Cybersecurity

12 readers
3 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS
101
 
 

Report on the Malicious Uses of #AI

https://www.schneier.com/blog/archives/2025/06/report-on-the-malicious-uses-of-ai.html

#OpenAI #ChatGPT #cybersecurity

102
 
 

New #PathWiper data wiper #malware hits critical infrastructure in #Ukraine

https://www.bleepingcomputer.com/news/security/new-pathwiper-data-wiper-malware-hits-critical-infrastructure-in-ukraine/

#cybersecurity

103
 
 

Critical #Fortinet flaws now exploited in #Qilin #ransomware attacks

https://www.bleepingcomputer.com/news/security/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/

#cybersecurity

104
 
 

"We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users. We found that native Android apps—including Facebook, Instagram, and several Yandex apps including Maps and Browser—silently listen on fixed local ports for tracking purposes.

These native Android apps receive browsers' metadata, cookies and commands from the Meta Pixel and Yandex Metrica scripts embedded on thousands of web sites. These JavaScripts load on users' mobile browsers and silently connect with native apps running on the same device through localhost sockets. As native apps access programatically device identifiers like the Android Advertising ID (AAID) or handle user identities as in the case of Meta apps, this method effectively allows these organizations to link mobile browsing sessions and web cookies to user identities, hence de-anonymizing users' visiting sites embedding their scripts.

This web-to-app ID sharing method bypasses typical privacy protections such as clearing cookies, Incognito Mode and Android's permission controls. Worse, it opens the door for potentially malicious apps eavesdropping on users’ web activity."

https://localmess.github.io/

#CyberSecurity #Android #Meta #Yandex #Surveillance #Privacy #DataProtection #GDPR #MobileApps

105
 
 

"On Thursday, the findings of the parliamentary committee investigating Italy's usage of the spyware were published, in a rare incident of a Western state shedding light into a usually secretive world of intelligence agencies and covert surveillance.
The committee confirmed that Paragon provided Graphite to two Italian agencies, including the country's external intelligence service, starting in 2023. The version of Graphite provided did not include the ability to activate the phone's microphone or camera, the report said.

Instead, it only enabled its operators access to encrypted communications on the hacked devices. The report also confirmed that Graphite exploited a vulnerability in WhatsApp that Meta identified and patched in December 2024, one month before the spyware's activity was publicly disclosed.

The vulnerability's discovery also caused "panic" at Israel's military intelligence Unit 8200, according to the recent Israeli television report.

The Italian committee also confirmed Meta's claim that several activists involved in migrant rights in Italy had their phones hacked, including Luca Casarini, Giuseppe Caccia, and David Yambio – though in Yambio's case, the hack was carried out not by Graphite but by another unnamed spyware."

https://www.haaretz.com/israel-news/security-aviation/2025-06-05/ty-article/.premium/italy-admits-activists-were-hacked-with-israeli-spyware-but-not-journalists/00000197-3ff4-d079-ab97-7ff5bd8a0000

#EU #Italy #CyberSecurity #Surveillance #Privacy #Spyware #Paragon #Graphite #Israel

106
 
 

#Proxy Services Feast on #Ukraine’s IP Address Exodus

https://krebsonsecurity.com/2025/06/proxy-services-feast-on-ukraines-ip-address-exodus/

#cybercrime #cybersecurity #Russia #politics

107
 
 

#Italy Admits Hacking Activists With Israeli #Spyware #Paragon

https://archive.ph/Ocm8S

#cybersecurity #privacy #politics

108
 
 

Hacker selling critical #Roundcube #webmail exploit as tech info disclosed

https://www.bleepingcomputer.com/news/security/hacker-selling-critical-roundcube-webmail-exploit-as-tech-info-disclosed/

#cybersecurity

109
 
 

What Really Happened in the Aftermath of the #LizardSquad Hacks

https://www.wired.com/story/ctrl-alt-chaos-joe-tidy-book-excerpt/

#cybercrime #cybersecurity #gaming #PSN #PlayStation #PlayStationNetwork

110
 
 

#ViLE gang members sentenced for #DEA portal breach, extortion

https://www.bleepingcomputer.com/news/security/vile-gang-members-sentenced-for-breaching-law-enforcement-portal/

#cybercrime #cybersecurity

111
 
 

#Interlock #ransomware claims #KetteringHealth breach, leaks stolen data

https://www.bleepingcomputer.com/news/security/interlock-ransomware-claims-kettering-health-breach-leaks-stolen-data/

#cybersecurity #privacy #DataBreach #healthcare

112
 
 

US offers $10M for tips on state hackers tied to #RedLine #malware

https://www.bleepingcomputer.com/news/security/us-offers-10m-for-tips-on-state-hackers-tied-to-redline-malware/

#cybersecurity

113
 
 
114
 
 

FBI: #Play #ransomware breached 900 victims, including critical orgs

https://www.bleepingcomputer.com/news/security/fbi-play-ransomware-breached-900-victims-including-critical-orgs/

#cybercrime #cybersecurity

115
 
 

Hacker arrested for breaching 5,000 hosting accounts to mine #crypto

https://www.bleepingcomputer.com/news/security/hacker-arrested-for-breaching-5-000-hosting-accounts-to-mine-crypto/

#cybersecurity #cybercrime

116
 
 

#Cisco warns of #ISE and #CCP flaws with public exploit code

https://www.bleepingcomputer.com/news/security/cisco-warns-of-ise-and-ccp-flaws-with-public-exploit-code/

#cybersecurity

117
 
 

#Ukraine claims it hacked #Tupolev, #Russia’s strategic warplane maker

https://www.bleepingcomputer.com/news/security/ukraine-claims-it-hacked-tupolev-russias-strategic-warplane-maker/

#cybersecurity #politics

118
 
 

FBI warns of #NFT #AirDrop scams targeting #HederaHashgraph wallets

https://www.bleepingcomputer.com/news/security/fbi-warns-of-nft-airdrop-scams-targeting-hedera-hashgraph-wallets/

#crypto #cybersecurity

119
 
 

Hackers target #Salesforce accounts in data extortion attacks

https://www.bleepingcomputer.com/news/security/google-hackers-target-salesforce-accounts-in-data-extortion-attacks/

#cybersecurity

120
 
 

Hacker targets other hackers and gamers with backdoored #GitHub code

https://www.bleepingcomputer.com/news/security/hacker-targets-other-hackers-and-gamers-with-backdoored-github-code/

#cybersecurity #gaming

121
 
 

Wired's "You're Not Ready," A collection of articles about current cyber threats

https://www.wired.com/youre-not-ready/

#cybersecurity #QuantumComputers AI #PQE #infrastructure #Meshtastic

122
 
 

4 ways to protect your digital identity in 2025.

https://tuta.com/blog/how-to-protect-digital-identity

#cybersecurity #guide

123
 
 

Hewlett Packard Enterprise warns of critical #StoreOnce auth bypass

https://www.bleepingcomputer.com/news/security/hewlett-packard-enterprise-warns-of-critical-storeonce-auth-bypass/

#HPE #cybersecurity

124
 
 

Phone chipmaker #Qualcomm fixes three zero-days exploited by hackers

https://techcrunch.com/2025/06/03/phone-chipmaker-qualcomm-fixes-three-zero-days-exploited-by-hackers/

#cybersecurity

125
 
 

Indian #grocery startup #KiranaPro was hacked and its servers deleted, CEO confirms

https://techcrunch.com/2025/06/03/indian-grocery-startup-kiranapro-was-hacked-and-its-servers-deleted-ceo-confirms/

#India #cybersecurity

view more: ‹ prev next ›