Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29735 bookmarks
Custom sorting
Navigating Through The Fog
Navigating Through The Fog
Key Takeaways An open directory associated with a ransomware affiliate, likely linked to the Fog ransomware group, was discovered in December 2024. It contained tools and scripts for reconnaissance…
·thedfirreport.com·
Navigating Through The Fog
WooCommerce admins targeted by fake security patches that hijack sites
WooCommerce admins targeted by fake security patches that hijack sites
A large-scale phishing campaign targets WooCommerce users with a fake security alert urging them to download a "critical patch" that adds a Wordpress backdoor to the site.
·bleepingcomputer.com·
WooCommerce admins targeted by fake security patches that hijack sites
Brave's Cookiecrumbler tool taps community to help block cookie notices
Brave's Cookiecrumbler tool taps community to help block cookie notices
Brave has open-sourceed a new tool called "Cookiecrumbler," which uses large language models (LLMs) to detect cookie consent notices and then community-driven reviews to block those that won't break site functionality.
·bleepingcomputer.com·
Brave's Cookiecrumbler tool taps community to help block cookie notices
MY TAKE: Notes on how GenAI is shifting tension lines in cybersecurity on the eve of RSAC 2025
MY TAKE: Notes on how GenAI is shifting tension lines in cybersecurity on the eve of RSAC 2025
SAN FRANCISCO -- The first rule of reporting is to follow the tension lines—the places where old assumptions no longer quite hold. Related: GenAI disrupting tech jobs I’ve been feeling that tension lately. Just arrived in the City by the Bay. Trekked here with some 40,000-plus cyber security pros and company execs flocking to RSAC
·lastwatchdog.com·
MY TAKE: Notes on how GenAI is shifting tension lines in cybersecurity on the eve of RSAC 2025
Top 10 Malware Q1 2025
Top 10 Malware Q1 2025
In Q1 2025, the Top 10 Malware observed via the MS-ISAC® changed slightly from the previous quarter. Read our blog post to learn more.
·cisecurity.org·
Top 10 Malware Q1 2025
What Is the New Trusted AI Safety Knowledge Certification? | CSA
What Is the New Trusted AI Safety Knowledge Certification? | CSA
CSA and Northeastern University’s Trusted AI Safety Knowledge Certification Program trains professionals to build, secure, and manage AI responsibly across its lifecycle.
·cloudsecurityalliance.org·
What Is the New Trusted AI Safety Knowledge Certification? | CSA
Friday Squid Blogging: Squid Facts on Your Phone - Schneier on Security
Friday Squid Blogging: Squid Facts on Your Phone - Schneier on Security
Text “SQUID” to 1-833-SCI-TEXT for daily squid facts. The website has merch. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
·schneier.com·
Friday Squid Blogging: Squid Facts on Your Phone - Schneier on Security
Windows 11 KB5055627 update released with 30 new changes, fixes
Windows 11 KB5055627 update released with 30 new changes, fixes
​​Microsoft has released the KB5055627 preview cumulative update for Windows 11 24H2 with many new features gradually rolling out, and some new bug fixes for everyone.
·bleepingcomputer.com·
Windows 11 KB5055627 update released with 30 new changes, fixes
Craft CMS RCE exploit chain used in zero-day attacks to steal data
Craft CMS RCE exploit chain used in zero-day attacks to steal data
Two vulnerabilities impacting Craft CMS were chained together in zero-day attacks to breach servers and steal data, with exploitation ongoing, according to CERT Orange Cyberdefense.
·bleepingcomputer.com·
Craft CMS RCE exploit chain used in zero-day attacks to steal data
To Catch A Thief | Rubrik
To Catch A Thief | Rubrik
For this special live recording of To Catch a Thief at The New York Stock Exchange, host and former lead cybersecurity and digital espionage reporter for The...
·youtu.be·
To Catch A Thief | Rubrik
Largest telecom in Africa warns of cyber incident exposing customer data
Largest telecom in Africa warns of cyber incident exposing customer data
MTN Group said an “unknown third-party has claimed to have accessed data linked” to parts of its system and that the incident “resulted in unauthorised access to personal information of some MTN customers in certain markets.”
·therecord.media·
Largest telecom in Africa warns of cyber incident exposing customer data