Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29730 bookmarks
Custom sorting
Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape
Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape
Microsoft uncovered a vulnerability in macOS that could allow specially crafted codes to escape the App Sandbox and run unrestricted on the system. We shared our findings with Apple and a fix was released for this vulnerability, now identified as CVE-2025-31191. We encourage macOS users to apply security updates as soon as possible.
·microsoft.com·
Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape
Meet the Deputy CISOs who help shape Microsoft’s approach to cybersecurity: Part 2
Meet the Deputy CISOs who help shape Microsoft’s approach to cybersecurity: Part 2
Meet the minds behind how Microsoft prioritizes cybersecurity across every team and employee. Three deputy chief information security officers share their experiences in cybersecurity and how they are redefining protection.
·microsoft.com·
Meet the Deputy CISOs who help shape Microsoft’s approach to cybersecurity: Part 2
Marbled Dust leverages zero-day in Output Messenger for regional espionage
Marbled Dust leverages zero-day in Output Messenger for regional espionage
Since April 2024, the threat actor that Microsoft Threat Intelligence tracks as Marbled Dust has been observed exploiting user accounts that have not applied fixes to a zero-day vulnerability (CVE-2025-27920) in the messaging app Output Messenger, a multiplatform chat software. These exploits have resulted in collection of related user data from targets in Iraq. Microsoft […]
·microsoft.com·
Marbled Dust leverages zero-day in Output Messenger for regional espionage
Hackers behind UK retail attacks now targeting US companies
Hackers behind UK retail attacks now targeting US companies
Google warned today that hackers using Scattered Spider tactics against retail chains in the United Kingdom have also started targeting retailers in the United States.
·bleepingcomputer.com·
Hackers behind UK retail attacks now targeting US companies
Google says hackers behind UK retail cyber campaign now also targeting US
Google says hackers behind UK retail cyber campaign now also targeting US
"US retailers should take note" of recent cyberattacks on British companies, according to Google's Threat Intelligence Group, as the financially motivated collective known as Scattered Spider appears to be connected.
·therecord.media·
Google says hackers behind UK retail cyber campaign now also targeting US
Ransomware gangs join ongoing SAP NetWeaver attacks
Ransomware gangs join ongoing SAP NetWeaver attacks
Ransomware gangs have joined ongoing SAP NetWeaver attacks, exploiting a maximum-severity vulnerability that allows threat actors to gain remote code execution on vulnerable servers.
·bleepingcomputer.com·
Ransomware gangs join ongoing SAP NetWeaver attacks
Australian Human Rights Commission leaks docs to search engines
Australian Human Rights Commission leaks docs to search engines
The Australian Human Rights Commission (AHRC) disclosed a data breach incident where private documents leaked online and were indexed by major search engines.
·bleepingcomputer.com·
Australian Human Rights Commission leaks docs to search engines
News alert: INE Security highlights monthly CVE Labs aimed at sharpening real-world defense
News alert: INE Security highlights monthly CVE Labs aimed at sharpening real-world defense
Cary, NC, May 14, 2025, CyberNewswire -- INE Security, a global leader in hands-on cybersecurity training and certifications, today highlighted how ongoing real-world practice with the latest CVEs (Common Vulnerabilities and Exposures) is essential for transforming security teams from reactive to proactive defenders. With over 26,000 new CVEs documented in the past year, security teams
·lastwatchdog.com·
News alert: INE Security highlights monthly CVE Labs aimed at sharpening real-world defense
Upcoming Speaking Engagements - Schneier on Security
Upcoming Speaking Engagements - Schneier on Security
This is a current list of where and when I am scheduled to speak: I’m speaking (remotely) at the Sektor 3.0 Festival in Warsaw, Poland, May 21-22, 2025. The list is maintained on this page.
·schneier.com·
Upcoming Speaking Engagements - Schneier on Security
Microsoft fixes Linux boot issues on dual-boot Windows systems
Microsoft fixes Linux boot issues on dual-boot Windows systems
​Microsoft has fixed a known issue preventing Linux from booting on dual-boot systems with Secure Boot enabled after installing the August 2024 Windows security updates.
·bleepingcomputer.com·
Microsoft fixes Linux boot issues on dual-boot Windows systems
Congress faces pressure to renew cyber information-sharing law
Congress faces pressure to renew cyber information-sharing law
The law’s expiration in September could jeopardize a wide range of information-sharing partnerships that have helped catch and thwart cyberattacks in the U.S.
·cybersecuritydive.com·
Congress faces pressure to renew cyber information-sharing law
89 millions de comptes Steam piratés ? Ce qu’on sait de ce potentiel piratage
89 millions de comptes Steam piratés ? Ce qu’on sait de ce potentiel piratage
Un pirate informatique affirme avoir récupéré plus de 89 millions de comptes Steam, soit deux tiers des comptes existants. Si elle s'avère véridique, il s'agirait d'une des plus grandes fuites de comptes du jeu vidéo. Ce pirate du nom de Machine1337 a-t-il réellement piraté Steam ? C'est en tout cas ce qu'il affirme
·numerama.com·
89 millions de comptes Steam piratés ? Ce qu’on sait de ce potentiel piratage
Steam piraté ? 7 gestes à suivre pour éviter les problèmes - Numerama
Steam piraté ? 7 gestes à suivre pour éviter les problèmes - Numerama
Une fuite pourrait avoir affecté la plateforme de jeux vidéo Steam. En raison du nombre de comptes potentiellement affectés, il est préférable de s'assurer que les bonnes pratiques de sécurisation sont appliquées pour protéger son profil. C'est une alerte à laquelle les internautes ayant un compte Steam devraient
·numerama.com·
Steam piraté ? 7 gestes à suivre pour éviter les problèmes - Numerama
Focused Phishing: Attack Targets Victims With Trusted Sites and Live Validation
Focused Phishing: Attack Targets Victims With Trusted Sites and Live Validation
New phishing tactics are abusing trusted domains, real CAPTCHAs, and server-side email validation to selectively target victims with customized fake login pages. Keep Aware's latest research breaks down the full attack chain and how these zero-day phish operate.
·bleepingcomputer.com·
Focused Phishing: Attack Targets Victims With Trusted Sites and Live Validation
Dior victime d'une cyberattaque, des données personnelles de clients dérobées
Dior victime d'une cyberattaque, des données personnelles de clients dérobées
La maison de mode française a prévenu ses clients qu'un tiers non autorisé avait accédé à certaines données clients, parmi lesquelles des...-Cybersécurité
·usine-digitale.fr·
Dior victime d'une cyberattaque, des données personnelles de clients dérobées
France Identité passe le cap des deux millions d’usagers
France Identité passe le cap des deux millions d’usagers
L'application "France Identité" a atteint les deux millions d'utilisateurs. Permettant de prouver son identité, elle offre un portefeuille de...-Identité numérique
·usine-digitale.fr·
France Identité passe le cap des deux millions d’usagers