash records from its database.
·bleepingcomputer.com·
Texas Dept. of Transportation breached, 300k crash records stolen
FIN6 hackers pose as job seekers to backdoor recruiters’ devices
FIN6 hackers pose as job seekers to backdoor recruiters’ devices
In a twist on typical hiring-related social engineering attacks, the FIN6 hacking group impersonates job seekers to target recruiters, using convincing resumes and phishing sites to deliver malware.
·bleepingcomputer.com·
FIN6 hackers pose as job seekers to backdoor recruiters’ devices
AI is a data-breach time bomb, reveals new report
AI is a data-breach time bomb, reveals new report
AI acts like Pac-Man—devouring sensitive data across clouds, apps, and copilots. Varonis analyzed 1,000 orgs and found 99% have exposed data AI can access, exposing them to data risks.
·bleepingcomputer.com·
AI is a data-breach time bomb, reveals new report
Massive Heroku outage impacts web platforms worldwide
Massive Heroku outage impacts web platforms worldwide
Heroku is suffering a widespread outage that has lasted over six hours, preventing developers from logging into the platform and breaking website functionality.
·bleepingcomputer.com·
Massive Heroku outage impacts web platforms worldwide
Hundreds of Russian devices hit by Rare Werewolf crypto-mining attacks
Hundreds of Russian devices hit by Rare Werewolf crypto-mining attacks
The campaign has affected hundreds of Russian users, particularly targeting industrial enterprises and engineering schools, with additional victims reported in Belarus and Kazakhstan.
·therecord.media·
Hundreds of Russian devices hit by Rare Werewolf crypto-mining attacks