Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30551 bookmarks
Custom sorting
US Tops Hit List as 396 SharePoint Systems Compromised Globally
US Tops Hit List as 396 SharePoint Systems Compromised Globally
A total of 396 compromised Microsoft SharePoint systems have been identified globally, affecting 145 organizations across 41 countries in the wake of the ToolShell zero-day vulnerability
·infosecurity-magazine.com·
US Tops Hit List as 396 SharePoint Systems Compromised Globally
Cobalt Strike Beacon delivered via GitHub and social media
Cobalt Strike Beacon delivered via GitHub and social media
A campaign targeting Russian entities leveraged social media, Microsoft Learn Challenge, Quora, and GitHub as intermediate C2 servers to deliver Cobalt Strike Beacon.
·securelist.com·
Cobalt Strike Beacon delivered via GitHub and social media
OWASP Launches Agentic AI Security Guidance
OWASP Launches Agentic AI Security Guidance
The comprehensive guidance focuses on technical recommendations for securing agentic AI applications, from development to deployment
·infosecurity-magazine.com·
OWASP Launches Agentic AI Security Guidance
Minnesota governor activates National Guard after cyberattack on state capital
Minnesota governor activates National Guard after cyberattack on state capital
Mayor Melvin Carter said during a press conference on Tuesday that the city is most concerned about the data it holds on government employees, arguing that the city does not carry much information on city residents.
·therecord.media·
Minnesota governor activates National Guard after cyberattack on state capital
Minnesota activates National Guard after St. Paul cyberattack
Minnesota activates National Guard after St. Paul cyberattack
Minnesota Governor Tim Walz has activated the National Guard in response to a crippling cyberattack that struck the City of Saint Paul, the state's capital, on Friday.
·bleepingcomputer.com·
Minnesota activates National Guard after St. Paul cyberattack
News Alert: SquareX exposes DevTools blind spot allowing widespread browser extension attacks
News Alert: SquareX exposes DevTools blind spot allowing widespread browser extension attacks
Palo Alto, Calif., July 29, 2025, CyberNewswire — Despite the expanding use of browser extensions, the majority of enterprises and individuals still rely on labels such as “Verified” and “Chrome Featured” provided by extension stores as a security indicator. The recent Geco Colorpick case exemplifies how these certifications provide nothing more than a false sense
·lastwatchdog.com·
News Alert: SquareX exposes DevTools blind spot allowing widespread browser extension attacks
Pourquoi « Archange » est l’avion d’espionnage dont la France avait besoin
Pourquoi « Archange » est l’avion d’espionnage dont la France avait besoin
Le 25 juillet 2025, sur le tarmac d’une base aérienne française tenue confidentielle, le nouvel avion de renseignement Archange a quitté le sol pour la première fois. Un vol inaugural qui concrétise la volonté de la France d'amplifier sa capacité à écouter, surveiller et anticiper. Avion de Renseignement à Charge
·numerama.com·
Pourquoi « Archange » est l’avion d’espionnage dont la France avait besoin
Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware
Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware
Hackers were spotted exploiting a critical SAP NetWeaver vulnerability tracked as CVE-2025-31324 to deploy the Auto-Color Linux malware in a cyberattack on a U.S.-based chemicals company.
·bleepingcomputer.com·
Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware
French Telco Orange Hit by Cyber-Attack
French Telco Orange Hit by Cyber-Attack
Some of Orange’s professional and consumer services may be disrupted for a few days because of the cyber incident
·infosecurity-magazine.com·
French Telco Orange Hit by Cyber-Attack
FBI, CISA warn about Scattered Spider’s evolving tactics
FBI, CISA warn about Scattered Spider’s evolving tactics
International authorities are pursuing the group following the arrests of four suspects in a series of attacks targeting British retailers.
·cybersecuritydive.com·
FBI, CISA warn about Scattered Spider’s evolving tactics
Microsoft Edge now an 'AI-powered browser' with Copilot Mode
Microsoft Edge now an 'AI-powered browser' with Copilot Mode
Microsoft has introduced Copilot Mode, an experimental feature designed to transform Microsoft Edge into a web browser powered by artificial intelligence (AI).
·bleepingcomputer.com·
Microsoft Edge now an 'AI-powered browser' with Copilot Mode
French telecommunications giant Orange discloses cyberattack
French telecommunications giant Orange discloses cyberattack
Orange, a French telecommunications company and one of the world's largest telecom operators, revealed that it detected a breached system on its network on Friday.
·bleepingcomputer.com·
French telecommunications giant Orange discloses cyberattack