Cyber Security News
56.6K subscribers
203 photos
3 videos
114K links
Be Cyber Aware. Subscribe.

Our chat: t.me/cybersecuritynewschat

Our vacancies channel: @CyberSecurityJobs

LinkedIn: https://www.linkedin.com/company/securitynews/

📩 Collab: cybersecnewsinfo@gmail.com

Paid Ads: @cybersecadmin
Download Telegram
Ceva Logistics Breach Hits Banks, Retailers, and Steam Gamers

Shipping giant Ceva Logistics confirmed a cyberattack that breached eight European warehouses and stole customer data.

Exposed records include names, home addresses, phone numbers, and email addresses, rippling out to Dutch retailer Bol, De Bijenkorf, football club Ajax, banking giant ING, and Ace & Tate.

Valve discovered the breach on August 7 and warned Steam hardware customers, while Ceva said it activated security protocols as the investigation with authorities continues.

@Cyber_Security_Channel
6
Join the Webinar: Cybersecurity, Privacy and Data Protection Law in 2026.

Stay ahead of latest privacy regulations, understand legal impact of AI, and earn CPE credits.

Key Insights:

Global overview of new cyber, privacy & data protection laws

Recent regulatory developments in cybersec and AI

Compliance requirements and penalties

Personal liability of CISOs, executives & professionals

Practical strategies: reduce legal & regulatory risks

Cyber insurance pitfalls: how to avoid in 2026

Best practices: data breach investigation & disclosure

How ImmuniWeb helps organizations strengthen compliance 

📅 Date & Time: August 20, 2026

• Session 1: Geneva 10am | Dubai 12pm | Singapore 4pm
• Session 2: Geneva 5pm | New York 11am | California 8am

🎤 Host: Dr. Ilia Kolochenko, Founder, Chief Architect & CEO at ImmuniWeb.

Register: tap here to claim your spot.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
6🔥2
China-Linked JDY Botnet Scouts Networks for Rapid Exploitation

Lumen's Black Lotus Labs uncovered a resurgence of the China-nexus JDY botnet, spanning over 1,500 compromised SOHO and IoT devices.

The network scans and fingerprints targets to identify vulnerable infrastructure within hours of new vulnerability disclosures.

Compromised routers evade IP-based defenses while serving as distributed reconnaissance infrastructure.

Researchers found a particular focus on U.S. military-related networks, raising concerns over follow-on attacks.

@Cyber_Security_Channel
5👍2🤩1💯1
Cheaper Mid-Tier AI Models Show Sharp Rise in Hacking Skill

New research from XBOW revealed that mid-priced AI models like GLM-5.2, Grok 4.5, and Claude Opus 4.7 now perform strongly at real-world hacking tasks.

GPT-5.5 missed only 10% of vulnerabilities in testing, down sharply from GPT-5's 40% miss rate, and did best without source code access, mirroring real attacker conditions.

Researchers warned that because these models are far cheaper to run than frontier systems, attackers can query them repeatedly at scale, gaining an edge with no budget limits.

@Cyber_Security_Channel
8👏1
🌎 Prevent Critical Incidents with Early Knowledge about Emerging Attacks from 16K Orgs

Actionable threat intelligence is a №1 priority for modern SOCs, as it gives them the REAL advantage against attackers.

@anyrun_app TI Feeds provide leading companies with a live stream malware & phishing IPs, domains, and URLs from 16K SOCs and 700K analysts globally.

🎯 Early detection of campaigns launched in the previous 24 hours

🔎 Faster incident response with actionable sandbox reports for every IOC

🚨 Proactive threat blocking and containment that reduces attacker dwell time

For CISOs, this means turning global attack activity into an early-warning layer for your own security program.

Reduce risks from emerging threats for your company with TI Feeds → tap here and test the method today.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
4👀2
Four in Five Data Breach Cases go Unsolved as Cyberattacks Surge

Arrests have consistently lagged far behind incident counts.

The arrest rate stood at 20 percent (729 cases) in 2022, 28 percent (1,184 cases) in 2023, 21 percent (985 cases) in 2024 and 26 percent (1,265 cases) last year.

So far this year, only 544 arrests have been made out of 2,844 cases through June, pushing the arrest rate down to 19 percent — roughly one arrest for every five incidents.

Cyber_Security_Channel
5👍2🔥1👀1
AI Data Giant Alation Confirms Cyberattack

Alation, an AI-powered data intelligence platform serving about 500 enterprises including roughly half of the Fortune 1000, confirmed a cyberattack this week.

The incident began as service degradation before the company acknowledged unauthorized access to an isolated AWS-hosted system.

Alation has not said whether data was stolen or detailed the attack's cause.

It says it is investigating and will share updates as they become available.

@Cyber_Security_Channel
1👍1
Apollo Global Management Confirms Data Breach Amid Hacking Wave Targeting Financial Giants

Apollo Global Management, the private equity giant managing $938 billion in assets, has confirmed hackers stole personal data from its cloud systems.

Attackers used social engineering between July 6 and July 10 to steal names, birth dates, home addresses, and Social Security numbers.

The breach follows Google warnings that hackers have been extorting major private equity and financial firms, netting ransoms as high as $750,000.

Apollo has not disclosed how many people were affected or whether it paid a ransom.

@Cyber_Security_Channel
1🔥1👏1
Fake Crypto Conference Lure Targets Cybersecurity Researchers

Security firm Huntress disclosed a hacking campaign that targeted cybersecurity professionals around the Black Hat and Def Con conferences.

A hacker posing as a crypto news outlet approached researchers on X, then sent a rigged Google Doc with a fake encrypted sidebar built via Google Apps Script.

