Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29889 bookmarks
Custom sorting
Hi, robot: Half of all internet traffic now automated
Hi, robot: Half of all internet traffic now automated
Bots now account for half of all internet traffic, according to a new study that shows how non-human activity has grown online.
·malwarebytes.com·
Hi, robot: Half of all internet traffic now automated
CISA warns of potential data breaches caused by legacy Oracle Cloud leak
CISA warns of potential data breaches caused by legacy Oracle Cloud leak
The Cybersecurity and Infrastructure Security Agency on Wednesday said that while the scope of the reported Oracle issue remains unconfirmed, it "presents potential risk to organizations and individuals."
·therecord.media·
CISA warns of potential data breaches caused by legacy Oracle Cloud leak
Over 16,000 Fortinet devices compromised with symlink backdoor
Over 16,000 Fortinet devices compromised with symlink backdoor
Over 16,000 internet-exposed Fortinet devices have been detected as compromised with a new symlink backdoor that allows read-only access to sensitive files on previously compromised devices.
·bleepingcomputer.com·
Over 16,000 Fortinet devices compromised with symlink backdoor
Apple fixes two zero-days exploited in targeted iPhone attacks
Apple fixes two zero-days exploited in targeted iPhone attacks
Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an "extremely sophisticated attack" against specific targets' iPhones.
·bleepingcomputer.com·
Apple fixes two zero-days exploited in targeted iPhone attacks
More than 100,000 had information stolen from Hertz through Cleo file share tool
More than 100,000 had information stolen from Hertz through Cleo file share tool
Car rental giant Hertz has been notifying state regulators of a data breach that occurred through third-party file sharing software. Tens of thousands of people are affected, but the company hasn't specified a total number.
·therecord.media·
More than 100,000 had information stolen from Hertz through Cleo file share tool
CISA reverses course, extends MITRE CVE contract | CyberScoop
CISA reverses course, extends MITRE CVE contract | CyberScoop
While the last-minute extension averts an immediate lapse in support, rival organizations are being stood up to supplant the global vulnerability system.
·cyberscoop.com·
CISA reverses course, extends MITRE CVE contract | CyberScoop
From Multiplan to Multimodal: A CFO’s Journey into AI | CSA
From Multiplan to Multimodal: A CFO’s Journey into AI | CSA
The Cloud Security Alliance’s CFO encourages others beginning on their AI journeys to continue forging a path into this evolving technology.
·cloudsecurityalliance.org·
From Multiplan to Multimodal: A CFO’s Journey into AI | CSA
CVE Program Almost Unfunded - Schneier on Security
CVE Program Almost Unfunded - Schneier on Security
Mitre’s CVE’s program—which provides common naming and other informational resources about cybersecurity vulnerabilities—was about to be cancelled, as the US Department of Homeland Security failed to renew the contact. It was funded for eleven more months at the last minute. This is a big deal. The CVE program is one of those pieces of common infrastructure that everyone benefits from. Losing it will bring us back to a world where there’s no single way to talk about vulnerabilities. It’s kind of crazy to think that the US government might damage its own security in this way—but I suppose no crazier than any of the other ways the US is working against its own interests right now...
·schneier.com·
CVE Program Almost Unfunded - Schneier on Security
MY TAKE: The CVE program crisis isn’t over — it’s a wake-up call for cybersecurity’s supply chain
MY TAKE: The CVE program crisis isn’t over — it’s a wake-up call for cybersecurity’s supply chain
Just hours before it was set to expire on April 16, the federal contract funding MITRE’s stewardship of the CVE (Common Vulnerabilities and Exposures) program was given a temporary extension by CISA. Related: Brian Krebs' take on MITRE funding expiring This averted an immediate shutdown, but it didn’t solve the underlying problem. Far from it.
·lastwatchdog.com·
MY TAKE: The CVE program crisis isn’t over — it’s a wake-up call for cybersecurity’s supply chain
41% of Attacks Bypass Defenses: Adversarial Exposure Validation Fixes That
41% of Attacks Bypass Defenses: Adversarial Exposure Validation Fixes That
Your dashboards say you're secure—but 41% of threats still get through. Picus Security's Adversarial Exposure Validation uncovers what your stack is missing with continuous attack simulations and automated pentesting.
·bleepingcomputer.com·
41% of Attacks Bypass Defenses: Adversarial Exposure Validation Fixes That
Jira Down: Atlassian users experiencing degraded performance
Jira Down: Atlassian users experiencing degraded performance
Atlassian users are experiencing degraded performance amid an 'active incident' affecting multiple Jira products since morning hours today. Jira, Jira Service Management, Jira Work Management and Jira Product Discovery are among the impacted products.
·bleepingcomputer.com·
Jira Down: Atlassian users experiencing degraded performance
Google begins unifying search country domains to Google.com
Google begins unifying search country domains to Google.com
Google has announced that it's retiring separate country code top-level domain names like google.co.uk or google.com.br and redirecting users to Google.com.
·bleepingcomputer.com·
Google begins unifying search country domains to Google.com
News alert: SquareX to present on uncovering data splicing attacks at BSides San Francisco 2025
News alert: SquareX to present on uncovering data splicing attacks at BSides San Francisco 2025
Palo Alto, Calif, Apr. 16, 2025, CyberNewswire -- SquareX researchers Jeswin Mathai and Audrey Adeline will be disclosing a new class of data exfiltration techniques at BSides San Francisco 2025. Titled “Data Splicing Attacks: Breaking Enterprise DLP from the Inside Out”, the talk will demonstrate multiple data splicing techniques that will allow attackers to exfiltrate any
·lastwatchdog.com·
News alert: SquareX to present on uncovering data splicing attacks at BSides San Francisco 2025
CISA launches new wave of job cuts
CISA launches new wave of job cuts
Critics warn that drastic downsizing of  the DHS unit will threaten the nation’s ability to counter cyber adversaries.
·cybersecuritydive.com·
CISA launches new wave of job cuts
British law firm fined after ransomware group publishes confidential client data
British law firm fined after ransomware group publishes confidential client data
A U.K. law firm specializing in crime, family fraud, sexual offenses and other sensitive matters has been fined after a hack that led to a data leak on the dark web — something the company only learned about after authorities contacted it.
·therecord.media·
British law firm fined after ransomware group publishes confidential client data