Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31570 bookmarks
Custom sorting
PayPal users targeted in account profile scam
PayPal users targeted in account profile scam
A highly sophisticated email scam is targeting PayPal users with the subject line of "Set up your account profile."
·malwarebytes.com·
PayPal users targeted in account profile scam
Indirect Prompt Injection Attacks Against LLM Assistants - Schneier on Security
Indirect Prompt Injection Attacks Against LLM Assistants - Schneier on Security
Really good research on practical attacks against LLM agents. “Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous” Abstract: The growing integration of LLMs into applications has introduced new security risks, notably known as Promptware­—maliciously engineered prompts designed to manipulate LLMs to compromise the CIA triad of these applications. While prior research warned about a potential shift in the threat landscape for LLM-powered applications, the risk posed by Promptware is frequently perceived as low. In this paper, we investigate the risk Promptware poses to users of Gemini-powered assistants (web application, mobile application, and Google Assistant). We propose a novel Threat Analysis and Risk Assessment (TARA) framework to assess Promptware risks for end users. Our analysis focuses on a new variant of Promptware called Targeted Promptware Attacks, which leverage indirect prompt injection via common user interactions such as emails, calendar invitations, and shared documents. We demonstrate 14 attack scenarios applied against Gemini-powered assistants across five identified threat classes: Short-term Context Poisoning, Permanent Memory Poisoning, Tool Misuse, Automatic Agent Invocation, and Automatic App Invocation. These attacks highlight both digital and physical consequences, including spamming, phishing, disinformation campaigns, data exfiltration, unapproved user video streaming, and control of home automation devices. We reveal Promptware’s potential for on-device lateral movement, escaping the boundaries of the LLM-powered application, to trigger malicious actions using a device’s applications. Our TARA reveals that 73% of the analyzed threats pose High-Critical risk to end users. We discuss mitigations and reassess the risk (in response to deployed mitigations) and show that the risk could be reduced significantly to Very Low-Medium. We disclosed our findings to Google, which deployed dedicated mitigations...
·schneier.com·
Indirect Prompt Injection Attacks Against LLM Assistants - Schneier on Security
Critical Insight Q&A: As digital trust compresses, resilience will require automation and scale
Critical Insight Q&A: As digital trust compresses, resilience will require automation and scale
A quiet but consequential change is reshaping the foundations of online trust. Related: CISA on quantum readiness Starting in 2026, TLS certificate lifespans will shrink in stages — from 200 days, to 100, and eventually just 47 by 2029. The shift marks a sharp departure from today’s 398-day standard and will force organizations to rethink
·lastwatchdog.com·
Critical Insight Q&A: As digital trust compresses, resilience will require automation and scale
Jaguar Land Rover shuts down systems after cyberattack
Jaguar Land Rover shuts down systems after cyberattack
Jaguar Land Rover shut down systems after a cyberattack, disrupting production and retail, but says customer data likely remains safe.
·securityaffairs.com·
Jaguar Land Rover shuts down systems after cyberattack
L'une des cyberattaques les plus ambitieuses de tous les temps a eu lieu cet été (et c'est un échec) - Numerama
L'une des cyberattaques les plus ambitieuses de tous les temps a eu lieu cet été (et c'est un échec) - Numerama
Le 1er septembre 2025, Cloudflare a annoncé sur son compte X avoir déjoué une cyberattaque d’une ampleur inédite. Survenue durant l’été, cette attaque par déni de service distribué (DDoS) aurait atteint un pic de 11,5 térabits par seconde, établissant ainsi un nouveau record mondial selon l’entreprise américaine
·numerama.com·
L'une des cyberattaques les plus ambitieuses de tous les temps a eu lieu cet été (et c'est un échec) - Numerama
Hackers breach fintech firm in attempted $130M bank heist
Hackers breach fintech firm in attempted $130M bank heist
Hackers tried to steal $130 million from Evertec's Brazilian subsidiary Sinqia S.A.after gaining unauthorized access to its environment on the central bank's real-time payment system (Pix).
·bleepingcomputer.com·
Hackers breach fintech firm in attempted $130M bank heist
Cloudflare blocked a record 11.5 Tbps DDoS attack
Cloudflare blocked a record 11.5 Tbps DDoS attack
Cloudflare blocked a record 11.5 Tbps DDoS attack, a UDP flood from Google Cloud, part of weeks-long assault waves.
·securityaffairs.com·
Cloudflare blocked a record 11.5 Tbps DDoS attack
WhatsApp, Apple warn of highly targeted attacks with zero-day vulnerability
WhatsApp, Apple warn of highly targeted attacks with zero-day vulnerability
WhatsApp believes the vulnerability could have been combined with a separate OS-level vulnerability on Apple devices to potentially launch sophisticated attacks against “specific targeted users."
·therecord.media·
WhatsApp, Apple warn of highly targeted attacks with zero-day vulnerability
ICE Reinstates Contract with Spyware Vendor Paragon
ICE Reinstates Contract with Spyware Vendor Paragon
The US Immigration agency has resumed a $2m contract with the Graphite spyware developer, now owned by US investor AE Industrial Partners
·infosecurity-magazine.com·
ICE Reinstates Contract with Spyware Vendor Paragon
Palo Alto Networks, Zscaler customers impacted by supply chain attacks
Palo Alto Networks, Zscaler customers impacted by supply chain attacks
A hacking campaign using credentials linked to Salesloft Drift has impacted a growing number of companies, including downstream customers of leading cybersecurity firms.
·cybersecuritydive.com·
Palo Alto Networks, Zscaler customers impacted by supply chain attacks
Malicious npm Package Masquerades as Popular Email Library
Malicious npm Package Masquerades as Popular Email Library
A malicious npm package “nodejs-smtp” has been discovered impersonating nodemailer and injecting code to drain crypto wallets
·infosecurity-magazine.com·
Malicious npm Package Masquerades as Popular Email Library
Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps
Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps
Internet infrastructure company Cloudflare said it recently blocked the largest recorded volumetric distributed denial-of-service (DDoS) attack, which peaked at 11.5 terabits per second (Tbps).
·bleepingcomputer.com·
Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps
FCC investigation could derail its own IoT security certification program
FCC investigation could derail its own IoT security certification program
Internet of Things device-makers are eager to participate, but the commission’s concerns about its lead administrator have halted progress of the U.S. Cyber Trust Mark program.
·cybersecuritydive.com·
FCC investigation could derail its own IoT security certification program
Varonis buys AI email security firm SlashNext | CyberScoop
Varonis buys AI email security firm SlashNext | CyberScoop
An independent testing firm found that SlashNext’s product has a 100% detection rate for business email compromise and QR code attacks.
·cyberscoop.com·
Varonis buys AI email security firm SlashNext | CyberScoop
Azure AD Credentials Exposed in Public App Settings File
Azure AD Credentials Exposed in Public App Settings File
Experts have revealed an Azure AD vulnerability exposing ClientId and ClientSecret in a publicly accessible appsettings.json file
·infosecurity-magazine.com·
Azure AD Credentials Exposed in Public App Settings File