#InfosecNews

β„΅β‚€ πŸ³οΈβ€βš§οΈπŸ΄β€β˜ οΈnull_aleph
2025-04-16

theregister.com/2025/04/16/hom

Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program

Because vulnerability management has nothing to do with national security, right?

B'ad Samurai 🐐badsamurai@infosec.exchange
2025-04-04

Not sure if this git repo owner is on Fedi, but I'm really happy with this RSS infosec news feed. So, thank you!

raw.githubusercontent.com/Endl

#infosecnews

Opalsec :verified:Opalsec@infosec.exchange
2025-04-03

Staying ahead means staying informed, right? Here's our latest wrap of the day's Cyber News:

πŸ—žοΈ opalsec.io/daily-news-update-t

If you're short on time, here’s a quick whip-around of the top 3 stories of note:

πŸ•΅οΈβ€β™‚οΈ Hunters Ransomware Rethink: Is the heat getting too much? Hunters International leadership reportedly told affiliates ransomware is now too "risky," planning a shift to pure data theft/extortion under a "World Leaks" banner. While their current status is murky, this potential pivot away from encryption echoes moves by other groups and highlights how defensive pressures are forcing attacker evolution – something we all need to track.

πŸ“§ White House OpSec Woes: Remember that recent White House Signal mishap? Well, now the same National Security Adviser is reportedly facing heat for using personal Gmail for sensitive (if unclassified) government discussions, raising serious OpSec and compliance alarms. It's a potent reminder for us all: even seemingly benign comms on personal platforms can create significant risks, and basic security hygiene is non-negotiable, especially when sensitive info is involved.

πŸ“ž Verizon API Call Log Leak: Here’s a worrying find: a simple API flaw in Verizon's Call Filter app exposed the incoming call history of potentially all their wireless customers to each other. Technically, it was a textbook case of broken object-level authorization – the API didn't check if the user's token matched the phone number whose logs were requested in a header. This highlights the critical need for robust API authorization checks and the significant privacy impact even call metadata can have.

Have a read of the full newsletter, and sign up to get all the details straight to your inbox each day:

πŸ“¨ opalsec.io/daily-news-update-t

#CyberSecurity #InfoSec #ThreatIntel #Ransomware #DataBreach #DataLeak #Vulnerability #APIsecurity #CloudSecurity #SupplyChainSecurity #Malware #Privacy #CyberAttack #InfoSecNews #ThreatHunting #CISCO #Verizon #GitHub #NationalSecurity #AndroidSecurity #EDR #CyberAwareness

Opalsec :verified:Opalsec@infosec.exchange
2025-03-25

Hey folks, ready for your daily dose of cyber intel? β˜•οΈ

Tuesday's update is out and it's packed with need-to-know updates:

🚨 Critical Next.js Flaw: Authorization bypass vulnerability (CVE-2025-29927) impacting versions before 15.2.3. Upgrade ASAP or block those 'x-middleware-subrequest' headers!

🐜 Weaver Ant's Long Game: Chinese hackers spied on a telco network for four years using compromised Zyxel routers and custom web shells. Talk about persistence!

🐍 VanHelsing RaaS Emerges: A new ransomware player targeting Windows, ARM, ESXi systems. Keep an eye on this one!

☁️ Oracle Cloud Breach Claims: Did they or didn't they? Oracle denies a breach, but a threat actor is claiming otherwise.

πŸš‚ Ukrainian Railway Hit: Cyberattack disrupts online ticket sales amidst crucial transport operations. Resilience is key.

πŸ”„ DrayTek Router Chaos: ISPs are scrambling as DrayTek routers enter reboot loops. Potential vulnerability or buggy update at play.

πŸ€– AI-Enhanced Cybercrime: Europol warns that organized crime is leveling up with AI, partnering with state-aligned entities.

πŸ›°οΈ Starlink Intercepted: Thai authorities seize Starlink transmitters headed for Myanmar scam centers. Criminals are finding ways around cut-offs.

πŸš“ Cybercrime Crackdown: 300+ suspects arrested in Africa for cyber scams. A win for international law enforcement!

🧬 23andMe's Bankruptcy Woes: Privacy advocates raise concerns about DNA data as 23andMe files for bankruptcy. What happens to all that genetic info?

πŸ”’ Pennsylvania County Ransomware: Sensitive data stolen during a ransomware attack. Another reminder to shore up those defenses.

πŸ‘οΈβ€πŸ—¨οΈ China Bans Facial Recognition: Consent is now required for facial recognition in China. But are there exceptions for government and AI training?

πŸ‘‰ Dive into the full details here: opalsec.io/daily-news-update-t

Stay vigilant, stay informed, and let's keep the digital world a little safer, one update at a time. πŸ›‘οΈ

#Cyber #CyberSec #Cybersecurity #InfoSec #ThreatIntelligence #ThreatIntel #Ransomware #NextJS #China #AI #Cybercrime #DataBreach #Privacy #Starlink #Europol #Vulnerability #WeaverAnt #VanHelsing #OracleCloud #Ukraine #DrayTek #23andMe #CyberAttack #infosecurity #Privacy #DataPrivacy #AI #InfoSecNews #News

2024-12-27

FYI: From THE Doctor: πŸ”΄ Dec 19's Top Cyber News NOW! - Ep 775 youtube.com/watch?v=T4TONhs5o- ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-27

ICYMI: From THE Doctor: πŸ”΄ Dec 24's Top Cyber News NOW! - Ep 778 youtube.com/watch?v=lCF4UwPPtJ ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-27

From THE Doctor: πŸ”΄ Dec 30's Top Cyber News NOW! - Ep 781 youtube.com/watch?v=Wh95nCuHB0 ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-26

FYI: From THE Doctor: πŸ”΄ Dec 13's Top Cyber News NOW! - Ep 771 youtube.com/watch?v=9gYbdv-YLW ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-26

ICYMI: From THE Doctor: πŸ”΄ Dec 19's Top Cyber News NOW! - Ep 775 youtube.com/watch?v=T4TONhs5o- ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-26

From THE Doctor: πŸ”΄ Dec 24's Top Cyber News NOW! - Ep 778 youtube.com/watch?v=lCF4UwPPtJ ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-25

FYI: From THE Doctor: Why Cybersecurity Certs Are BROKEN in 2024 | Industry Expert Jason Dion Reveals The Spicy Truth youtube.com/watch?v=BXA7OMWTue ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-25

ICYMI: From THE Doctor: πŸ”΄ Dec 13's Top Cyber News NOW! - Ep 771 youtube.com/watch?v=9gYbdv-YLW ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-25

From THE Doctor: πŸ”΄ Dec 19's Top Cyber News NOW! - Ep 775 youtube.com/watch?v=T4TONhs5o- ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-24

FYI: From THE Doctor: πŸ”΄ Dec 20's Top Cyber News NOW! - Ep 776 youtube.com/watch?v=5jKhwVpSll ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-24

ICYMI: From THE Doctor: Why Cybersecurity Certs Are BROKEN in 2024 | Industry Expert Jason Dion Reveals The Spicy Truth youtube.com/watch?v=BXA7OMWTue ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-24

From THE Doctor: πŸ”΄ Dec 13's Top Cyber News NOW! - Ep 771 youtube.com/watch?v=9gYbdv-YLW ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

2024-12-23

FYI: From THE Doctor: πŸ”΄ Dec 27's Top Cyber News NOW! - Ep 780 youtube.com/watch?v=xI7lobDrff ( :-{Δ±β–“ #SimplyCyber #GeraldAuger #infosecnews

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst