<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2024-11-08T23:42:40Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by zCat</title>
  <author>
    <name>zCat</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1zm7jduqq2nmxz5wxh4ujtm00g9vxzqa0r82yt7flvm67yje5gfaqa5pnd6.rss" />
  <link href="https://nostr.ae/npub1zm7jduqq2nmxz5wxh4ujtm00g9vxzqa0r82yt7flvm67yje5gfaqa5pnd6" />
  <id>https://nostr.ae/npub1zm7jduqq2nmxz5wxh4ujtm00g9vxzqa0r82yt7flvm67yje5gfaqa5pnd6</id>
  <icon>https://play-lh.googleusercontent.com/_Ng5PTAe-Nsj7LRlFAZmPIrm3Jbi8126ol0T3PMBLk240GCAe-IlEjiW2R7A0KIqqqI=w480-h960-rw</icon>
  <logo>https://play-lh.googleusercontent.com/_Ng5PTAe-Nsj7LRlFAZmPIrm3Jbi8126ol0T3PMBLk240GCAe-IlEjiW2R7A0KIqqqI=w480-h960-rw</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsr4ltl8krw6pu44zevgxchjatejt3992s8nltguc9pnreppc63ufgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85huzlye</id>
    
      <title type="html">Ad-based spyware delivery (zero click, if I understand it right) ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr4ltl8krw6pu44zevgxchjatejt3992s8nltguc9pnreppc63ufgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85huzlye" />
    <content type="html">
      Ad-based spyware delivery (zero click, if I understand it right)&lt;br/&gt;&lt;br/&gt;More reads:&lt;br/&gt;&lt;a href=&#34;https://x.com/IntCyberDigest/status/1997101543015801169&#34;&gt;https://x.com/IntCyberDigest/status/1997101543015801169&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://x.com/BleepinComputer/status/1996682923664118014&#34;&gt;https://x.com/BleepinComputer/status/1996682923664118014&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://x.com/lukOlejnik/status/1996604138512146890&#34;&gt;https://x.com/lukOlejnik/status/1996604138512146890&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://x.com/StarkPrivacy/status/1996995200699302015&#34;&gt;https://x.com/StarkPrivacy/status/1996995200699302015&lt;/a&gt;
    </content>
    <updated>2025-12-06T11:07:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp8ql769u00unsr0gju4j6t7kjraq69ynqpzajaykz5qek4m5vx9czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85fmuras</id>
    
      <title type="html">Pixnapping - stealing pixels and reconstructing the screen with ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp8ql769u00unsr0gju4j6t7kjraq69ynqpzajaykz5qek4m5vx9czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85fmuras" />
    <content type="html">
      Pixnapping - stealing pixels and reconstructing the screen with secrets (like Signal messages, Authenticator&amp;#39;s code, etc.) on Android 😬 #privacy #security&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://www.pixnapping.com/&#34;&gt;https://www.pixnapping.com/&lt;/a&gt;
    </content>
    <updated>2025-10-19T12:43:18Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfwz0kmy43hcj3lp007g3grwenz9cd37cgeu6tfw6nd0jk95wryzgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85fryvdt</id>
    
      <title type="html">📺 Watch DC Privacy Summit here (6h52m but with a lot of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfwz0kmy43hcj3lp007g3grwenz9cd37cgeu6tfw6nd0jk95wryzgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85fryvdt" />
    <content type="html">
      📺 Watch DC Privacy Summit here (6h52m but with a lot of breaks): &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.youtube.com/live/TeFzGvD2JOc&#34;&gt;https://www.youtube.com/live/TeFzGvD2JOc&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Agenda:&lt;br/&gt;&lt;a href=&#34;https://www.dcprivacysummit.org/agenda.html&#34;&gt;https://www.dcprivacysummit.org/agenda.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#privacy
    </content>
    <updated>2025-10-18T14:10:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr7ykdsfgrl9ap6tsj0fmykf0v9g54yaglcl9frp426gu326cvtdczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rtlm80</id>
    
      <title type="html">Learn zero knowledge for free with 0xPARC (older material but ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr7ykdsfgrl9ap6tsj0fmykf0v9g54yaglcl9frp426gu326cvtdczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rtlm80" />
    <content type="html">
      Learn zero knowledge for free with 0xPARC (older material but well explained)&lt;br/&gt;&lt;br/&gt;#zeroknowledge #zk #zksnark&lt;br/&gt;&lt;br/&gt;source: &lt;a href=&#34;https://learn.0xparc.org/&#34;&gt;https://learn.0xparc.org/&lt;/a&gt;
    </content>
    <updated>2025-10-15T22:12:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr9f3rm6lc426uxfktlch9gk0m9dy42ak42kzsjeprc63rcynt94qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p850ma7h8</id>
    
      <title type="html">⚡ Tails 7.1 released - it changes the home page of Tor Browser ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr9f3rm6lc426uxfktlch9gk0m9dy42ak42kzsjeprc63rcynt94qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p850ma7h8" />
    <content type="html">
      ⚡ Tails 7.1 released - it changes the home page of Tor Browser to an offline page and explains better how to set an administration password. #privacy&lt;br/&gt;&lt;br/&gt;source:&lt;br/&gt;&lt;a href=&#34;https://tails.net/news/version_7.1/&#34;&gt;https://tails.net/news/version_7.1/&lt;/a&gt;
    </content>
    <updated>2025-10-15T22:07:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0pnv5fq3gamey5jrwhexhafn0nncw5rgh60v30f9zn0qas9lf8xgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85jx4dsv</id>
    
      <title type="html">📱 GrapheneOS is finally ready to break free from Pixels, and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0pnv5fq3gamey5jrwhexhafn0nncw5rgh60v30f9zn0qas9lf8xgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85jx4dsv" />
    <content type="html">
      📱 GrapheneOS is finally ready to break free from Pixels, and it may never look back&lt;br/&gt;&lt;br/&gt;GrapheneOS didn’t reveal the name of its new partner, but said that those devices will be priced in the same range as Pixels.&lt;br/&gt;&lt;br/&gt;tl;dr: no privacy for poor people 😬 #privacy&lt;br/&gt;&lt;br/&gt;source:&lt;br/&gt;&lt;a href=&#34;https://www.androidauthority.com/graphene-os-major-android-oem-partnership-3606853/&#34;&gt;https://www.androidauthority.com/graphene-os-major-android-oem-partnership-3606853/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;
    </content>
    <updated>2025-10-15T22:03:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxu0zmrlp6tw7j50h88dzx0kcayjwpnmgfrlv9p9p8lt0a40s6mvszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85qkn4gk</id>
    
      <title type="html">#Crypto circus in last hours 🤡 🎪 🏆 Biggest liquidation ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxu0zmrlp6tw7j50h88dzx0kcayjwpnmgfrlv9p9p8lt0a40s6mvszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85qkn4gk" />
    <content type="html">
      #Crypto circus in last hours 🤡 🎪 &lt;br/&gt;&lt;br/&gt;🏆 Biggest liquidation in history:&lt;br/&gt;&lt;a href=&#34;https://x.com/unusual_whales/status/1976839842261835887&#34;&gt;https://x.com/unusual_whales/status/1976839842261835887&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;💰 Insiders are richer:&lt;br/&gt;&lt;a href=&#34;https://x.com/martypartymusic/status/1976771889738793109&#34;&gt;https://x.com/martypartymusic/status/1976771889738793109&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;🙉 Rumors (crypto[.]com &amp;amp; wintermute blew up - all denied):&lt;br/&gt;&lt;a href=&#34;https://x.com/heycape_/status/1976795205736223050&#34;&gt;https://x.com/heycape_/status/1976795205736223050&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;🪦CEX down as usal (Coinbase sucks):&lt;br/&gt;&lt;a href=&#34;https://x.com/WatcherGuru/status/1976779135159877727&#34;&gt;https://x.com/WatcherGuru/status/1976779135159877727&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;📉 Oracle issues:&lt;br/&gt;&lt;a href=&#34;https://x.com/omeragoldberg/status/1976796779120107696&#34;&gt;https://x.com/omeragoldberg/status/1976796779120107696&lt;/a&gt;
    </content>
    <updated>2025-10-11T09:12:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspq0vplrd4mnqhd9ehsd2xtm6efuncwu92s24dvq5t65y782rywxczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p852mlxtd</id>
    
      <title>Nostr event nevent1qqspq0vplrd4mnqhd9ehsd2xtm6efuncwu92s24dvq5t65y782rywxczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p852mlxtd</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspq0vplrd4mnqhd9ehsd2xtm6efuncwu92s24dvq5t65y782rywxczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p852mlxtd" />
    <content type="html">
       &lt;img src=&#34;https://image.nostr.build/3d9d9a9e73ccd4bbb0e9fb9e03765bcb20497e3464ddf6c0888655c13129e84c.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&amp;#34;The insider who opened trades 30 mins before Trumps tarrif announcement closed the trades for $104m&#43;$88m=$192m profits.&lt;br/&gt;&lt;br/&gt;The @HyperliquidX accounts were opened today.&amp;#34;&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://x.com/martypartymusic/status/1976771889738793109&#34;&gt;https://x.com/martypartymusic/status/1976771889738793109&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Amazing how we all act like it is normal 🤷‍♂️
    </content>
    <updated>2025-10-11T07:46:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst9kwvu6z3huugt7pt5vla8mvtgxcg7lnzx86lwg2qjhe256jz5mszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hfdpla</id>
    
