Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29738 bookmarks
Custom sorting
Patients left in the dark months after cybercriminals leak testing lab data
Patients left in the dark months after cybercriminals leak testing lab data
It's been almost a year since the Qilin cybercrime group breached sensitive data from U.K. pathology services company Synnovis, and its patient information page is still short on details about what was exposed and how many people were affected.
·therecord.media·
Patients left in the dark months after cybercriminals leak testing lab data
Microsoft makes all new accounts passwordless by default
Microsoft makes all new accounts passwordless by default
Microsoft has announced that all new Microsoft accounts will be "passwordless by default" to secure them against password attacks such as phishing, brute force, and credential stuffing.
·bleepingcomputer.com·
Microsoft makes all new accounts passwordless by default
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs
A employee at Elon Musk's artificial intelligence company xAI leaked a private key on GitHub that for the past two months could have allowed anyone to query private xAI large language models (LLMs) which appear to have been custom made for…
·krebsonsecurity.com·
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs
Hacker 'NullBulge' pleads guilty to stealing Disney's Slack data
Hacker 'NullBulge' pleads guilty to stealing Disney's Slack data
A California man who used the alias "NullBulge" has pleaded guilty to illegally accessing Disney's internal Slack channels and stealing over 1.1 terabytes of internal company data.
·bleepingcomputer.com·
Hacker 'NullBulge' pleads guilty to stealing Disney's Slack data
More than 100,000 impacted by December data breach at Ascension Health
More than 100,000 impacted by December data breach at Ascension Health
Ascension Health revealed another security incident this week, warning more than 100,000 people in multiple states that their information was likely accessed by hackers late last year.
·therecord.media·
More than 100,000 impacted by December data breach at Ascension Health
Quantum computer threat spurring quiet overhaul of internet security | CyberScoop
Quantum computer threat spurring quiet overhaul of internet security | CyberScoop
Cryptography experts say the race to fend off future quantum-computer attacks has entered a decisive but measured phase, with companies quietly replacing the internet plumbing that the majority of the industry once considered unbreakable.
·cyberscoop.com·
Quantum computer threat spurring quiet overhaul of internet security | CyberScoop
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks
Russia-aligned hacktivists persistently target key public and private organizations in the Netherlands with distributed denial of service (DDoS) attacks, causing access problems and service disruptions.
·bleepingcomputer.com·
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks
Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape
Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape
Microsoft uncovered a vulnerability in macOS that could allow specially crafted codes to escape the App Sandbox and run unrestricted on the system. We shared our findings with Apple and a fix was released for this vulnerability, now identified as CVE-2025-31191. We encourage macOS users to apply security updates as soon as possible.
·microsoft.com·
Analyzing CVE-2025-31191: A macOS security-scoped bookmarks-based sandbox escape
Ukrainian extradited to US for Nefilim ransomware attacks
Ukrainian extradited to US for Nefilim ransomware attacks
A Ukrainian national has been extradited from Spain to the United States to face charges over allegedly conducting Nefilim ransomware attacks against companies.
·bleepingcomputer.com·
Ukrainian extradited to US for Nefilim ransomware attacks
Understanding the challenges of securing an NGO
Understanding the challenges of securing an NGO
Joe talks about how helping the helpers can put a fire in you and the importance of keeping nonprofits cybersecure.
·blog.talosintelligence.com·
Understanding the challenges of securing an NGO
Harrods the next UK retailer targeted in a cyberattack
Harrods the next UK retailer targeted in a cyberattack
London's iconic department store, Harrods, has confirmed it was targeted in a cyberattack, becoming the third major UK retailer to report cyberattacks in a week following incidents at M&S and the Co-op.
·bleepingcomputer.com·
Harrods the next UK retailer targeted in a cyberattack
State-of-the-art phishing: MFA bypass
State-of-the-art phishing: MFA bypass
Threat actors are bypassing MFA with adversary-in-the-middle attacks via reverse proxies. Phishing-as-a-Service tools like Evilproxy make these threats harder to detect.
·blog.talosintelligence.com·
State-of-the-art phishing: MFA bypass
US as a Surveillance State - Schneier on Security
US as a Surveillance State - Schneier on Security
Two essays were just published on DOGE’s data collection and aggregation, and how it ends with a modern surveillance state. It’s good to see this finally being talked about.
·schneier.com·
US as a Surveillance State - Schneier on Security
Claude Chatbot Used for Automated Political Messaging
Claude Chatbot Used for Automated Political Messaging
Anthropic has found its Claude chatbot is being used for automated political messaging, enabling AI-driven influence campaigns
·infosecurity-magazine.com·
Claude Chatbot Used for Automated Political Messaging
MY TAKE: RSAC 2025 – Conversing with vendors hanging out in the Marriott Marquis mezzanine
MY TAKE: RSAC 2025 – Conversing with vendors hanging out in the Marriott Marquis mezzanine
SAN FRANCISCO — Sometimes, the best insights come not from the keynote stage, but from the hotel lobby. Related: RSAC 2025 top takeaways In between sessions at RSAC 2025, I slipped over to the Marriott lobby and held quick, off-the-cuff interviews with a handful of cybersecurity vendors — each doing something genuinely different, often radical,
·lastwatchdog.com·
MY TAKE: RSAC 2025 – Conversing with vendors hanging out in the Marriott Marquis mezzanine