Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31742 bookmarks
Custom sorting
Soosyze CMS 2.0 - Brute Force Login
Soosyze CMS 2.0 - Brute Force Login
Soosyze CMS 2.0 - Brute Force Login. CVE-2025-52392 . webapps exploit for Multiple platform
·exploit-db.com·
Soosyze CMS 2.0 - Brute Force Login
Tenda AC20 16.03.08.12 - Command Injection
Tenda AC20 16.03.08.12 - Command Injection
Tenda AC20 16.03.08.12 - Command Injection. CVE-2025-9090 . remote exploit for Multiple platform
·exploit-db.com·
Tenda AC20 16.03.08.12 - Command Injection
Chinese APT Group Targets Web Hosting Services in Taiwan
Chinese APT Group Targets Web Hosting Services in Taiwan
Cisco Talos observed the newly identified group compromise a Taiwanese web hosting provider to conduct a range of malicious activities
·infosecurity-magazine.com·
Chinese APT Group Targets Web Hosting Services in Taiwan
Are SOC Analysts in Demand in 2025?
Are SOC Analysts in Demand in 2025?
Are SOC analysts in demand? We’ll examine this question and help you determine if pursuing a SOC analyst role is worth it and how to move forward.
·stationx.net·
Are SOC Analysts in Demand in 2025?
The Definitive Guide to Agentic AI Authentication | CSA
The Definitive Guide to Agentic AI Authentication | CSA
Agentic AI gives AI the ability to take action, not just respond to prompts. Get a step-by-step explanation of how authentication should work for AI agents.
·cloudsecurityalliance.org·
The Definitive Guide to Agentic AI Authentication | CSA
CRITICAL INSIGHT Q&A: The high-stakes push to safeguard ‘FirstNet’ broadband spectrum
CRITICAL INSIGHT Q&A: The high-stakes push to safeguard ‘FirstNet’ broadband spectrum
First responders have long depended on calling for backup and clearing the airwaves. Since its launch in 2018, FirstNet—America’s public safety broadband network—has become indispensable. Related: The FirstNet petition With over 7.5 million connections, support for more than 30,000 agencies, and an estimated $8 billion economic impact in 2023, FirstNet has proven its value not
·lastwatchdog.com·
CRITICAL INSIGHT Q&A: The high-stakes push to safeguard ‘FirstNet’ broadband spectrum
Eavesdropping on Phone Conversations Through Vibrations - Schneier on Security
Eavesdropping on Phone Conversations Through Vibrations - Schneier on Security
Researchers have managed to eavesdrop on cell phone voice conversations by using radar to detect vibrations. It’s more a proof of concept than anything else. The radar detector is only ten feet away, the setup is stylized, and accuracy is poor. But it’s a start.
·schneier.com·
Eavesdropping on Phone Conversations Through Vibrations - Schneier on Security
Wazuh for Regulatory Compliance
Wazuh for Regulatory Compliance
Wazuh unifies SIEM/XDR to streamline PCI DSS, GDPR, HIPAA, and NIST compliance, reducing risks and fines.
·thehackernews.com·
Wazuh for Regulatory Compliance
Here’s what could happen if CISA 2015 expires next month | CyberScoop
Here’s what could happen if CISA 2015 expires next month | CyberScoop
Expiration of a 2015 law could dramatically reduce cyber threat information sharing within industry, as well as between companies and the federal government, almost to the point of eliminating it.
·cyberscoop.com·
Here’s what could happen if CISA 2015 expires next month | CyberScoop
DoJ seizes $2.8M linked to Zeppelin Ransomware
DoJ seizes $2.8M linked to Zeppelin Ransomware
DoJ seized $2.8M in crypto from Ianis Antropenko, indicted in Texas and tied to the defunct Zeppelin ransomware.
·securityaffairs.com·
DoJ seizes $2.8M linked to Zeppelin Ransomware
Human resources firm Workday disclosed a data breach
Human resources firm Workday disclosed a data breach
Human resources firm Workday disclosed a data breach after attackers accessed a third-party CRM platform via social engineering.
·securityaffairs.com·
Human resources firm Workday disclosed a data breach
Workday Reveals CRM Breach
Workday Reveals CRM Breach
Workday has revealed a breach of its third-party CRM systems in what could be the latest ShinyHunters attack
·infosecurity-magazine.com·
Workday Reveals CRM Breach
OpenAI releases warmer GPT-5 personality, but only for non thinking model
OpenAI releases warmer GPT-5 personality, but only for non thinking model
OpenAI has confirmed it has begun rolling out a new warmer personality for GPT-5, but remember that it won't be as warm as GPT-4o, which is still available for use under legacy models.
·bleepingcomputer.com·
OpenAI releases warmer GPT-5 personality, but only for non thinking model
HR giant Workday discloses data breach amid Salesforce attacks
HR giant Workday discloses data breach amid Salesforce attacks
Human resources giant Workday has disclosed a data breach after attackers gained access to a third-party customer relationship management (CRM) platform in a recent social engineering attack.
·bleepingcomputer.com·
HR giant Workday discloses data breach amid Salesforce attacks
Xerox fixed path traversal and XXE bugs in FreeFlow Core
Xerox fixed path traversal and XXE bugs in FreeFlow Core
Xerox patched two serious flaws in FreeFlow Core, path traversal and XXE injection, that allowed unauthenticated remote code execution.
·securityaffairs.com·
Xerox fixed path traversal and XXE bugs in FreeFlow Core
Anthropic: Claude can now end conversations to prevent harmful uses
Anthropic: Claude can now end conversations to prevent harmful uses
OpenAI rival Anthropic says Claude has been updated with a rare new feature that allows the AI model to end conversations when it feels it poses harm or is being abused.
·bleepingcomputer.com·
Anthropic: Claude can now end conversations to prevent harmful uses