      <title type="html">Coinbase should invest into infrastructure and people (to not ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst9kwvu6z3huugt7pt5vla8mvtgxcg7lnzx86lwg2qjhe256jz5mszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hfdpla" />
    <content type="html">
      Coinbase should invest into infrastructure and people (to not sell customer&amp;#39;s personal data) rather then military parades. It is down... as usual 🤷‍♂️
    </content>
    <updated>2025-10-10T22:10:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqegcsx08nmlr4p84e53s08vst85v2wsr63qy7ptfy6udfdvlqljszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rjz82z</id>
    
      <title type="html">Same as Coinbase btw</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqegcsx08nmlr4p84e53s08vst85v2wsr63qy7ptfy6udfdvlqljszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rjz82z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdv7s7xpzq53jvcvz7ad6th7cdwfczfc03yx2txnum26ajsgw6gqcpzpmhxue69uhkummnw3ezumt0d5hsufhru6&#39;&gt;nevent1q…hru6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Same as Coinbase btw
    </content>
    <updated>2025-10-09T23:27:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdv7s7xpzq53jvcvz7ad6th7cdwfczfc03yx2txnum26ajsgw6gqczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hdzg8w</id>
    
      <title type="html">So, they got some underpaid dude with 500$ lure and then couple ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdv7s7xpzq53jvcvz7ad6th7cdwfczfc03yx2txnum26ajsgw6gqczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hdzg8w" />
    <content type="html">
      So, they got some underpaid dude with 500$ lure and then couple of 1000$. These companies deserve public shame 🤦‍♂️&lt;br/&gt;&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nevent1qqszxpxegm89u8p9kpxf9dm3tknr7860lyannvd7lmm0dr4gcqkvt4gpzpmhxue69uhkummnw3ezumt0d5hsygqkl5n0qqz57es4r34a0yj7mm6ptpss8tce63zlj0mx7h3ykdzz0gpsgqqqqqqsrrefhg&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;nevent1q…efhg&lt;/a&gt;&lt;/span&gt; &lt;/div&gt; 🚨 Discord hack&lt;br/&gt;&lt;br/&gt;- Name, Discord username, email and other contact details if provided to Discord customer support&lt;br/&gt;- Limited billing information such as payment type, the last four digits of your credit card, and purchase history if associated with your account&lt;br/&gt;- IP addresses&lt;br/&gt;- Messages with our customer service agents &lt;br/&gt;Limited corporate data (training materials, internal presentations)&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service&#34;&gt;https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service&lt;/a&gt; &lt;/blockquote&gt;
    </content>
    <updated>2025-10-09T23:26:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8ay8qenjswxl7pn7mu5xu6aldlmchttaxjar9lan9z2rmkvr48lqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85f67hwy</id>
    
      <title type="html">Great, but I am biased</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8ay8qenjswxl7pn7mu5xu6aldlmchttaxjar9lan9z2rmkvr48lqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85f67hwy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgggn5w6qtslxylygq8ujl6jc2y8n6z2eyvrc68s5gzz7cgj7zt5spzamhxue69uhhyetvv9ujumn0wd68ytnzv9hxgtcyaxm0n&#39;&gt;nevent1q…xm0n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Great, but I am biased
    </content>
    <updated>2025-10-09T23:16:03Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgdy87g8ankz726cfyxp05z8e4ql658uxxt70m3q9gulcuav8mnhszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ulcqxu</id>
    
      <title type="html">Funny, I watched another YouTube privacy guru who was arrested in ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgdy87g8ankz726cfyxp05z8e4ql658uxxt70m3q9gulcuav8mnhszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ulcqxu" />
    <content type="html">
      Funny, I watched another YouTube privacy guru who was arrested in the past for running a dark market. Probably these people should not be giving privacy advice (until you want to end like them) 😬
    </content>
    <updated>2025-10-09T23:13:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvn4c4plt6rnf98rglq0n0emyr08w0lwjs5paysjc9ddce0yr34xqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85w20az9</id>
    
      <title type="html">🚨 Redis: Redis warns of critical flaw impacting thousands of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvn4c4plt6rnf98rglq0n0emyr08w0lwjs5paysjc9ddce0yr34xqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85w20az9" />
    <content type="html">
      🚨 Redis: Redis warns of critical flaw impacting thousands of instances&lt;br/&gt;&lt;br/&gt;Source:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/redis-warns-of-max-severity-flaw-impacting-thousands-of-instances/&#34;&gt;https://www.bleepingcomputer.com/news/security/redis-warns-of-max-severity-flaw-impacting-thousands-of-instances/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;🚨 Unity: Steam and Microsoft warn of Unity flaw exposing gamers to attacks&lt;br/&gt;&lt;br/&gt;Source:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/steam-and-microsoft-warn-of-unity-flaw-exposing-gamers-to-attacks/&#34;&gt;https://www.bleepingcomputer.com/news/security/steam-and-microsoft-warn-of-unity-flaw-exposing-gamers-to-attacks/&lt;/a&gt;
    </content>
    <updated>2025-10-06T16:07:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst9dl4zmnsr93pzha0ss6sg48n6ml4nfreq5lestylh96csay3hpqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85yluvgr</id>
    
      <title type="html">Weekend fun that collects last trades and updates live price ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst9dl4zmnsr93pzha0ss6sg48n6ml4nfreq5lestylh96csay3hpqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85yluvgr" />
    <content type="html">
      Weekend fun that collects last trades and updates live price through WebSockets in your browser. Loaded from IPFS, because why not?😀&lt;br/&gt;&lt;br/&gt;It probably has a couple of bugs, but it works on my local. ZEC, XMR, BTC, ETH&lt;br/&gt;&lt;br/&gt;IPFS gateway:&lt;br/&gt;&lt;a href=&#34;https://ipfs.io/ipns/k51qzi5uqu5djm23wijwx9pxh0kqyf2m9ab16d7i9b73s2eu3ecor3ad77z3l6/&#34;&gt;https://ipfs.io/ipns/k51qzi5uqu5djm23wijwx9pxh0kqyf2m9ab16d7i9b73s2eu3ecor3ad77z3l6/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;DWEB gateway:&lt;br/&gt;&lt;a href=&#34;https://k51qzi5uqu5djm23wijwx9pxh0kqyf2m9ab16d7i9b73s2eu3ecor3ad77z3l6.ipns.dweb.link/&#34;&gt;https://k51qzi5uqu5djm23wijwx9pxh0kqyf2m9ab16d7i9b73s2eu3ecor3ad77z3l6.ipns.dweb.link/&lt;/a&gt;&lt;br/&gt;
    </content>
    <updated>2025-10-05T19:00:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2fe6jhdfg872t0xm5phxyr9arnflfypeftm93gsvw352z79afk3szyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85naekdf</id>
    
      <title type="html">Jason Hassler: &amp;#34;17 countries have rolled out or passed ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2fe6jhdfg872t0xm5phxyr9arnflfypeftm93gsvw352z79afk3szyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85naekdf" />
    <content type="html">
      Jason Hassler: &amp;#34;17 countries have rolled out or passed digital ID laws in the last 3 months:&lt;br/&gt;&lt;br/&gt;-EU&lt;br/&gt;-UK&lt;br/&gt;-Laos&lt;br/&gt;-China&lt;br/&gt;-Taiwan&lt;br/&gt;-Mexico&lt;br/&gt;-Zambia&lt;br/&gt;-Canada&lt;br/&gt;-Ethiopia&lt;br/&gt;-Thailand&lt;br/&gt;-Vietnam&lt;br/&gt;-Australia&lt;br/&gt;-Costa Rica&lt;br/&gt;-Switzerland&lt;br/&gt;-Papua New Guinea&lt;br/&gt;&lt;br/&gt;Totally just a coincidence, I&amp;#39;m sure.&amp;#34; #privacy&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://x.com/JasonBassler1/status/1974623479304687699&#34;&gt;https://x.com/JasonBassler1/status/1974623479304687699&lt;/a&gt;
    </content>
    <updated>2025-10-05T12:16:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsthngpvpft5jr7lfdylxrdt7327l2lg0lrg2ee0lxcnc5kmlccmrgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p855hjysa</id>
    
      <title type="html">Ente: What would normally take 30 minutes for your photo library ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsthngpvpft5jr7lfdylxrdt7327l2lg0lrg2ee0lxcnc5kmlccmrgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p855hjysa" />
    <content type="html">
      Ente: What would normally take 30 minutes for your photo library now runs in less than 30 seconds, thanks to vector databases.&lt;br/&gt;&lt;br/&gt;Ente is great alternative (that actually cares about your privacy) to Google Photos.&lt;br/&gt;&lt;br/&gt;Read more: &lt;a href=&#34;https://ente.io/blog/vector-db/&#34;&gt;https://ente.io/blog/vector-db/&lt;/a&gt;
    </content>
    <updated>2025-10-04T19:21:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0m2ustdredk2r4seg4t3vqh5nf74vx07almtdj5znyjnsad9m88qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ys5u2m</id>
    
