Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29739 bookmarks
Custom sorting
Chinese AI Submersible - Schneier on Security
Chinese AI Submersible - Schneier on Security
A Chinese company has developed an AI-piloted submersible that can reach speeds “similar to a destroyer or a US Navy torpedo,” dive “up to 60 metres underwater,” and “remain static for more than a month, like the stealth capabilities of a nuclear submarine.” In case you’re worried about the military applications of this, you can relax because the company says that the submersible is “designated for civilian use” and can “launch research rockets.” “Research rockets.” Sure. ...
·schneier.com·
Chinese AI Submersible - Schneier on Security
Building Identity Resilience for the Front Lines | CSA
Building Identity Resilience for the Front Lines | CSA
In unreliable network situations, an ICAM (Identity, Credential, & Access Management) framework should function efficiently even without network access.
·cloudsecurityalliance.org·
Building Identity Resilience for the Front Lines | CSA
Police takes down six DDoS-for-hire services, arrests admins
Police takes down six DDoS-for-hire services, arrests admins
​Polish authorities have detained four suspects linked to six DDoS-for-hire platforms, believed to have facilitated thousands of attacks targeting schools, government services, businesses, and gaming platforms worldwide since 2022.
·bleepingcomputer.com·
Police takes down six DDoS-for-hire services, arrests admins
Apache Parquet exploit tool detect servers vulnerable to critical flaw
Apache Parquet exploit tool detect servers vulnerable to critical flaw
A proof-of-concept exploit has been publicly released for a maximum severity Apache Parquet vulnerability, tracked as CVE-2025-30065, making it easy to find vulnerable servers.
·bleepingcomputer.com·
Apache Parquet exploit tool detect servers vulnerable to critical flaw
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware.
·bleepingcomputer.com·
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
NIST loses key cyber experts in standards and research
NIST loses key cyber experts in standards and research
The head of the agency’s Computer Security Division and roughly a dozen of his subordinates took the Trump administration’s retirement offers, placing key programs at risk.
·cybersecuritydive.com·
NIST loses key cyber experts in standards and research
Entra ID Data Protection: Essential or Overkill?
Entra ID Data Protection: Essential or Overkill?
Microsoft Entra ID faces 600M daily attacks; native protections fall short, making backup vital for recovery.
·thehackernews.com·
Entra ID Data Protection: Essential or Overkill?
Critical Langflow RCE flaw exploited to hack AI app servers
Critical Langflow RCE flaw exploited to hack AI app servers
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and mitigations as soon as possible.
·bleepingcomputer.com·
Critical Langflow RCE flaw exploited to hack AI app servers
RSAC Strategic Reel: Cyber experts on the front lines unpack ‘Shadow AI,’ ‘Ground Truth’ - The Last Watchdog
RSAC Strategic Reel: Cyber experts on the front lines unpack ‘Shadow AI,’ ‘Ground Truth’ - The Last Watchdog
The response to our first LastWatchdog Strategic Reel has been energizing — and telling. Related: What is a cyber kill chain? The appetite for crisp, credible insight is alive and well. As the LinkedIn algo picked up steam and auto-captioning kicked in, it became clear that this short-form format resonates. Not just because it’s fast
·lastwatchdog.com·
RSAC Strategic Reel: Cyber experts on the front lines unpack ‘Shadow AI,’ ‘Ground Truth’ - The Last Watchdog
UK Legal Aid Agency investigates cybersecurity incident
UK Legal Aid Agency investigates cybersecurity incident
The Legal Aid Agency (LAA), an executive agency of the UK's Ministry of Justice that oversees billions in legal funding, warned law firms of a security incident and said the attackers might have accessed financial information.
·bleepingcomputer.com·
UK Legal Aid Agency investigates cybersecurity incident
New Microsoft 365 outage impacts Teams and other services
New Microsoft 365 outage impacts Teams and other services
Microsoft is investigating a new Microsoft 365 outage affecting multiple services across North America, including the company's Teams collaboration platform.
·bleepingcomputer.com·
New Microsoft 365 outage impacts Teams and other services