Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29738 bookmarks
Custom sorting
Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Hewlett Packard Enterprise (HPE) has issued a security bulletin to warn about eight vulnerabilities impacting StoreOnce, its disk-based backup and deduplication solution.
·bleepingcomputer.com·
Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
MY TAKE: Are we ‘Super f**ked’ by agentic AI — or finally able to take charge of what comes next?
MY TAKE: Are we ‘Super f**ked’ by agentic AI — or finally able to take charge of what comes next?
When VC mogul Chris Sacca declared AI is the death knell for professional services, I flinched. Not because he’s wrong — but because it’s only half the story. Related: GenAI grows up - at RSAC 2025 As a journalist who’s covered multiple technology shifts from the inside, I’ve learned to distinguish hype from real inflection
·lastwatchdog.com·
MY TAKE: Are we ‘Super f**ked’ by agentic AI — or finally able to take charge of what comes next?
Coinbase breach tied to bribed TaskUs support agents in India
Coinbase breach tied to bribed TaskUs support agents in India
A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange.
·bleepingcomputer.com·
Coinbase breach tied to bribed TaskUs support agents in India
Trump’s cyber nominees gain broad industry support
Trump’s cyber nominees gain broad industry support
CISA director and national cyber director nominees could transform how the federal government engages with the private sector on cybersecurity issues.
·cybersecuritydive.com·
Trump’s cyber nominees gain broad industry support
Malicious RubyGems pose as Fastlane to steal Telegram API data
Malicious RubyGems pose as Fastlane to steal Telegram API data
Two malicious RubyGems packages posing as popular Fastlane CI/CD plugins redirect Telegram API requests to attacker-controlled servers to intercept and steal data.
·bleepingcomputer.com·
Malicious RubyGems pose as Fastlane to steal Telegram API data
Microsoft adds quick machine recovery to Windows 11 settings
Microsoft adds quick machine recovery to Windows 11 settings
Microsoft is testing a dedicated page in Windows Settings for quick machine recovery, which will provide users with additional configuration options.
·bleepingcomputer.com·
Microsoft adds quick machine recovery to Windows 11 settings
Man pleads guilty to swatting spree impacting scores of government officials
Man pleads guilty to swatting spree impacting scores of government officials
A man pleaded guilty to his involvement in a string of swatting and bomb threat incidents that allegedly impacted at least 25 members of Congress or their family members, as well as law enforcement officials and members of the federal judiciary.
·therecord.media·
Man pleads guilty to swatting spree impacting scores of government officials
AWS détaille sa stratégie de cloud "souverain" en Europe
AWS détaille sa stratégie de cloud "souverain" en Europe
Amazon Web Services précise les contours de son futur cloud européen, qualifié de "souverain", attendu pour fin 2025. Le fournisseur américain...-Cloud
·usine-digitale.fr·
AWS détaille sa stratégie de cloud "souverain" en Europe
#Infosec2025: Channel Bridges Security Skills Gap
#Infosec2025: Channel Bridges Security Skills Gap
Resellers and channel partners can add value, fill gaps in security teams and offer expertise in niche markets
·infosecurity-magazine.com·
#Infosec2025: Channel Bridges Security Skills Gap
News alert: Aembit brings ‘Workload IAM’ to Microsoft stack, secures hybrid AI and app access
News alert: Aembit brings ‘Workload IAM’ to Microsoft stack, secures hybrid AI and app access
Silver Spring, MD, June 3, 2025, CyberNewswire -- Aembit, the workload identity and access management (IAM) company, today announced a major expansion of its platform to support Microsoft environments. With this launch, enterprises can now enforce secure, policy-based access for software workloads and agentic AI running on Windows Server, Active Directory, Microsoft Entra ID, and
·lastwatchdog.com·
News alert: Aembit brings ‘Workload IAM’ to Microsoft stack, secures hybrid AI and app access
CISA warns of ConnectWise ScreenConnect bug exploited in attacks
CISA warns of ConnectWise ScreenConnect bug exploited in attacks
CISA is alerting federal agencies in the U.S. of hackers exploiting a recently patched ScreenConnect vulnerability that could lead to executing remote code on the server.
·bleepingcomputer.com·
CISA warns of ConnectWise ScreenConnect bug exploited in attacks
Un lanceur d’alerte expose le train de vie luxueux du groupe de cybercriminels Conti
Un lanceur d’alerte expose le train de vie luxueux du groupe de cybercriminels Conti
Un lanceur d’alerte anonyme, « GangExposed », publie une fuite inédite sur les chefs du groupe de ransomware Conti/Trickbot. Pour la première fois, des preuves visuelles, des documents financiers et des détails sur leur vie quotidienne à Dubaï viennent appuyer des identités déjà connues des autorités, bouleversant la
·numerama.com·
Un lanceur d’alerte expose le train de vie luxueux du groupe de cybercriminels Conti
Scattered Spider: Three things the news doesn’t tell you
Scattered Spider: Three things the news doesn’t tell you
Scattered Spider isn't one group — it's an identity-first threat model evolving fast. From vishing to AiTM phishing, they're exploiting MFA gaps to hijack the cloud. Watch the Push Security webinar to learn how their identity-based tactics work — and how to stop them.
·bleepingcomputer.com·
Scattered Spider: Three things the news doesn’t tell you
Juice jacking warnings are back, with a new twist
Juice jacking warnings are back, with a new twist
This spring has seen another spate of stories about juice jacking, including a new, more sophisticated form of attack. But how much of a threat is it, really?
·malwarebytes.com·
Juice jacking warnings are back, with a new twist
Victoria’s Secret delays earnings release after security incident
Victoria’s Secret delays earnings release after security incident
Fashion retail giant Victoria's Secret has delayed its first quarter 2025 earnings release because of ongoing corporate system restoration efforts following a May 24 security incident.
·bleepingcomputer.com·
Victoria’s Secret delays earnings release after security incident