      <title>Nostr event nevent1qqs0m2ustdredk2r4seg4t3vqh5nf74vx07almtdj5znyjnsad9m88qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ys5u2m</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0m2ustdredk2r4seg4t3vqh5nf74vx07almtdj5znyjnsad9m88qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ys5u2m" />
    <content type="html">
       &lt;img src=&#34;https://image.nostr.build/15a5d3990043b2438791ca8b0359065cafb45e7e1328f4b28a9f8c67f117a769.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;Stolen from X:&lt;br/&gt;&lt;a href=&#34;https://x.com/malwrhunterteam/status/1785966314835579101&#34;&gt;https://x.com/malwrhunterteam/status/1785966314835579101&lt;/a&gt;
    </content>
    <updated>2025-10-04T08:43:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspw8hxhp52lv6azx0wvr6jd6f0n0st06zeyfuvjep5ujmkmmqd8rgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8593665q</id>
    
      <title type="html">Printers have unique fingerprints, but what about photos/cameras? ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspw8hxhp52lv6azx0wvr6jd6f0n0st06zeyfuvjep5ujmkmmqd8rgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8593665q" />
    <content type="html">
      Printers have unique fingerprints, but what about photos/cameras? 🫆 #privacy&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://image.nostr.build/3ffb6746ded68be529f30c2571ea5484296dd45dfa448a69f4b0b41a2e9421ae.jpg&#34;&gt;  &lt;br/&gt;&lt;br/&gt;Source:&lt;br/&gt;&lt;a href=&#34;https://blur-fields.github.io/&#34;&gt;https://blur-fields.github.io/&lt;/a&gt;
    </content>
    <updated>2025-10-04T08:38:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstgpxj5jk9y5arek0ek0uxfgtmzwra7e5vykwd55auhjat25hg0xszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85aqqtg0</id>
    
      <title type="html">nice tl;dr ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstgpxj5jk9y5arek0ek0uxfgtmzwra7e5vykwd55auhjat25hg0xszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85aqqtg0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszxpxegm89u8p9kpxf9dm3tknr7860lyannvd7lmm0dr4gcqkvt4gpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0e4ws09&#39;&gt;nevent1q…ws09&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;nice tl;dr&lt;br/&gt;  &lt;img src=&#34;https://image.nostr.build/bc0184f351423216feb8510bbf775c816b0b9b6600a761e04dc84f4a42ad185e.jpg&#34;&gt;  
    </content>
    <updated>2025-10-03T23:50:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszxpxegm89u8p9kpxf9dm3tknr7860lyannvd7lmm0dr4gcqkvt4gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p857749nm</id>
    
      <title type="html">🚨 Discord hack - Name, Discord username, email and other ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszxpxegm89u8p9kpxf9dm3tknr7860lyannvd7lmm0dr4gcqkvt4gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p857749nm" />
    <content type="html">
      🚨 Discord hack&lt;br/&gt;&lt;br/&gt;- Name, Discord username, email and other contact details if provided to Discord customer support&lt;br/&gt;- Limited billing information such as payment type, the last four digits of your credit card, and purchase history if associated with your account&lt;br/&gt;- IP addresses&lt;br/&gt;- Messages with our customer service agents &lt;br/&gt;Limited corporate data (training materials, internal presentations)&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service&#34;&gt;https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service&lt;/a&gt;
    </content>
    <updated>2025-10-03T23:48:02Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfxm8fh6ln8yty7xxt40km0fua9gc3l97wezwf9mdkgepgypevxmgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85j4wlk7</id>
    
      <title type="html">Monero: The first testnet (alpha stressnet) for Full-Chain ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfxm8fh6ln8yty7xxt40km0fua9gc3l97wezwf9mdkgepgypevxmgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85j4wlk7" />
    <content type="html">
      Monero: The first testnet (alpha stressnet) for Full-Chain Membership Proofs (FCMP&#43;&#43;) and CARROT is live! 👀
    </content>
    <updated>2025-10-03T23:39:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgjwl50x42lkru95vz0fcp8xmyu0zekquldlcaquey84u3rkvgk8czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hyqd4y</id>
    
      <title type="html">Zcash info hub: https://scifi.money/ What is #Zcash, why does it ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgjwl50x42lkru95vz0fcp8xmyu0zekquldlcaquey84u3rkvgk8czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hyqd4y" />
    <content type="html">
      Zcash info hub: &lt;a href=&#34;https://scifi.money/&#34;&gt;https://scifi.money/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;What is #Zcash, why does it exists, how it works and why you might be interested 👀
    </content>
    <updated>2025-10-03T21:35:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstkwxv99r82p6052cqj5czw3zsknyej7qjhzndqkfu8s3hpafuzdszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85etk3a7</id>
    
      <title type="html">Chat control is not dead. Germany is being Germany. Fight ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstkwxv99r82p6052cqj5czw3zsknyej7qjhzndqkfu8s3hpafuzdszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85etk3a7" />
    <content type="html">
      Chat control is not dead. Germany is being Germany. Fight against! ✊&lt;br/&gt;&lt;br/&gt;Single Blog:&lt;br/&gt;&lt;a href=&#34;https://signal.org/blog/pdfs/germany-chat-control.pdf&#34;&gt;https://signal.org/blog/pdfs/germany-chat-control.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Tuta Blog:&lt;br/&gt;&lt;a href=&#34;https://tuta.com/blog/unity-day-reminder-no-to-surveillance&#34;&gt;https://tuta.com/blog/unity-day-reminder-no-to-surveillance&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;
    </content>
    <updated>2025-10-03T21:30:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9acv8ly38ftts3ppc5zv540j52fx52gtadkwyue5hx0z7gnqt0uqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xlx9wt</id>
    
      <title>Nostr event nevent1qqs9acv8ly38ftts3ppc5zv540j52fx52gtadkwyue5hx0z7gnqt0uqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xlx9wt</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9acv8ly38ftts3ppc5zv540j52fx52gtadkwyue5hx0z7gnqt0uqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xlx9wt" />
    <content type="html">
      Is this the last free speech platform?
    </content>
    <updated>2025-10-03T21:20:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstpksr4q7d9lqfgq2wkxug3paxuw56ukgkxu2jwvfpnvtqngvdtngzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85uekcfa</id>
    
      <title type="html">BTW, fuck Google, fuck Android *sigh* ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstpksr4q7d9lqfgq2wkxug3paxuw56ukgkxu2jwvfpnvtqngvdtngzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85uekcfa" />
    <content type="html">
      BTW, fuck Google, fuck Android *sigh* &lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://image.nostr.build/58b34a2228fd2db9001c583c1bdcc27df0eba564e12fdeddc3068f030696532c.gif&#34;&gt; 
    </content>
    <updated>2025-08-30T11:56:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswyu906tzfwg9hth6fke6akzmpu60pqs45uk9022k8lsk2k4awlqczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85u2rgw4</id>
    
      <title type="html">Delete WhatsApp. It is spyware with security holes ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswyu906tzfwg9hth6fke6akzmpu60pqs45uk9022k8lsk2k4awlqczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85u2rgw4" />
    <content type="html">
      Delete WhatsApp. It is spyware with security holes&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://x.com/BleepinComputer/status/1961466788450894254&#34;&gt;https://x.com/BleepinComputer/status/1961466788450894254&lt;/a&gt;
    </content>
    <updated>2025-08-30T11:46:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0lnjjs5yqcz08e70qpr2050mzwelqy3ujym9ddn5w7ghhh6hn8qszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85j9pk07</id>
    
      <title>Nostr event nevent1qqs0lnjjs5yqcz08e70qpr2050mzwelqy3ujym9ddn5w7ghhh6hn8qszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85j9pk07</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0lnjjs5yqcz08e70qpr2050mzwelqy3ujym9ddn5w7ghhh6hn8qszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85j9pk07" />
    <content type="html">
      #Zcash #Privacy #Freedom 
    </content>
    <updated>2025-08-30T11:43:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8va3hgpf84e6cx0xj5gyqzsvarcadv9ant6hnz7s9mvez788p7cgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85agv3zv</id>
    
      <title type="html">The new version of zCat, an Android data aggregator for #Zcash , ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8va3hgpf84e6cx0xj5gyqzsvarcadv9ant6hnz7s9mvez788p7cgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85agv3zv" />
    <content type="html">
      The new version of zCat, an Android data aggregator for #Zcash , privacy &amp;amp; security news was released! Please update your app to v0.1.8!             &lt;br/&gt;&lt;br/&gt;Available in multiple languages: EN🇺🇸, BR🇧🇷, CS🇨🇿, DE🇩🇪, ES🇪🇸, FR🇫🇷,  IN🇮🇩, PL🇵🇱, RU🇷🇺, TH🇹🇭 &amp;amp; TR🇹🇷&lt;br/&gt;&lt;br/&gt;What is new? Integration of the ZKRadio. It is test implementation, it may be changed in the next version&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://image.nostr.build/bc5d1b31d1fa6a22e74c6e8b45653424f08107a833219992cdabebb716edc68c.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;Added ZcashEsp RSS feed as a News source. If you are aware of any other Zcash related RSS feeds, please let me know.&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://image.nostr.build/0b778fcc5abadebc6d257c009e28811f93931e28517f926d9bf8692af2d2c559.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;Added new localisations: Indonesian 🇮🇩 and Polish 🇵🇱 languages are brought back after being paused, and there is added a new language - Thai 🇹🇭language&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://image.nostr.build/f1a5ad86215dd90e4dbd95aad8065c6d40c68476a230e9d929c0665bb653a742.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;The &amp;#39;official announcement&amp;#39; can be found on Free2Z&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://free2z.cash/zCat/zpage/zcat-the-newest-version-v018-was-released&#34;&gt;https://free2z.cash/zCat/zpage/zcat-the-newest-version-v018-was-released&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Enjoy and have a great weekend.&lt;br/&gt;
    </content>
    <updated>2025-03-08T11:13:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp7jem6jqyaawlm7csa0znn0p2pcsd7w0zxlj45whz3tu9634205czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85c5w60v</id>
    
