tgindex
Cyber Security News

Cyber Security News

Статистика

Be Cyber Aware. Subscribe. Our chat: t.me/cybersecuritynewschat Our vacancies channel: @CyberSecurityJobs LinkedIn: https://www.linkedin.com/company/securitynews/ 📩 Collab: cybersecnewsinfo@gmail.com Paid Ads: @cybersecadmin

Последний пост
13 авг.
Последнее чтение
15 авг.
Постов за неделю
3
Всего постов
31
Тип
открытый
Язык
und
Категория
Новости и СМИ
В каталоге с
13 авг.
Подписчики
56 365
+45 за 3 дн.
Сутки
+9
+0,02%
Неделя
 
Месяц
 
Просмотров на пост
4 668
31 постов
Вовлечённость
8,3%
к подписчикам
Постов в день
0,4
всего 31
Упоминаний
2
каналов
Охват размещения
оценка
1/24сутки в ленте
1 871
1/48двое суток
2 144
1/72трое суток
2 312

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • 13 авг.1 76546

    Join the Webinar: Cybersecurity, Privacy and Data Protection Law in 2026. Stay ahead of latest privacy regulations, understand legal impact of AI, and earn CPE credits. ⚡ Key Insights: ✔ Global overview of new cyber, privacy & data protection laws ✔ Recent regulatory developments in cybersec and AI ✔ Compliance requirements and penalties ✔ Personal liability of CISOs, executives & professionals ✔ Practical strategies: reduce legal & regulatory risks ✔ Cyber insurance pitfalls: how to avoid in 2026 ✔ Best practices: data breach investigation & disclosure ✔ How ImmuniWeb helps organizations strengthen compliance  📅 Date & Time: August 20, 2026 • Session 1: Geneva 10am | Dubai 12pm | Singapore 4pm • Session 2: Geneva 5pm | New York 11am | California 8am 🎤 Host: Dr. Ilia Kolochenko, Founder, Chief Architect & CEO at ImmuniWeb. ✅ Register: tap here to claim your spot. ----- #ad #paidpromotion #sponsored @Cyber_Security_Channel

  • 12 авг.2 11043

    Ceva Logistics Breach Hits Banks, Retailers, and Steam Gamers Shipping giant Ceva Logistics confirmed a cyberattack that breached eight European warehouses and stole customer data. Exposed records include names, home addresses, phone numbers, and email addresses, rippling out to Dutch retailer Bol, De Bijenkorf, football club Ajax, banking giant ING, and Ace & Tate. Valve discovered the breach on August 7 and warned Steam hardware customers, while Ceva said it activated security protocols as the investigation with authorities continues. @Cyber_Security_Channel

  • 11 авг.2 5041019

    🎥 Smile, You’re on Camera! North Korean IT Workers Got Hired and Exposed Live Researchers created a fake company, hired suspected DPRK operatives linked to Lazarus Group, and watched their activity unfold inside controlled @anyrun_app Sandbox environments. Along the way, they uncovered: 🪪 Fake IDs and stolen identities 🖥️ Remote access tools and system reconnaissance 🤖 AI-assisted coding and document alteration 🌐 VPN and VPS infrastructure 🔐 Shared 2FA services, crypto wallets, and account activity A must-read for any company that doesn’t want its next remote hire to be a spy. Read the full investigation – tap here to access the article. ----- #ad #paidpromotion #sponsored @Cyber_Security_Channel

  • 8 авг.3 74824

    Framework Discloses Data Breach via Metabase Zero-Day Framework notified customers that a zero-day flaw in vendor Metabase let attackers into its cloud database, the company disclosed Thursday. The breach exposed names, emails, phone numbers, and addresses, though payment data was untouched. A spokesperson would not give an exact count, confirming only that "all customers" were hit among Framework's hundreds of thousands of buyers. Metabase said it blocked the malicious endpoints and patched the underlying SQL injection bug. @Cyber_Security_Channel

  • 7 авг.3 77536

    The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem Attack surface expansion is frequently framed as a tooling gap, but the evidence points elsewhere — toward a persistent, structural failure in attack surface discovery, asset discovery, and visibility. Cyber_Security_Channel

