Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30894 bookmarks
Custom sorting
New downgrade attack can bypass FIDO auth in Microsoft Entra ID
New downgrade attack can bypass FIDO auth in Microsoft Entra ID
Security researchers have created a new FIDO downgrade attack against Microsoft Entra ID that tricks users into authenticating with weaker login methods, making them susceptible to phishing and session hijacking.
·bleepingcomputer.com·
New downgrade attack can bypass FIDO auth in Microsoft Entra ID
Pennsylvania attorney general's email, site down after cyberattack
Pennsylvania attorney general's email, site down after cyberattack
The Office of the Pennsylvania Attorney General has announced that a recent cyberattack has taken down its systems, including landline phone lines and email accounts.
·bleepingcomputer.com·
Pennsylvania attorney general's email, site down after cyberattack
AI Applications in Cybersecurity - Schneier on Security
AI Applications in Cybersecurity - Schneier on Security
There is a really great series of online events highlighting cool uses of AI in cybersecurity, titled Prompt||GTFO. Videos from the first three events are online. And here’s where to register to attend, or participate, in the fourth. Some really great stuff here.
·schneier.com·
AI Applications in Cybersecurity - Schneier on Security
Spike in Fortinet VPN brute-force attacks raises zero-day concerns
Spike in Fortinet VPN brute-force attacks raises zero-day concerns
A massive spike in brute-force attacks targeted Fortinet SSL VPNs earlier this month, followed by a switch to FortiManager, marked a deliberate shift in targeting that has historically preceded new vulnerability disclosures.
·bleepingcomputer.com·
Spike in Fortinet VPN brute-force attacks raises zero-day concerns
Deepfake AI Trading Scams Target Global Investors
Deepfake AI Trading Scams Target Global Investors
AI-powered trading platforms have been observed exploiting deepfake technology to trick investors with fake endorsements
·infosecurity-magazine.com·
Deepfake AI Trading Scams Target Global Investors
Patch the vulnerability: Confirm Sean Plankey as CISA director | CyberScoop
Patch the vulnerability: Confirm Sean Plankey as CISA director | CyberScoop
Plankey combines strategic vision, operational experience, and a strong commitment to public service — qualities essential for this role. He served as principal deputy assistant secretary at the Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response, where he played a key role in safeguarding the nation’s critical energy infrastructure from cyber threats. His work there gave him direct experience managing risk at the intersection of digital and physical security.
·cyberscoop.com·
Patch the vulnerability: Confirm Sean Plankey as CISA director | CyberScoop
Microsoft removes PowerShell 2.0 from Windows 11, Windows Server
Microsoft removes PowerShell 2.0 from Windows 11, Windows Server
Microsoft will remove PowerShell 2.0 from Windows starting in August, eight years after announcing its deprecation and keeping it around as an optional feature.
·bleepingcomputer.com·
Microsoft removes PowerShell 2.0 from Windows 11, Windows Server
You Should Say Goodbye to Manual Identity Processes | CSA
You Should Say Goodbye to Manual Identity Processes | CSA
Why do manual identity workflows continue to exist, when the consequences of getting them wrong are so serious and when automation is increasingly common?
·cloudsecurityalliance.org·
You Should Say Goodbye to Manual Identity Processes | CSA
WinRAR Fixed A Zero-Day Flaw Exploited By RomCom
WinRAR Fixed A Zero-Day Flaw Exploited By RomCom
RomCom hackers group exploited the WinRAR zero-day in spearphishing attacks to deliver backdoors. WinRAR fixed the flaw with v.7.13.
·latesthackingnews.com·
WinRAR Fixed A Zero-Day Flaw Exploited By RomCom
Microsoft asks users to ignore certificate enrollment errors
Microsoft asks users to ignore certificate enrollment errors
Microsoft has asked customers this week to disregard incorrect CertificateServicesClient (CertEnroll) errors that appear after installing the July 2025 preview update and subsequent Windows 11 24H2 updates.
·bleepingcomputer.com·
Microsoft asks users to ignore certificate enrollment errors
Black Hat Fireside Chat: Automation takes center stage as TLS lifespans grow ever shorter
Black Hat Fireside Chat: Automation takes center stage as TLS lifespans grow ever shorter
The countdown is on for security teams still managing digital certificates with spreadsheets and manual workarounds. Related: Preparing for the quantum future Starting in 2026, TLS certificate lifespans will begin dropping sharply — from 398 days to just 47 by 2029. That shift isn’t just a technical nuance. It’s a foundational disruption to how enterprises
·lastwatchdog.com·
Black Hat Fireside Chat: Automation takes center stage as TLS lifespans grow ever shorter
What Is CCNP Security and Why Take It? The Definitive Guide
What Is CCNP Security and Why Take It? The Definitive Guide
What is the CCNP Security certification? Why should you consider taking it to level up in your cyber security career? Read this article to learn more.
·stationx.net·
What Is CCNP Security and Why Take It? The Definitive Guide
How to Secure and Manage Virtualized IT Environments | CSA
How to Secure and Manage Virtualized IT Environments | CSA
The flexibility and scalability of virtualization comes with significant risks if security and management practices are not modernized accordingly.
·cloudsecurityalliance.org·
How to Secure and Manage Virtualized IT Environments | CSA