      <title>Nostr event nevent1qqsp7jem6jqyaawlm7csa0znn0p2pcsd7w0zxlj45whz3tu9634205czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85c5w60v</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp7jem6jqyaawlm7csa0znn0p2pcsd7w0zxlj45whz3tu9634205czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85c5w60v" />
    <content type="html">
       &lt;img src=&#34;https://image.nostr.build/bc084412c9a3ab9a2248cb0f8dc9b69ee8c37520f0c205c8d643732d32146655.jpg&#34;&gt;   &lt;img src=&#34;https://image.nostr.build/bc084412c9a3ab9a2248cb0f8dc9b69ee8c37520f0c205c8d643732d32146655.jpg&#34;&gt; 
    </content>
    <updated>2025-02-26T22:16:18Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2tlf3kkfkp83x2s0ns2u6n0zvf246jlmjq2jry3vukejtddux65czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85n34nu3</id>
    
      <title type="html">Hacker steals record $1.46 billion from Bybit ETH cold wallet ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2tlf3kkfkp83x2s0ns2u6n0zvf246jlmjq2jry3vukejtddux65czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85n34nu3" />
    <content type="html">
      Hacker steals record $1.46 billion from Bybit ETH cold wallet&lt;br/&gt;&lt;br/&gt;Cryptocurrency exchange Bybit revealed today that an unknown attacker stole over $1.46 billion worth of cryptocurrency from one of its ETH cold wallets.&lt;br/&gt;&lt;br/&gt;&amp;#34;The incident occurred when our ETH multisig cold wallet executed a transfer to our warm wallet. Unfortunately, this transaction was manipulated through a sophisticated attack that masked the signing interface, displaying the correct address while altering the underlying smart contract logic,&amp;#34; Bybit explained.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/hacker-steals-record-146-billion-from-bybit-eth-cold-wallet/&#34;&gt;https://www.bleepingcomputer.com/news/security/hacker-steals-record-146-billion-from-bybit-eth-cold-wallet/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#security #hack #crypto
    </content>
    <updated>2025-02-21T22:45:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs00fhsgxpp5rw4vzajy4fveg874q09wmsr0eu7f5tsc83rjc77zrgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rcqt9g</id>
    
      <title type="html">Vulnerabilities in MongoDB Library Allow RCE on Node[.]js Servers ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs00fhsgxpp5rw4vzajy4fveg874q09wmsr0eu7f5tsc83rjc77zrgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rcqt9g" />
    <content type="html">
      Vulnerabilities in MongoDB Library Allow RCE on Node[.]js Servers&lt;br/&gt;&lt;br/&gt;Two critical-severity vulnerabilities in the Mongoose Object Data Modeling (ODM) library for MongoDB could have allowed attackers to achieve remote code execution (RCE) on Node[.]js application server.&lt;br/&gt;&lt;br/&gt;The first of the critical-severity flaws in the library, tracked as CVE-2024-53900, could allow an attacker to exploit the $where value to potentially achieve RCE on Node.js. The second issue, tracked as CVE-2025-23061, is a bypass for CVE-2024-53900’s patch.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/vulnerabilities-in-mongodb-library-allow-rce-on-node-js-servers/&#34;&gt;https://www.securityweek.com/vulnerabilities-in-mongodb-library-allow-rce-on-node-js-servers/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#security #nodejs #rce
    </content>
    <updated>2025-02-21T22:44:09Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9qvgjc0speqj6v6vf8k9wudws3pagn0yzzqjwve2pcaev98fmqtczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85uk2z6a</id>
    
      <title type="html">The newest version of zCat, an Android data aggregator for ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9qvgjc0speqj6v6vf8k9wudws3pagn0yzzqjwve2pcaev98fmqtczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85uk2z6a" />
    <content type="html">
      The newest version of zCat, an Android data aggregator for #Zcash, privacy &amp;amp; security news was released! Please update your app to v0.1.6!       &lt;br/&gt;&lt;br/&gt;Available in multiple languages: EN 🇺🇸, BR 🇧🇷, CS 🇨🇿, DE 🇩🇪, ES 🇪🇸, FR 🇫🇷 &amp;amp; RU 🇷🇺&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://play.google.com/store/apps/details?id=crypto.crab.app.zcat&#34;&gt;https://play.google.com/store/apps/details?id=crypto.crab.app.zcat&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;It is only small patch release with smaller changes and bug fixes (and more languages). More info in the post on Free2Z:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://free2z.cash/zCat/zpage/zcat-the-newest-version-v016-was-released&#34;&gt;https://free2z.cash/zCat/zpage/zcat-the-newest-version-v016-was-released&lt;/a&gt;
    </content>
    <updated>2025-02-21T10:41:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs28s7tjx0v0yz7egr5wnncjapqz3gq0380kvdt0e92kfh5uqqldaqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85n5khdv</id>
    
      <title type="html">New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs28s7tjx0v0yz7egr5wnncjapqz3gq0380kvdt0e92kfh5uqqldaqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85n5khdv" />
    <content type="html">
      New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — Patch Now&lt;br/&gt;&lt;br/&gt;&amp;#34;Successful MitM exploitation could permit malicious actors to compromise and hijack SSH sessions, and gain unauthorized access to sensitive data.&amp;#34;&lt;br/&gt;&lt;br/&gt;&amp;#34;DoS attack can result in availability issues, preventing administrators from managing servers and locking legitimate users out, effectively crippling routine operations.&amp;#34;&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2025/02/new-openssh-flaws-enable-man-in-middle.html&#34;&gt;https://thehackernews.com/2025/02/new-openssh-flaws-enable-man-in-middle.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#security #ssh #mitm 
    </content>
    <updated>2025-02-20T07:45:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfjuyh3dh0fvxmyd7f7qfg33te2pm0dgvlfgftx3tu2ze3fw8r28gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85p8nrxn</id>
    
      <title type="html">Phishing attack hides JavaScript using invisible Unicode trick: A ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfjuyh3dh0fvxmyd7f7qfg33te2pm0dgvlfgftx3tu2ze3fw8r28gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85p8nrxn" />
    <content type="html">
      Phishing attack hides JavaScript using invisible Unicode trick: &lt;br/&gt;&lt;br/&gt;A new JavaScript obfuscation method utilizing invisible Unicode characters to represent binary values is being actively abused in phishing attacks targeting affiliates of an American political action committee (PAC).&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/phishing-attack-hides-javascript-using-invisible-unicode-trick/&#34;&gt;https://www.bleepingcomputer.com/news/security/phishing-attack-hides-javascript-using-invisible-unicode-trick/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#security #phishing
    </content>
    <updated>2025-02-20T07:34:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswkre7htrxffgafwaxcnpr2lsd5fprayhwu57fhmagm264fwndr9gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p854a8m7k</id>
    
      <title type="html">Hackers Exploit Signal&amp;#39;s Linked Devices Feature to Hijack ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswkre7htrxffgafwaxcnpr2lsd5fprayhwu57fhmagm264fwndr9gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p854a8m7k" />
    <content type="html">
      Hackers Exploit Signal&amp;#39;s Linked Devices Feature to Hijack Accounts via Malicious QR Codes&lt;br/&gt;&lt;br/&gt;&amp;#34;In the attacks spotted by the Google Threat Intelligence Group, the threat actors, including one it&amp;#39;s tracking as UNC5792, have resorted to malicious QR codes that, when scanned, will link a victim&amp;#39;s account to an actor-controlled Signal instance.&lt;br/&gt;&lt;br/&gt;As a result, future messages get delivered synchronously to both the victim and the threat actor in real-time, thereby granting threat actors a persistent way to eavesdrop on the victim&amp;#39;s conversations. Google said UAC-0195 partially overlaps with a hacking group known as UAC-0195.&amp;#34;&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2025/02/hackers-exploit-signals-linked-devices.html&#34;&gt;https://thehackernews.com/2025/02/hackers-exploit-signals-linked-devices.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#security #privacy #signal
    </content>
    <updated>2025-02-20T07:22:19Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszgaypexhqpn0dfz6l3egl38lr0sqkx3rcag5mghdcchwdx2649dqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85jvtk5m</id>
    