  • 4 авг.5 045138

    Apple Challenges UK Government's iCloud Backdoor Demand Apple has filed a legal complaint against the UK government over a secret order demanding backdoor access to encrypted iCloud data. The company brought the case to the UK's Investigatory Powers Tribunal, which hears government surveillance disputes. The challenge targets a technical capability notice issued last year that would force Apple to grant access to encrypted user data on demand. The clash follows Apple's 2025 decision to pull Advanced Data Protection for UK users rather than build in a backdoor. @Cyber_Security_Channel

  • 2 авг.4 86663

    CareCloud Breach Exposes Medical Records of 345,000 Patients U.S. health tech giant CareCloud has confirmed that hackers stole patient data from one of its AWS-hosted health record stores. New regulatory filings show the intrusion, which ran from March 10 to 16, has affected at least 345,000 people across the U.S. so far. Stolen data includes names, Social Security numbers, passport and driver's license numbers, and financial account details. CareCloud stores records for more than 45,000 healthcare providers, and no ransomware group has claimed responsibility. @Cyber_Security_Channel

  • 31 июл.4 650118

    July 2026 in Cyber: AI Agents Went on Offense, Vuln Loads Broke Records Autonomous AI agents showed up on both sides — Hugging Face was breached by an external agent looping through a swarm of sandboxes, and AgentBaiting seeded 800+ fake AI skills and MCP servers pushing SmartLoader. Microsoft dropped 622 CVEs in one Patch Tuesday — triple June's record, plus zero-days in AD FS and SharePoint. WordPress «wp2shell» RCE and a Windows «LegacyHive» privilege escalation piled on. SonicWall SMA1000, ShareFile, and 11 Microsoft-signed Linux UEFI shims were all exploited or exposed pre-patch. Qilin ransomware weaponized a critical Palo Alto GlobalProtect bug; Coca-Cola paused Fairlife dairy; two Scattered Spider members got 5.5 years each for the £29M TfL breach. @Cyber_Security_Channel

  • 30 июл.4 406510

    Microsoft Patch Tuesday: 622 CVEs, «the mother of all» Releases Microsoft disclosed 622 vulnerabilities in July — triple Junes previous record of 206 — including 63 critical and two exploited zero-days (CVE-2026-56155 in AD FS, CVE-2026-56164 in SharePoint Server). Breakdown: 416 in Windows, 82 in Office, 46 in Edge; Trend Micros Dustin Childs called it «the mother of all releases». Analysts credit AI-powered bug discovery — 2026 could top 2,000-3,000 CVEs, blowing past the 1,245 full-year record from 2020. @Cyber_Security_Channel

  • 28 июл.4 852123

    🤝 Cyber Security News is looking for ADVERTISERS Our community is continuously growing and we are searching for exciting companies & products to share with our audience. Requirements to Qualify • Relevant to channels niche / industry • Long-term approach and collaboration mindset • $2,000+ monthly ad spend budget to invest in campaigns What We Offer • Exposure to 80,000+ community members • Personal success manager to scale your campaigns • Brand awareness, leads, sign-ups, customers, followers, etc. 📩 Contact for Partnership If you are serious about promoting your business, send us an introduction Email → cybersecnewsinfo@gmail.com Important Note Spots to become a sponsor are limited. Reach out before they fill up. (we only have 6 left) - - - - - @Cyber_Security_Channel

  • 27 июл.5 09167

    AgentBaiting: 800 Fake AI skills and MCP Servers Seed SmartLoader Malware Island researchers uncovered ~7,600 malicious repos from ~6,600 fake profiles, 800+ posing as AI skills or MCP servers. ZIP archives disguised as installers deliver SmartLoader, which injects StealC — pulling browser sessions, tokens, API creds, and screenshots. Around 200 campaign repos accounted for over 14 million downloads before takedown. @Cyber_Security_Channel

  • 26 июл.4 9651

    ClickLock macOS Malware Hostage-takes Users Until They Type Their Password Group-IB documented ClickLock, a macOS stealer delivered via a ClickFix «Cloudflare human verification» lure that runs a malicious Terminal command. It shows a fake password dialog with the victims real username; if refused, it kills Finder and Terminal every 210 ms for up to 83 hours until the password is entered. After that it grabs credentials, browser data, crypto wallet extensions, FileZilla configs and shell history, then self-deletes — ~100 infections across 33 countries since May. @Cyber_Security_Channel

