Cyber Security News
55.1K subscribers
172 photos
3 videos
113K links
Be Cyber Aware.

Our chat: t.me/cybersecuritynewschat

Our vacancies channel: @CyberSecurityJobs

LinkedIn: https://www.linkedin.com/company/securitynews/

Improve Your Cyber Skills: https://linktr.ee/cybersecuritynews

📩 Cooperation: @cybersecadmin
Download Telegram
Cybersecurity in Medical Devices: From Insight to Action

A central theme of the session was the critical role of penetration testing in ensuring medical device security.

Unlike traditional IT testing, medical device pentesting covers a much broader spectrum — from embedded hardware and firmware through industry specific communication interfaces and protocols, to cloud services and hospital network integration.

By embedding penetration testing across all stages of medical device development, deployment, and maintenance, manufacturers can confidently bring secure innovations to market — protecting both patients and the integrity of digital healthcare systems.

Cyber_Security_Channel
7
🚨 CastleLoader Attacks Government Agencies, Compromising up to 400+ Devices at Once

Its unusual process hollowing via an AutoIt3 script is hard for EDR to detect.

See full analysis from #ANYRUN with extracted runtime config, C2s, and #IOCs 👇

Read the full blog article — click here.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
4
The 5 Critical Cybersecurity Controls Every Organization Needs

Administrative accounts represent your organization’s “keys to the kingdom”.

Regular reviews ensure that only necessary personnel have elevated privileges.

Failure to minimize admin accounts and/or eliminate shared accounts can lead to accountability issues during security incidents.

Ensuring all activities are logged and traceable to a single user aids investigations and deters potential compromises.

Cyber_Security_Channel
3👍3🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
ℹ️ Join ImmuniWeb AI Platform 2026 Webinar: New Products and Capabilities to enhance your ImmuniWeb® AI Platform skills, earn CPE credits, and qualify to become ImmuniWeb® Certified Professional.

✔️ Key Insights that Will be Covered:

• Useful and novel product features, functionalities and integrations
• New cybersecurity and compliance products by ImmuniWeb
• Practical use of ML and AI by ImmuniWeb in year 2026
• Cybersecurity cost reduction with ImmuniWeb
• Cybersecurity compliance with ImmuniWeb
• Live demo of ImmuniWeb AI Platform
• Full 2026 product map

Date & Time: January 29 at 10am and 5pm CET

Host: Dr. Ilia Kolochenko, CEO & Chief Architect at ImmuniWeb, Attorney-at-Law.

Register Now:

Session 1 – January 29, 2026 – Geneva 10am | Dubai 1pm | Singapore 5pm

👉 Click here.

Session 2 – January 29, 2026 – Geneva 5pm | New York 11am | California 8am

👉 Click here.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
2👍2
120 Data Breach Statistics for 2026

So, here are the 120 data breach stats for 2025.

All the sources we mentioned applies its own methodology, so numbers vary, and we include them all so readers can judge for themselves.

Cyber_Security_Channel
👍21
❗️Cyber Security News is looking for VOLUNTEERS to join our Team: Round 5

Our community is continuously growing and we are looking to further expand the internal Team of Content Authors.

Responsibilities

• Browse news on Internet
• Format and publish posts to the channels of our community
• Offer creative ideas to enhance content

Requirements

• Research skills
• Stable Wi-Fi connection
• Interest in cybersecurity
• Mobile device with Telegram app
• Up to date knowledge about trending topics, current events

Offerings

Exchange of knowledge with industry colleagues
• Experience as a manager of a large cybersecurity community (for CV)
• Influence a growing community with a large audience

Contacts

If you are interested in the above position or have any questions, feel free to reach out directly → @cybersecadmin

P.S. Apologies if we have not responded to everybody from previous Rounds. This cycle will be managed more closely.

Send this post to a friend/colleague!

- - - - -

@Cyber_Security_Channel
👍108🔥3
LastPass Warns Backup Request is Phishing Campaign in Disguise

Company warned of a phishing campaign with false claims that the company is conducting maintenance and asking customers to back up their vaults in the next 24 hours, according to an alert released by the company.

“This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks,” a spokesperson for LastPass said in a statement.

The spokesperson added that LastPass would never ask customers for their master passwords or demand action under a tight deadline.

@Cyber_Security_Channel
3👍1
⚡️149 Million Usernames and Passwords Exposed by Unsecured Database

Security researcher Jeremiah Fowler discovered an unsecured database with 149 million credentials, including 48M Gmail accounts and 17M Facebook logins.

Fowler suspects the massive collection was assembled using info-stealing malware — malicious software that infects devices and uses techniques like key-logging to capture everything victims type into websites.

Users who reuse passwords across multiple services face compounded risk, since criminals can test stolen credentials against dozens of platforms to find matches.

@Cyber_Security_Channel
7🤯6👍5
🔥 Malware Trends Report 2025 From @anyrun_app is Live!
 
Key Takeaways:

• Phishing, driven by MFA-bypassing PhaaS kits like Tycoon2FA and EvilProxy, evolved into an advanced malicious vector. 

Lumma and XWorm stayed on top, showing how mature and scalable modern malware ecosystems have become.

Stealers and RATs still dominate, with activity nearly 3x higher than in 2024.
 
👨‍💻 See which malware families, TTPs, and phishing techniques defined 2025 and what they mean for your security strategy.

Read the full report — click here.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
7👍1🔥1👏1
Fortinet Confirms FortiCloud SSO Exploitation Against Patched Devices

"As an additional workaround we recommend disabling the FortiCloud SSO feature.

This will prevent abuse via that method but not a third-party SSO system, so this is recommended only in conjunction with the local-in policy" — Fortinet notes.

Cyber_Security_Channel
2🔥2🥰1
⚡️ ShinyHunters Phishing Spree Steals MFA, Breaches SaaS Apps via SSO attacks

Mandiant says a surge in advanced voice phishing (vishing) tied to ShinyHunters-linked clusters is harvesting single sign-on credentials and multi-factor authentication codes to breach cloud SaaS platforms and siphon sensitive data for extortion, abusing spoofed corporate login flows and bogus credential pages from targeted victims (see vishing breaches and extortion techniques).

“While this methodology of targeting identity providers and SaaS platforms is consistent with our prior observations… the breadth of targeted cloud platforms continues to expand as these threat actors seek more sensitive data for extortion,” Mandiant noted in its threat intelligence report.

Cyber_Security_Channel
3🔥2👍1🤩1