      <title type="html">Qubes OS 4.2.4 has been released! What is new: - All security ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszgaypexhqpn0dfz6l3egl38lr0sqkx3rcag5mghdcchwdx2649dqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85jvtk5m" />
    <content type="html">
      Qubes OS 4.2.4 has been released!&lt;br/&gt;&lt;br/&gt;What is new:&lt;br/&gt;- All security updates to date&lt;br/&gt;- All bug fixes to date&lt;br/&gt;- Included Fedora template upgraded from Fedora 40 to 41&lt;br/&gt;&lt;br/&gt;#privacy #security&lt;br/&gt;&lt;br/&gt;More info:&lt;br/&gt;&lt;a href=&#34;https://www.qubes-os.org/news/2025/02/18/qubes-os-4-2-4-has-been-released/&#34;&gt;https://www.qubes-os.org/news/2025/02/18/qubes-os-4-2-4-has-been-released/&lt;/a&gt;
    </content>
    <updated>2025-02-18T11:18:58Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9x5e8atkqdjpm5m38l2medxwuyzgyrn07safwsrkyu7953rra5jgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p856hz3dn</id>
    
      <title type="html">🦓 The #Zcash Foundation has announced a release of Zebra ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9x5e8atkqdjpm5m38l2medxwuyzgyrn07safwsrkyu7953rra5jgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p856hz3dn" />
    <content type="html">
      🦓 The #Zcash Foundation has announced a release of Zebra 2.2.0. &lt;br/&gt;&lt;br/&gt;This release introduces an additional consensus check on the branch ID of NU6 transactions, along with some important refactors and other improvements.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://zfnd.org/zebra-2-2-0-release/&#34;&gt;https://zfnd.org/zebra-2-2-0-release/&lt;/a&gt;
    </content>
    <updated>2025-02-08T10:37:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdfu0xw3kqjlg79py8rx2pxzfvh629td283d9snaq7qft6gq420gqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p853th879</id>
    
      <title type="html">💻 Tails has released a security patch with Tails 6.12. These ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdfu0xw3kqjlg79py8rx2pxzfvh629td283d9snaq7qft6gq420gqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p853th879" />
    <content type="html">
      💻 Tails has released a security patch with Tails 6.12.&lt;br/&gt;&lt;br/&gt;These vulnerabilities can only be exploited by a powerful attacker who has already exploited another vulnerability to take control of an application in Tails.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://blog.torproject.org/new-release-tails-6-12/&#34;&gt;https://blog.torproject.org/new-release-tails-6-12/&lt;/a&gt;
    </content>
    <updated>2025-02-08T10:31:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq6c3qvq337lux7an7qrgalc308jqmwxjgjyd05vpkeu83agr0vdczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85pkcwqz</id>
    
      <title type="html">🇬🇧 U.K. orders Apple to let it spy on users’ encrypted ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq6c3qvq337lux7an7qrgalc308jqmwxjgjyd05vpkeu83agr0vdczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85pkcwqz" />
    <content type="html">
      🇬🇧 U.K. orders Apple to let it spy on users’ encrypted accounts&lt;br/&gt;&lt;br/&gt;Secret order requires blanket access to protected cloud backups around the world, which if implemented would undermine Apple’s privacy pledge to its users. #privacy&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.washingtonpost.com/technology/2025/02/07/apple-encryption-backdoor-uk/&#34;&gt;https://www.washingtonpost.com/technology/2025/02/07/apple-encryption-backdoor-uk/&lt;/a&gt;
    </content>
    <updated>2025-02-08T10:13:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgszvutq68ca6pu5lpvuegtgaqc5w2jc027h5shw8e65eyg40ttaqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85l8zunz</id>
    
      <title type="html">Be careful about what you download from the official app stores ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgszvutq68ca6pu5lpvuegtgaqc5w2jc027h5shw8e65eyg40ttaqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85l8zunz" />
    <content type="html">
      Be careful about what you download from the official app stores 🧐 &lt;br/&gt;&lt;br/&gt;Bleeping Computer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/mobile/google-play-apple-app-store-apps-caught-stealing-crypto-wallets/&#34;&gt;https://www.bleepingcomputer.com/news/mobile/google-play-apple-app-store-apps-caught-stealing-crypto-wallets/&lt;/a&gt;
    </content>
    <updated>2025-02-07T08:57:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf9khwnhdvy9fakpap43ayu29hccxydlhugdqy3dzt7zsglfzfsdczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rujc9n</id>
    
      <title type="html">🇫🇷 Crypto mixers and anything that &amp;#34;opacifies ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf9khwnhdvy9fakpap43ayu29hccxydlhugdqy3dzt7zsglfzfsdczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rujc9n" />
    <content type="html">
      🇫🇷 Crypto mixers and anything that &amp;#34;opacifies transactions&amp;#34; are going to be banned in France.&lt;br/&gt;&lt;br/&gt;If you use them, it will be presumed money laundering for your pear.&lt;br/&gt;&lt;br/&gt;These two amendments have been adopted.&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://image.nostr.build/e772c3220d6dc3bba6f6a7cff9434550d5fbd5dd82982bf02d9340f4ef3b2912.jpg&#34;&gt; &lt;br/&gt;  &lt;img src=&#34;https://image.nostr.build/8073398daa5ff5a7823ff9b51641cc741cc6a9dfcbdbb31836fee0958200b528.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;Original tweet:&lt;br/&gt;&lt;a href=&#34;https://x.com/fakenine_/status/1887531025984614541&#34;&gt;https://x.com/fakenine_/status/1887531025984614541&lt;/a&gt;
    </content>
    <updated>2025-02-07T08:56:09Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2t56kpfj8mrgjka25m9d0h6nwxn0ks37hg4ssepamw6f3wlwgjeqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p855z8kxe</id>
    
      <title type="html">🇨🇿 The president of Czech Republic signed a new set of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2t56kpfj8mrgjka25m9d0h6nwxn0ks37hg4ssepamw6f3wlwgjeqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p855z8kxe" />
    <content type="html">
      🇨🇿 The president of Czech Republic signed a new set of rules for cryptocurrencies. &lt;br/&gt;&lt;br/&gt;Tl;Dr: Steps to integrate MiCA and no capital gains tax after 3 years of holding.&lt;br/&gt;&lt;br/&gt;Source (in Czech):&lt;br/&gt;&lt;a href=&#34;https://www.seznamzpravy.cz/clanek/ekonomika-finance-byznys-meny-kryptomeny-prezident-pavel-podepsal-zakon-zavadejici-pravidla-pro-trh-s-kryptomenami-269565&#34;&gt;https://www.seznamzpravy.cz/clanek/ekonomika-finance-byznys-meny-kryptomeny-prezident-pavel-podepsal-zakon-zavadejici-pravidla-pro-trh-s-kryptomenami-269565&lt;/a&gt;
    </content>
    <updated>2025-02-07T08:54:45Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqv3fujw2xtyyxhv4xvekf2u78h3v04gpm9vjrj8r2d5xfm3l9uxqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p858yyr60</id>
    
      <title>Nostr event nevent1qqsqv3fujw2xtyyxhv4xvekf2u78h3v04gpm9vjrj8r2d5xfm3l9uxqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p858yyr60</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqv3fujw2xtyyxhv4xvekf2u78h3v04gpm9vjrj8r2d5xfm3l9uxqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p858yyr60" />
    <content type="html">
       &lt;img src=&#34;https://image.nostr.build/bd43a20719393cf689355177bc1f22e9a056a09e6e0928673f9617527cceadc6.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;Merry Christmas and Happy Holidays to everyone! 🎄🎅&lt;br/&gt;&lt;br/&gt;Privacy is not a crime 😎 &lt;br/&gt;&lt;br/&gt;#zcash #privacy
    </content>
    <updated>2024-12-25T06:57:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2s6k7as3d8zdhy60v6yxs876hrl9jgmvqc2wgfe8r6rqmydrv45gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85sr5x55</id>
    
      <title type="html">Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2s6k7as3d8zdhy60v6yxs876hrl9jgmvqc2wgfe8r6rqmydrv45gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85sr5x55" />
    <content type="html">
      Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws,  Adobe Patches Over 160 Vulnerabilities Across 16 Products.&lt;br/&gt;&lt;br/&gt;Today is Microsoft&amp;#39;s December 2024 Patch Tuesday, which includes security updates for 71 flaws, including one actively exploited zero-day vulnerability.&lt;br/&gt;&lt;br/&gt;This Patch Tuesday fixed sixteen critical vulnerabilities, all of which are remote code execution flaws.&lt;br/&gt;&lt;br/&gt;This month&amp;#39;s Patch Tuesday fixes one actively exploited, publicly disclosed zero-day vulnerability CVE-2024-49138 - Windows Common Log File System Driver Elevation of Privilege Vulnerability.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;BleepingComputer :&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2024-patch-tuesday-fixes-1-exploited-zero-day-71-flaws/&#34;&gt;https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2024-patch-tuesday-fixes-1-exploited-zero-day-71-flaws/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;SecurityWeek:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/microsoft-ships-urgent-patch-for-exploited-windows-clfs-zero-day/&#34;&gt;https://www.securityweek.com/microsoft-ships-urgent-patch-for-exploited-windows-clfs-zero-day/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Security week (Adobe): &lt;a href=&#34;https://www.securityweek.com/adobe-patches-over-160-vulnerabilities-across-16-products/&#34;&gt;https://www.securityweek.com/adobe-patches-over-160-vulnerabilities-across-16-products/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #microsoft #zeroday #patch
    </content>
    <updated>2024-12-11T07:23:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsplpvd3cfy6mednfmhldxkff62uwt4rjf6nhgq02s043t3gccegvqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8548npdg</id>
    
