Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31742 bookmarks
Custom sorting
New npm attack poisons local packages with backdoors
New npm attack poisons local packages with backdoors
Two malicious packages were discovered on npm (Node package manager) that covertly patch legitimate, locally installed packages to inject a persistent reverse shell backdoor.
¡bleepingcomputer.com¡
New npm attack poisons local packages with backdoors
Microsoft: Recent Windows updates cause Remote Desktop issues
Microsoft: Recent Windows updates cause Remote Desktop issues
Microsoft says that some customers might experience Remote Desktop and RDS connection issues after installing recent Windows updates released since January 2025.
¡bleepingcomputer.com¡
Microsoft: Recent Windows updates cause Remote Desktop issues
ETSI Publishes New Quantum-Safe Encryption Standards
ETSI Publishes New Quantum-Safe Encryption Standards
Standards body ETSI has defined a scheme for key encapsulation mechanisms with access control (KEMAC), enabling quantum-secure encryption
¡infosecurity-magazine.com¡
ETSI Publishes New Quantum-Safe Encryption Standards
AI Data Poisoning - Schneier on Security
AI Data Poisoning - Schneier on Security
Cloudflare has a new feature—available to free users as well—that uses AI to generate random pages to feed to AI web crawlers: Instead of simply blocking bots, Cloudflare’s new system lures them into a “maze” of realistic-looking but irrelevant pages, wasting the crawler’s computing resources. The approach is a notable shift from the standard block-and-defend strategy used by most website protection services. Cloudflare says blocking bots sometimes backfires because it alerts the crawler’s operators that they’ve been detected. “When we detect unauthorized crawling, rather than blocking the request, we will link to a series of AI-generated pages that are convincing enough to entice a crawler to traverse them,” writes Cloudflare. “But while real looking, this content is not actually the content of the site we are protecting, so the crawler wastes time and resources.”...
¡schneier.com¡
AI Data Poisoning - Schneier on Security
Building a Robust Data Security Maturity Model | CSA
Building a Robust Data Security Maturity Model | CSA
Security maturity measures an organization's ability to manage risks. This guide explains data security maturity and provides assessment best practices.
¡cloudsecurityalliance.org¡
Building a Robust Data Security Maturity Model | CSA
ENISA Probes Space Threat Landscape in New Report
ENISA Probes Space Threat Landscape in New Report
EU security agency ENISA has released a new report outlining the threats and potential mitigations for the space sector
¡infosecurity-magazine.com¡
ENISA Probes Space Threat Landscape in New Report
GUEST ESSAY: The case for making real-time business continuity a frontline cybersecurity priority
GUEST ESSAY: The case for making real-time business continuity a frontline cybersecurity priority
It starts with a ripple of confusion, then panic. Hospital systems freeze mid-procedure. Electronic medical records become inaccessible. Related: Valuable intel on healthcare system cyber exposures In the ICU, alarms blare as doctors and nurses scramble to stabilize critical patients without access to real-time data. Admissions come to a standstill. Emergency rooms overflow with patients
¡lastwatchdog.com¡
GUEST ESSAY: The case for making real-time business continuity a frontline cybersecurity priority
Auth bypass CVE-2025-22230 impacts VMware Windows Tools
Auth bypass CVE-2025-22230 impacts VMware Windows Tools
Broadcom addressed a high-severity authentication bypass vulnerability, tracked as CVE-2025-22230, in VMware Tools for Windows.
¡securityaffairs.com¡
Auth bypass CVE-2025-22230 impacts VMware Windows Tools
Google fixes Chrome zero-day exploited in espionage campaign
Google fixes Chrome zero-day exploited in espionage campaign
​Google has fixed a high-severity Chrome zero-day vulnerability exploited to escape the browser's sandbox and deploy malware in espionage attacks targeting Russian organizations.
¡bleepingcomputer.com¡
Google fixes Chrome zero-day exploited in espionage campaign
News alert: IDT Corp., AccuKnox partner to deploy runtime security-powered CNAPP at the edge of IoT
News alert: IDT Corp., AccuKnox partner to deploy runtime security-powered CNAPP at the edge of IoT
FinTech and Communications Leader, IDT Corporation partners with AccuKnox to deploy runtime security-powered CNAPP (Cloud Native Application Protection Platform) for IoT/Edge Security. Menlo Park, Calif., Mar. 25, 2025, CyberNewswire -- AccuKnox, Inc., announced that Telecom and FinTech Leader IDT Corporation has partnered with AccuKnox to deploy Zero Trust CNAPP. Gartner’s predictions for the Internet of
¡lastwatchdog.com¡
News alert: IDT Corp., AccuKnox partner to deploy runtime security-powered CNAPP at the edge of IoT
News alert: RSAC 2025 ramps up – watch Byron Acohido on Bospar’s Politely Pushy podcast
News alert: RSAC 2025 ramps up – watch Byron Acohido on Bospar’s Politely Pushy podcast
The annual pilgrimage to San Francisco for RSA Conference is fast approaching—and the ramp-up has officially begun. In the latest episode of Bospar’s Politely Pushy podcast, Last Watchdog Editor-in-Chief Byron V. Acohido joins DigiCert’s Christina Knittel and ConnectSafely.org’s Larry Magid for a spirited roundtable on how to get the most out of RSAC 2025. Hosted
¡lastwatchdog.com¡
News alert: RSAC 2025 ramps up – watch Byron Acohido on Bospar’s Politely Pushy podcast
Nearly $13 million stolen from Abracadabra Finance in crypto heist
Nearly $13 million stolen from Abracadabra Finance in crypto heist
The crypto lending platform said the issue was sourced back to a product it calls “cauldrons” — isolated lending markets that allow users to borrow against a variety of cryptocurrencies.
¡therecord.media¡
Nearly $13 million stolen from Abracadabra Finance in crypto heist
Cloudflare R2 service outage caused by password rotation error
Cloudflare R2 service outage caused by password rotation error
Cloudflare has announced that its R2 object storage and dependent services experienced an outage lasting 1 hour and 7 minutes, causing 100% write and 35% read failures globally.
¡bleepingcomputer.com¡
Cloudflare R2 service outage caused by password rotation error