  • 25 июл.5 5661410

    1Password Partners with Anthropic to Give Claude Access to Your Credentials 1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values. Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself. Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies. @Cyber_Security_Channel

  • 22 июл.5 6371013

    🔍 What if the Phishing Page that Steals Access Never Appears in the Security Scan you Trust? Ghost Phishing can keep real lure hidden until the victim’s browser decrypts and renders it. Static analysis may return a clean result while the user is already interacting with a fully active phishing page. This risk can be reduced with browser-level visibility. ANY.RUN helps security teams see what actually happens in the browser, including: 👻 Decrypted phishing content as it appears 🧩 Runtime DOM changes and hidden page elements 🌐 Requests and redirects behind the attack ⚡ Clear evidence for faster triage and response Don’t let hidden phishing activity go unseen. Get full visibility with ANY.RUN → click here to enhance security now. ----- #ad #paidpromotion #sponsored @Cyber_Security_Channel

  • 21 июл.5 27837

    ⚡️Hugging Face Hacked in Autonomous AI Attack Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected…

  • 21 июл.4 7847

    ⚡️Hugging Face Hacked in Autonomous AI Attack Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected nodes, and revoked and rotated all affected credentials. Cyber_Security_Channel

  • 18 июл.5 9254

    FortiBleed campaign traced to INC and Lynx ransomware operations “The Nextcloud issue appears to have been used as part of the attackers’ broader operational workflow, likely for expansion or infrastructure access after initial compromise,” Ensar Seker, CISO at SOCRadar, told Cybersecurity Dive. Cyber_Security_Channel

  • 16 июл.6 05139

    Join the Webinar: Vulnerability Detection with AI, explore how AI is transforming the industry, understand the latest application security challenges, earn CPE credits, and gain practical insights from cybersecurity experts. ⚡ Key Insights: ✔ New threats from vibe coding ✔ Risks of AI to automate coding ✔ OWASP Top 10 for LLMs brief overview of ✔ Frequent application security pitfalls ✔ Implementation of risk-based application security program ✔ Automation of mobile & web security scanning with CI/CD pipeline ✔ Mobile application security scanning with Neuron Mobile ✔ Mastering web application & API security scanning with Neuron ✔ AI for automation of application security testing 📅 Date & Time: July 23, 2026 • Session 1 – Geneva 10am | Dubai 12pm | Singapore 4pm • Session 2 – Geneva 5pm | New York 11am | California 8am 🎤 Host: Dr. Ilia Kolochenko, Founder, Chief Architect & CEO at ImmuniWeb. ✅ Register: click here for sign up access. ----- #ad #paidpromotion #sponsored @Cyber_Security_Channel

  • 14 июл.5 98711

    Pegasus Infected Phone of EU Lawmaker Investigating Spyware Abuse Citizen Lab confirmed with high confidence that Stelios Kouloglou — a Greek MEP and substitute member of the European Parliament's PEGA Committee, which was set up to probe NSO Group's Pegasus abuses — was infected with the spyware twice, in October 2022 and March 2023. The first infection came while he was hospitalized; the second during the committee's final drafting phase. Attribution remains open, NSO did not respond, and Kouloglou announced plans to sue. @Cyber_Security_Channel

  • 12 июл.6 36078

    FortiBleed Credential-Harvesting Op Tied to INC and Lynx Ransomware Groups Researchers linked FortiBleed, a Golang-based tool that intercepts authentication traffic on Fortinet devices, to INC and Lynx ransomware operations — an operator was found logged into negotiation panels for both. Traffic-sniffing was observed on ~19,000 Fortinet devices; attackers gained admin access on 409 targets, fully compromised 354, and deployed ransomware on 12 — encrypting hundreds of endpoints. Some intrusions also leveraged a suspected zero-day in Nextcloud; no CVE has been assigned yet. @Cyber_Security_Channel

Cyber Security News — tgindex