      <title type="html">Researchers Uncover Prompt Injection Vulnerabilities in DeepSeek ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsplpvd3cfy6mednfmhldxkff62uwt4rjf6nhgq02s043t3gccegvqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8548npdg" />
    <content type="html">
      Researchers Uncover Prompt Injection Vulnerabilities in DeepSeek and Claude AI&lt;br/&gt;&lt;br/&gt;Details have emerged about a now-patched security flaw in the DeepSeek artificial intelligence (AI) chatbot that, if successfully exploited, could permit a bad actor to take control of a victim&amp;#39;s account by means of a prompt injection attack.&lt;br/&gt;&lt;br/&gt;Security researcher Johann Rehberger, who has chronicled many a prompt injection attack targeting various AI tools, found that providing the input &amp;#34;Print the xss cheat sheet in a bullet list. just payloads&amp;#34; in the DeepSeek chat triggered the execution of JavaScript code as part of the generated response – a classic case of cross-site scripting (XSS).&lt;br/&gt;&lt;br/&gt;XSS attacks can have serious consequences as they lead to the execution of unauthorized code in the context of the victim&amp;#39;s web browser.&lt;br/&gt;&lt;br/&gt;An attacker could take advantage of such flaws to hijack a user&amp;#39;s session and gain access to cookies and other data associated with the chat.deepseek[.]com domain, thereby leading to an account takeover.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/researchers-uncover-prompt-injection.html&#34;&gt;https://thehackernews.com/2024/12/researchers-uncover-prompt-injection.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #ai #injection
    </content>
    <updated>2024-12-11T07:17:03Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdlnjc0xm8f2smfcdghsdzzqwzxlrfe62nemlwqyn2w3cgagsdzhczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85qyx624</id>
    
      <title type="html">SAP Patches Critical Vulnerability in NetWeaver Enterprise ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdlnjc0xm8f2smfcdghsdzzqwzxlrfe62nemlwqyn2w3cgagsdzhczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85qyx624" />
    <content type="html">
      SAP Patches Critical Vulnerability in NetWeaver&lt;br/&gt;&lt;br/&gt;Enterprise software maker SAP on Tuesday announced the release of nine new and four updated security notes as part of its December 2024 Security Patch Day.&lt;br/&gt;&lt;br/&gt;Marked as ‘hot news’, the highest severity in SAP’s notebook, the first new security note addresses three vulnerabilities in NetWeaver AS for JAVA (Adobe Document Services), including a critical flaw that could lead to full system compromise.&lt;br/&gt;&lt;br/&gt;The critical issue, tracked as CVE-2024-47578 (CVSS score of 9.1), affects the Adobe Document Service component of NetWeaver, which allows an attacker with administrative privileges to send a crafted request from a vulnerable web application.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/sap-patches-critical-vulnerability-in-netweaver/&#34;&gt;https://www.securityweek.com/sap-patches-critical-vulnerability-in-netweaver/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #SAP #netweaver
    </content>
    <updated>2024-12-11T07:13:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf7y8nz6vuej0a456hh67stsa20xr9x9l4zj9du0xr7muu2qyzzzqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p856nukjd</id>
    
      <title type="html">Ivanti warns of maximum severity CSA auth bypass vulnerability ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf7y8nz6vuej0a456hh67stsa20xr9x9l4zj9du0xr7muu2qyzzzqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p856nukjd" />
    <content type="html">
      Ivanti warns of maximum severity CSA auth bypass vulnerability&lt;br/&gt;&lt;br/&gt;Today, Ivanti warned customers about a new maximum-severity authentication bypass vulnerability in its Cloud Services Appliance (CSA) solution.&lt;br/&gt;&lt;br/&gt;The security flaw (tracked as CVE-2024-11639 and reported by CrowdStrike&amp;#39;s Advanced Research Team) enables remote attackers to gain administrative privileges on vulnerable appliances running Ivanti CSA 5.0.2 or earlier without requiring authentication or user interaction by circumventing authentication using an alternate path or channel.&lt;br/&gt;&lt;br/&gt;Ivanti advises admins to upgrade vulnerable appliances to CSA 5.0.3 using detailed information available in this support document.&lt;br/&gt;&lt;br/&gt;&amp;#34;We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure. These vulnerabilities were disclosed through our responsible disclosure program,&amp;#34; the company said on Tuesday. &amp;#34;Currently, there is no known public exploitation of this these vulnerabilities that could be used to provide a list of indicators of compromise.&amp;#34;&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;BleepingComputer :&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/ivanti-warns-of-maximum-severity-csa-auth-bypass-vulnerability/&#34;&gt;https://www.bleepingcomputer.com/news/security/ivanti-warns-of-maximum-severity-csa-auth-bypass-vulnerability/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/ivanti-issues-critical-security-updates.html&#34;&gt;https://thehackernews.com/2024/12/ivanti-issues-critical-security-updates.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #ivanti #authenticationbypass
    </content>
    <updated>2024-12-11T07:12:16Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgxup85m2z6clnkynm44aycx5c7v4quhrwd77vmdfjx68xwpznzgszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hxs99c</id>
    
      <title type="html">New Cleo zero-day RCE flaw exploited in data theft attacks ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgxup85m2z6clnkynm44aycx5c7v4quhrwd77vmdfjx68xwpznzgszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85hxs99c" />
    <content type="html">
      New Cleo zero-day RCE flaw exploited in data theft attacks&lt;br/&gt;&lt;br/&gt;Hackers are actively exploiting a zero-day vulnerability in Cleo managed file transfer software to breach corporate networks and conduct data theft attacks.&lt;br/&gt;&lt;br/&gt;The flaw is found in the company&amp;#39;s secure file transfer products, Cleo LexiCom, VLTrader, and Harmony, and is a flaw that allows unrestricted file upload and downloads that leads to remote code execution.&lt;br/&gt;&lt;br/&gt;The Cleo MFT vulnerability affects versions 5[.]8[.]0[.]21 and earlier and is a bypass for a previously fixed flaw, CVE-2024-50623, which Cleo addressed in October 2024. However, the fix was incomplete, allowing threat actors to bypass it and continue to exploit it in attacks.&lt;br/&gt;&lt;br/&gt;Cleo says its software is used by 4,000 companies worldwide, including Target, Walmart, Lowes, CVS, The Home Depot, FedEx, Kroger, Wayfair, Dollar General, Victrola, and Duraflame.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;BleepingComputer :&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/&#34;&gt;https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/cleo-file-transfer-vulnerability-under.html&#34;&gt;https://thehackernews.com/2024/12/cleo-file-transfer-vulnerability-under.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Security Week:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/cleo-file-transfer-tool-vulnerability-exploited-in-wild-against-enterprises/&#34;&gt;https://www.securityweek.com/cleo-file-transfer-tool-vulnerability-exploited-in-wild-against-enterprises/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #rce #cleo
    </content>
    <updated>2024-12-11T07:09:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxgylreccfs29cxqh70layrkf2mdqe0cj3xx37k865lgap67cnvnczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85dx4jmw</id>
    
      <title type="html">Chinese hackers use Visual Studio Code tunnels for remote access ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxgylreccfs29cxqh70layrkf2mdqe0cj3xx37k865lgap67cnvnczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85dx4jmw" />
    <content type="html">
      Chinese hackers use Visual Studio Code tunnels for remote access&lt;br/&gt;&lt;br/&gt;Chinese hackers targeting large IT service providers in Southern Europe were seen abusing Visual Studio Code (VSCode) tunnels to maintain persistent remote access to compromised systems.&lt;br/&gt;&lt;br/&gt;VSCode tunnels are part of Microsoft&amp;#39;s Remote Development feature, which enables developers to securely access and work on remote systems via Visual Studio Code. Developers can also execute command and access the file system of remote devices, making it a powerful development tool.&lt;br/&gt;&lt;br/&gt;The tunnels are established using Microsoft Azure infrastructure, with executables signed by Microsoft, providing trustworthy access.&lt;br/&gt;&lt;br/&gt;Attack chains observed by the companies entail the use of SQL injection as an initial access vector to breach internet-facing applications and database servers. The code injection is accomplished by means of a legitimate penetration testing tool called SQLmap that automates the process of detecting and exploiting SQL injection flaws.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;BleepingComputer :&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/chinese-hackers-use-visual-studio-code-tunnels-for-remote-access/&#34;&gt;https://www.bleepingcomputer.com/news/security/chinese-hackers-use-visual-studio-code-tunnels-for-remote-access/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/hackers-weaponize-visual-studio-code.html&#34;&gt;https://thehackernews.com/2024/12/hackers-weaponize-visual-studio-code.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #visualstudiocode #sqlinjection
    </content>
    <updated>2024-12-11T07:03:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2gnpu0vkle3kru6tzlff6qnjpnxqtg0yh6z3x3c8fft4s83uw88gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85vpmumh</id>
    