Victims who entered a bogus decryption key risked infostealer malware on macOS, a disguised remote-access tool on Windows, or a fake Ledger wallet installer.

@Cyber_Security_Channel
2
Cyberattack Disrupts Boston Scientific's Global Operations

Medical device maker Boston Scientific, which serves roughly 48 million patients a year, disclosed a cyberattack causing a "global disruption" to its operations, including its ability to ship and process orders.

The company said its investigation is ongoing with no timeline for restoring systems, and has not confirmed whether patient data or implanted devices such as pacemakers were affected.

The breach follows recent cyberattacks on fellow device makers Abbott, Medtronic, and Stryker.

@Cyber_Security_Channel
4
White House Bans Foreign-Made Power Equipment Over Backdoor Risks

President Trump signed an executive order banning certain foreign-made equipment from the U.S. bulk power grid over fears of hidden backdoors.

The order warns such gear could let foreign adversaries remotely access critical infrastructure and creates a dangerous supply-chain dependency.

The Defense, Commerce, and Energy Departments now have 120 days to review existing equipment, flag risky deployments, and draft rules targeting high-risk supplier countries.

@Cyber_Security_Channel
4
ATF Declares Major Incident After Ransomware Gang Claims Hack

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a "major incident" after a cyberattack hit a stand-alone system separate from its main network.

The Qilin ransomware gang claimed responsibility on its leak site without offering proof.

An ATF spokesperson said the breached system held information on the targets of ongoing investigations.

Federal law requires major incidents be reported to Congress within a week, following similar breaches at the FBI and U.S. Marshals Service.

News from earlier last week.

@Cyber_Security_Channel
👍32
FBI Warns of OAuth Consent Phishing Campaign Targeting Prominent People

The FBI warned that a phishing campaign has targeted prominent individuals, their families, and associates since late 2025.

Attackers impersonating officials, journalists, and event organizers use commercial messaging apps to trick victims into granting OAuth consent to legitimate Microsoft and Google accounts.

The resulting token bypasses passwords and MFA entirely, and can only be revoked by manually invalidating it in account security settings.

@Cyber_Security_Channel
4👍2
X Warns of Coordinated Attack Targeting User Accounts After X Money Launch

X disclosed that attackers are mass-triggering password reset emails using publicly available usernames in a coordinated attempt to hijack profiles.

The attack surge began right after the wide rollout of X Money, a new payment feature offering cashback and instant transfers via FDIC-insured accounts.

X said it found no evidence of successful breaches so far, is investigating, and urged users to enable two-factor authentication and Password Reset Protect.

@Cyber_Security_Channel
Sality Botnet Dismantled After 23-Year Run Infecting 11 Million Devices

CrowdStrike, the FBI, Europol, and authorities from Bulgaria, Hungary, and Romania dismantled the Sality botnet, a Russia-based peer-to-peer network active since 2003.

The operation targeted infected machines' peer lists, cutting them off from the operator's control.

Sality enabled cryptocurrency theft and cyberattacks on victims in the US and abroad, and was linked to three DDoS attacks.

Shadowserver is now working with ISPs to identify and remediate remaining infected devices.

@Cyber_Security_Channel
Darknet Marketplace Exposed Over 150 Million US and Canadian IDs

A darknet marketplace called Nexus exposed more than 153 million US and Canadian driver's licenses alongside millions of ID cards, travel documents, and medical cards.

The data reportedly originated from identity-verification firm IDScan[.]net, though the company has not confirmed the breach.

Samples included records belonging to the US Defense Secretary and an FBI assistant director.

The marketplace went offline shortly after the leak was reported, and the FBI is now investigating.

@Cyber_Security_Channel
🔥2👍1
OpenAI Confirms AI Agents Hijacked a German Wiki Forum

OpenAI confirmed that its AI agents escaped a testing environment and hijacked a German wiki forum, using it as a message board for other agents.

The admission follows reports that OpenAI sat on the incident for weeks while handling a separate breach in which its agents compromised Hugging Face's servers, now under investigation by California's Attorney General.

OpenAI said it is now building a disclosure framework, acknowledging the industry lacks standards for reporting when AI systems behave unexpectedly.

@Cyber_Security_Channel
👀31
🔍 What Did August’s Major Cyber Attacks Reveal About Business Risk in the US and EU?

@anyrun_app's August threat roundup highlights:

🌎 A US-first RMM campaign spanning 46 countries, with 45% of activity in the US

🔐 Mirage2FA linked to 4,000+ US victims

📄 Fake business documents used to deliver credential-stealing malware

👤 Lazarus APT’s IT Workers infiltrating companies through fake remote identities

These incidents show how trusted business activity can put revenue, operations, sensitive data, and customer trust at risk.

Prepare your SOC for these attack patterns: tap here to discover how to respond faster.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
6👍4
House Committee Report Finds Chinese Telecoms Still Embedded in US Networks

A bipartisan House Select Committee on China report disclosed that China Mobile, China Unicom, and China Telecom remain embedded in U.S. internet infrastructure despite a federal ban.

The FCC revoked the state-owned carriers' authority to operate in the country over national security concerns, but their equipment and network ties were never fully removed.

Lawmakers warned this lingering access could let Beijing monitor or disrupt American communications networks.

@Cyber_Security_Channel
Looking for the Best Threat Intelligence Platform in 2026?

Choosing the right CTI platform can be challenging with so many options available.

We’ve compared the top threat intelligence platforms in 2026, looking at key capabilities, use cases, integrations, intelligence coverage, automation, and more.

See which platforms made the list and find the right fit for your security team.

Read the full comparison → click here for access.

-----

#ThreatIntel #Cybersecurity #ThreatIntelligence

@Cyber_Security_Channel
4