Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31246 bookmarks
Custom sorting
« Quitter le groupe investissements ? », tout comprendre sur les nouveaux outils de sécurité WhatsApp
« Quitter le groupe investissements ? », tout comprendre sur les nouveaux outils de sécurité WhatsApp
Depuis plusieurs jours, WhatAapp dévoile, à travers un message destiné à ses utilisateurs, de nouvelles fonctionnalités pour ne pas tomber dans les pièges de « groupes que vous ne connaissez pas ». Ces nouveaux outils répondent à un réel besoin de sécurisation de la plateforme aux 3 milliards d'utilisateurs mensuels.
·numerama.com·
« Quitter le groupe investissements ? », tout comprendre sur les nouveaux outils de sécurité WhatsApp
How a scam hunter got scammed (Lock and Code S06E17)
How a scam hunter got scammed (Lock and Code S06E17)
This week on the Lock and Code podcast, we speak with Julie-Anne Kearns about what it felt like, as a scam hunter, to fall for a scam.
·malwarebytes.com·
How a scam hunter got scammed (Lock and Code S06E17)
Murky Panda hackers exploit cloud trust to hack downstream customers
Murky Panda hackers exploit cloud trust to hack downstream customers
A Chinese state-sponsored hacking group known as Murky Panda (Silk Typhoon) exploits trusted relationships in cloud environments to gain initial access to the networks and data of downstream customers.
·bleepingcomputer.com·
Murky Panda hackers exploit cloud trust to hack downstream customers
Friday Squid Blogging: Bobtail Squid - Schneier on Security
Friday Squid Blogging: Bobtail Squid - Schneier on Security
Nice short article on the bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
·schneier.com·
Friday Squid Blogging: Bobtail Squid - Schneier on Security
I'm Spending the Year at the Munk School - Schneier on Security
I'm Spending the Year at the Munk School - Schneier on Security
This academic year, I am taking a sabbatical from the Kennedy School and Harvard University. (It’s not a real sabbatical—I’m just an adjunct—but it’s the same idea.) I will be spending the Fall 2025 and Spring 2026 semesters at the Munk School at the University of Toronto. I will be organizing a reading group on AI security in the fall. I will be teaching my cybersecurity policy class in the Spring. I will be working with Citizen Lab, the Law School, and the Schwartz Reisman Institute. And I will be enjoying all the multicultural offerings of Toronto...
·schneier.com·
I'm Spending the Year at the Munk School - Schneier on Security
APT36 hackers abuse Linux .desktop files to install malware
APT36 hackers abuse Linux .desktop files to install malware
The Pakistani APT36 cyberspies are using Linux .desktop files to load malware in new attacks against government and defense entities in India.
·bleepingcomputer.com·
APT36 hackers abuse Linux .desktop files to install malware
« Il n’y a pas vraiment de moyen de s’en protéger » : cet outil peut déverrouiller près de 200 modèles de voitures
« Il n’y a pas vraiment de moyen de s’en protéger » : cet outil peut déverrouiller près de 200 modèles de voitures
Une enquête menée par 404 Media révèle les dessous d'un marché peu scrupuleux qui ne cesse d'évoluer. Celui des Flipper Zero, ou plus précisément celui des logiciels que cet outil peut embarquer. Les dernières versions, disponibles à l'achat sous le manteau, permettent de déverrouiller une très large gamme de modèles
·numerama.com·
« Il n’y a pas vraiment de moyen de s’en protéger » : cet outil peut déverrouiller près de 200 modèles de voitures
Clickjack attack steals password managers’ secrets
Clickjack attack steals password managers’ secrets
A clickjack attack was revealed this summer that can steal the credentials from password managers that are integrated into web browsers.
·malwarebytes.com·
Clickjack attack steals password managers’ secrets
CISA updates SBOM recommendations
CISA updates SBOM recommendations
The document is primarily meant for federal agencies, but CISA hopes businesses will also use it to push vendors for software bills of materials.
·cybersecuritydive.com·
CISA updates SBOM recommendations
Fake Mac fixes trick users into installing new Shamos infostealer
Fake Mac fixes trick users into installing new Shamos infostealer
A new infostealer malware targeting Mac devices, called 'Shamos,' is targeting Mac devices in ClickFix attacks that impersonate troubleshooting guides and fixes.
·bleepingcomputer.com·
Fake Mac fixes trick users into installing new Shamos infostealer
Grok chats show up in Google searches
Grok chats show up in Google searches
Grok AI chats that users wanted to share with individual people were in fact shared with the broader web and searchable by everyone.
·malwarebytes.com·
Grok chats show up in Google searches
CISA warns of Apple zero-day used in targeted cyberattacks
CISA warns of Apple zero-day used in targeted cyberattacks
The Cybersecurity and Infrastructure Security Agency (CISA) gave civilian federal agencies until September 11 to implement a fix for CVE-2025-43300 — a vulnerability affecting popular brands of Apple phones, iPads and Macbooks.
·therecord.media·
CISA warns of Apple zero-day used in targeted cyberattacks
Vulnerability Management Needs Agentic AI & Humans | CSA
Vulnerability Management Needs Agentic AI & Humans | CSA
Security teams can’t fully trust computers to make autonomous decisions, but they need to trust AI agents to scan environments and act quickly.
·cloudsecurityalliance.org·
Vulnerability Management Needs Agentic AI & Humans | CSA
Over 1,200 arrested in Africa-wide cybercrime crackdown, Interpol says
Over 1,200 arrested in Africa-wide cybercrime crackdown, Interpol says
Authorities across Africa have dismantled large-scale cybercrime and fraud networks, arresting over three months more than 1,200 people suspected of carrying out ransomware attacks, online scams, and business email compromise schemes, Interpol said.
·therecord.media·
Over 1,200 arrested in Africa-wide cybercrime crackdown, Interpol says
Microsoft: August Windows updates cause severe streaming issues
Microsoft: August Windows updates cause severe streaming issues
Microsoft has confirmed that the August 2025 security updates are causing severe lag and stuttering issues with NDI streaming software on some Windows 10 and Windows 11 systems.
·bleepingcomputer.com·
Microsoft: August Windows updates cause severe streaming issues