      <title type="html">Exploits and vulnerabilities in Q3 2024 Q3 2024 saw multiple ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2gnpu0vkle3kru6tzlff6qnjpnxqtg0yh6z3x3c8fft4s83uw88gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85vpmumh" />
    <content type="html">
      Exploits and vulnerabilities in Q3 2024&lt;br/&gt;&lt;br/&gt;Q3 2024 saw multiple vulnerabilities discovered in Windows and Linux subsystems that are not standard for cyberattacks. This is because operating system developers have been releasing new security mitigations for whole sets of vulnerabilities in commonly used subsystems. &lt;br/&gt;&lt;br/&gt;For example, a log integrity check is set to appear in the Common Log Filing System (CLFS) in Windows, so the number of exploits for it will drop. As for Linux, this operating system has the Linux Kernel Runtime Guard (LKRG), implemented as a separate kernel module. &lt;br/&gt;&lt;br/&gt;Although the first version of LKRG was released back in 2018, it is undergoing constant refinement. And it is becoming more actively used in various Linux builds.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://securelist.com/exploits-and-vulnerabilities-q3-2024/114839/&#34;&gt;https://securelist.com/exploits-and-vulnerabilities-q3-2024/114839/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #exploits #vulnerabilities
    </content>
    <updated>2024-12-08T07:25:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgttjpr5vklgmqda4wda9eserhwsqxrm6h7agg3qnfqnxqagdp8agzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85nrrvgh</id>
    
      <title type="html">IT threat evolution in Q3 2024. Mobile statistics According to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgttjpr5vklgmqda4wda9eserhwsqxrm6h7agg3qnfqnxqagdp8agzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85nrrvgh" />
    <content type="html">
      IT threat evolution in Q3 2024. Mobile statistics&lt;br/&gt;&lt;br/&gt;According to Kaspersky Security Network, in Q3 2024:&lt;br/&gt;&lt;br/&gt;- As many as 6.7 million attacks involving malware, adware or potentially unwanted mobile apps were prevented.&lt;br/&gt;- Adware was the most common mobile threat, accounting for 36% of all detected threats.&lt;br/&gt;- More than 222,000 malicious and potentially unwanted installation packages were detected, of which:&lt;br/&gt;    A) 17,822 were associated with mobile banking Trojans.&lt;br/&gt;    B) 1576 packages were mobile ransomware Trojans&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://securelist.com/malware-report-q3-2024-mobile-statistics/114692/&#34;&gt;https://securelist.com/malware-report-q3-2024-mobile-statistics/114692/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #mobile #malware
    </content>
    <updated>2024-12-08T07:21:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrt9r3453pg96nce5tfctzu888h25dhqpsfn2ydwv8egn0rhr025qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85aqrzay</id>
    
      <title type="html">SecurityWeek sums up the last week news: ENISA and NCSC release ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrt9r3453pg96nce5tfctzu888h25dhqpsfn2ydwv8egn0rhr025qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85aqrzay" />
    <content type="html">
      SecurityWeek sums up the last week news:&lt;br/&gt;&lt;br/&gt;ENISA and NCSC release cybersecurity reports, abuse of Cloudflare services, FBI warns of gen-AI enabling fraud. &lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/in-other-news-cloudflare-abuse-uk-and-eu-cybersecurity-reports-fbi-gen-ai-alert/&#34;&gt;https://www.securityweek.com/in-other-news-cloudflare-abuse-uk-and-eu-cybersecurity-reports-fbi-gen-ai-alert/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity
    </content>
    <updated>2024-12-08T07:16:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspgp9j4nxk8hmjfmfnpr3dk6c27tlm0y7r5kjzqmlgwrqkuzq56tgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85j2c0x8</id>
    
      <title type="html">Data Breach News! Atrium Health Data Breach Impacts 585,000 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspgp9j4nxk8hmjfmfnpr3dk6c27tlm0y7r5kjzqmlgwrqkuzq56tgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85j2c0x8" />
    <content type="html">
      Data Breach News!&lt;br/&gt;&lt;br/&gt;Atrium Health Data Breach Impacts 585,000 People&lt;br/&gt;&lt;br/&gt;Healthcare company Atrium Health has notified the US Department of Health and Human Services (HHS) that a recently discovered data breach impacts more than 585,000 individuals.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/atrium-health-data-breach-impacts-585000-people/&#34;&gt;https://www.securityweek.com/atrium-health-data-breach-impacts-585000-people/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Blue Yonder SaaS giant breached by Termite ransomware gang&lt;br/&gt;&lt;br/&gt;The Termite ransomware gang has officially claimed responsibility for the November breach of software as a service (SaaS) provider Blue Yonder. Its list of over 3,000 customers includes other high-profile companies like Microsoft, Renault, Bayer, Tesco, Lenovo, DHL, 3M, Ace Hardware, Procter &amp;amp; Gamble, Carlsberg, Dole, Wallgreens, Western Digital, and 7-Eleven.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/blue-yonder-saas-giant-breached-by-termite-ransomware-gang/&#34;&gt;https://www.bleepingcomputer.com/news/security/blue-yonder-saas-giant-breached-by-termite-ransomware-gang/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #databreach #privacy&lt;br/&gt;
    </content>
    <updated>2024-12-08T07:14:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspymjmvnvpgcr352warav0vjez80qdnru0ql5q46m4fhh58jzdp2qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8577akkg</id>
    
      <title type="html">Ultralytics AI model hijacked to infect thousands with ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspymjmvnvpgcr352warav0vjez80qdnru0ql5q46m4fhh58jzdp2qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8577akkg" />
    <content type="html">
      Ultralytics AI model hijacked to infect thousands with cryptominer&lt;br/&gt;&lt;br/&gt;The popular Ultralytics YOLO11 AI model was compromised in a supply chain attack to deploy cryptominers on devices running versions 8.3.41 and 8.3.42 from the Python Package Index (PyPI)  &lt;br/&gt;&lt;br/&gt;Ultralytics is a software development company specializing in computer vision and artificial intelligence (AI), specifically in object detection and image processing.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s best known for its &amp;#34;YOLO&amp;#34; (You Only Look Once) advanced object detection model, which can quickly and accurately detect and identify objects in video streams in real time.&lt;br/&gt;&lt;br/&gt;Ultralytics tools are open-source and are used by numerous projects spanning a wide range of industries and applications.&lt;br/&gt;&lt;br/&gt;The library has been starred 33,600 times and forked 6,500 times on GitHub, and it has had over 260,000 downloads over the past 24 hours from PyPI alone.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;BleepingComputer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/ultralytics-ai-model-hijacked-to-infect-thousands-with-cryptominer/&#34;&gt;https://www.bleepingcomputer.com/news/security/ultralytics-ai-model-hijacked-to-infect-thousands-with-cryptominer/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/ultralytics-ai-library-compromised.html&#34;&gt;https://thehackernews.com/2024/12/ultralytics-ai-library-compromised.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #malware #ai
    </content>
    <updated>2024-12-08T07:09:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2kxe2jnjrctuccullzwp3492uakh9dwa7x9pmzcp8hwaamm8q3aqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p854upwgw</id>
    
      <title type="html">New Windows zero-day exposes NTLM credentials, gets unofficial ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2kxe2jnjrctuccullzwp3492uakh9dwa7x9pmzcp8hwaamm8q3aqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p854upwgw" />
    <content type="html">
      New Windows zero-day exposes NTLM credentials, gets unofficial patch&lt;br/&gt;&lt;br/&gt;A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer.&lt;br/&gt;&lt;br/&gt;The flaw was discovered by the 0patch team, a platform that provides unofficial support for end-of-life Windows versions, and was reported to Microsoft. However, no official fix has been released yet.&lt;br/&gt;&lt;br/&gt;According to 0patch, the issue, which currently has no CVE ID, impacts all Windows versions from Windows 7 and Server 2008 R2 up to the latest Windows 11 24H2 and Server 2022.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/new-windows-zero-day-exposes-ntlm-credentials-gets-unofficial-patch/&#34;&gt;https://www.bleepingcomputer.com/news/security/new-windows-zero-day-exposes-ntlm-credentials-gets-unofficial-patch/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #windows #patch
    </content>
    <updated>2024-12-08T07:04:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsggqgkc3tq69uhzsyaaqd6wl6g9sxh2farukt42uqas98s2y4ra8qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xh0qud</id>
    
      <title type="html">Researchers Uncover Flaws in Popular Open-Source Machine Learning ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsggqgkc3tq69uhzsyaaqd6wl6g9sxh2farukt42uqas98s2y4ra8qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xh0qud" />
    <content type="html">
      Researchers Uncover Flaws in Popular Open-Source Machine Learning Frameworks&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have disclosed multiple security flaws impacting open-source machine learning (ML) tools and frameworks such as MLflow, H2O, PyTorch, and MLeap that could pave the way for code execution.&lt;br/&gt;&lt;br/&gt;The vulnerabilities, discovered by JFrog, are part of a broader collection of 22 security shortcomings the supply chain security company first disclosed last month.&lt;br/&gt;&lt;br/&gt;Unlike the first set that involved flaws on the server-side, the newly detailed ones allow exploitation of ML clients and reside in libraries that handle safe model formats like Safetensors.&lt;br/&gt;&lt;br/&gt;&amp;#34;Hijacking an ML client in an organization can allow the attackers to perform extensive lateral movement within the organization,&amp;#34; the company said. &amp;#34;An ML client is very likely to have access to important ML services such as ML Model Registries or MLOps Pipelines.&amp;#34;&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/researchers-uncover-flaws-in-popular.html&#34;&gt;https://thehackernews.com/2024/12/researchers-uncover-flaws-in-popular.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #machinelearning #malware
    </content>
    <updated>2024-12-08T07:03:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0ry6qusy7pmcc6j2n44rxycr74kgmdnt4utkrskm6aq43zpxvcpqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85t7vejt</id>
    
      <title type="html">Crypto-stealing malware posing as a meeting app targets Web3 pros ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0ry6qusy7pmcc6j2n44rxycr74kgmdnt4utkrskm6aq43zpxvcpqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85t7vejt" />
    <content type="html">
      Crypto-stealing malware posing as a meeting app targets Web3 pros&lt;br/&gt;&lt;br/&gt;Cybercriminals are targeting people working in Web3 with fake business meetings using a fraudulent video conferencing platform that infects Windows and Macs with crypto-stealing malware.&lt;br/&gt;&lt;br/&gt;The campaign is dubbed &amp;#34;Meeten&amp;#34; after the name commonly used by the meeting software and has been underway since September 2024.&lt;br/&gt;&lt;br/&gt;The malware, which has both a Windows and a macOS version, targets victims&amp;#39; cryptocurrency assets, banking information, information stored on web browsers, and Keychain credentials (on Mac).&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/crypto-stealing-malware-posing-as-a-meeting-app-targets-web3-pros/&#34;&gt;https://www.bleepingcomputer.com/news/security/crypto-stealing-malware-posing-as-a-meeting-app-targets-web3-pros/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #cryptocurrency  #malware
    </content>
    <updated>2024-12-08T06:58:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9n83el227yvcxcnn2drvpt54txjw4l29dg02uzl6xv79hk0dxtjczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85kta6du</id>
    
      <title type="html">Hackers Leveraging Cloudflare Tunnels, DNS Fast-Flux to Hide ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9n83el227yvcxcnn2drvpt54txjw4l29dg02uzl6xv79hk0dxtjczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85kta6du" />
    <content type="html">
      Hackers Leveraging Cloudflare Tunnels, DNS Fast-Flux to Hide GammaDrop Malware&lt;br/&gt;&lt;br/&gt;The threat actor known as Gamaredon has been observed leveraging Cloudflare Tunnels as a tactic to conceal its staging infrastructure hosting a malware called GammaDrop.&lt;br/&gt;&lt;br/&gt;The activity is part of an ongoing spear-phishing campaign targeting Ukrainian entities since at least early 2024 that&amp;#39;s designed to drop the Visual Basic Script malware, Recorded Future&amp;#39;s Insikt Group said in a new analysis.&lt;br/&gt;&lt;br/&gt;The cybersecurity company is tracking the threat actor under the name BlueAlpha, which is also known as Aqua Blizzard, Armageddon, Hive0051, Iron Tilden, Primitive Bear, Shuckworm, Trident Ursa, UAC-0010, UNC530, and Winterflounder. The group, believed to be active since 2014, is affiliated with Russia&amp;#39;s Federal Security Service (FSB).&lt;br/&gt;&lt;br/&gt;The tools are chiefly engineered to steal valuable data from web applications running inside internet browsers, email clients, and instant messaging applications such as Signal and Telegram, as well as download additional payloads and propagate the malware via connected USB drives.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/hackers-leveraging-cloudflare-tunnels.html&#34;&gt;https://thehackernews.com/2024/12/hackers-leveraging-cloudflare-tunnels.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #cloudflare #malware
    </content>
    <updated>2024-12-08T06:56:03Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswuhas5vkacyttyfkdq3xyxx4jwscgwlsd9z8zrpw4jhlj2r60v4qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85wvrs9s</id>
    
      <title type="html">New Android spyware found on phone seized by Russian FSB After a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswuhas5vkacyttyfkdq3xyxx4jwscgwlsd9z8zrpw4jhlj2r60v4qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85wvrs9s" />
    <content type="html">
      New Android spyware found on phone seized by Russian FSB&lt;br/&gt;&lt;br/&gt;After a Russian programmer was detained by Russia&amp;#39;s Federal Security Service (FSB) for fifteen days and his phone confiscated, it was discovered that a new spyware was secretly installed on his device upon its return.&lt;br/&gt;&lt;br/&gt;The programmer, Kirill Parubets, was arrested by the FSB after being accused of donating to Ukraine. After regaining access to his mobile device, the programmer suspected it was tampered with by the Russian government after it exhibited unusual behavior and displayed a notifications stating, &amp;#34;Arm cortex vx3 synchronization.&amp;#34;&lt;br/&gt;&lt;br/&gt;After sharing it with Citizen Lab for forensic analysis, investigators confirmed that spyware had been installed on the device that impersonated a legitimate and popular Android app &amp;#39;Cube Call Recorder,&amp;#39; which has over 10,000,000 downloads on Google Play.&lt;br/&gt;&lt;br/&gt;Contrary to the legitimate app, though, the spyware has access to a broad range of permissions, giving it unfettered access to the device and allowing the attackers to monitor the activities on the phone.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/new-android-spyware-found-on-phone-seized-by-russian-fsb/&#34;&gt;https://www.bleepingcomputer.com/news/security/new-android-spyware-found-on-phone-seized-by-russian-fsb/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#android #spyware #privacy #cybersecurity
    </content>
    <updated>2024-12-06T07:28:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp4f9afhq05wsg2tuaj4ntp3cjl3fnxk9740z4l8ea326lv203whszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xcwhr6</id>
    
      <title type="html">Critical Vulnerability Discovered in SailPoint IdentityIQ ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp4f9afhq05wsg2tuaj4ntp3cjl3fnxk9740z4l8ea326lv203whszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xcwhr6" />
    <content type="html">
      Critical Vulnerability Discovered in SailPoint IdentityIQ&lt;br/&gt;&lt;br/&gt;SailPoint this week warned that a critical-severity vulnerability in the identity and access management (IAM) platform IdentityIQ could allow attackers to access restricted files.&lt;br/&gt;&lt;br/&gt;SailPoint’s IdentityIQ IAM platform provides full lifecycle and compliance management capabilities covering provisioning, access requests, certifications, and segregation of duties.&lt;br/&gt;&lt;br/&gt;The critical issue, tracked as CVE-2024-10905, has a CVSS score of 10/10 and is described as an improper access control flaw. The bug is, essentially, a directory traversal flaw that affects all IdentityIQ versions up to patch levels 8.4p2, 8.3p5, and 8.2p8.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/critical-vulnerability-discovered-in-sailpoint-identityiq/&#34;&gt;https://www.securityweek.com/critical-vulnerability-discovered-in-sailpoint-identityiq/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #identityiq
    </content>
    <updated>2024-12-06T07:26:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2jklmcrx4phmffkg0eqzalgeladakga6r7tmjdyas4c6tx7va3pgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85h5sp8n</id>
    
      <title type="html">U.S. org suffered four month intrusion by Chinese hackers A large ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2jklmcrx4phmffkg0eqzalgeladakga6r7tmjdyas4c6tx7va3pgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85h5sp8n" />
    <content type="html">
      U.S. org suffered four month intrusion by Chinese hackers&lt;br/&gt;&lt;br/&gt;A large U.S. organization with significant presence in China has been reportedly breached by China-based threat actors who persisted on its networks from April to August 2024.&lt;br/&gt;&lt;br/&gt;According to Symantec’s threat researchers, the operation appeared to focus on intelligence gathering, involving multiple compromised machines and targeting Exchange Servers, likely for email and data exfiltration.&lt;br/&gt;&lt;br/&gt;The researchers did not explicitly name the breached U.S. organization but mentioned that the same entity was targeted by the China-based ‘Daggerfly’ threat group in 2023.&lt;br/&gt;&lt;br/&gt;See more&lt;br/&gt;BleepingComputer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/us-org-suffered-four-month-intrusion-by-chinese-hackers/&#34;&gt;https://www.bleepingcomputer.com/news/security/us-org-suffered-four-month-intrusion-by-chinese-hackers/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hackers News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/researchers-uncover-4-month-cyberattack.html&#34;&gt;https://thehackernews.com/2024/12/researchers-uncover-4-month-cyberattack.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #cyberattack #breach
    </content>
    <updated>2024-12-06T07:24:31Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq6snzfze8sctrrnp4jjrclsq7j3cads7htf6mcctsde2e4qp0lxszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p858gupv4</id>
    
      <title type="html">I-O Data Confirms Zero-Day Attacks on Routers, Full Patches ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq6snzfze8sctrrnp4jjrclsq7j3cads7htf6mcctsde2e4qp0lxszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p858gupv4" />
    <content type="html">
      I-O Data Confirms Zero-Day Attacks on Routers, Full Patches Pending&lt;br/&gt;&lt;br/&gt;Japanese device maker I-O Data this week confirmed zero-day exploitation of critical flaws in multiple routers and warned that full patches won’t be available for a few weeks.&lt;br/&gt;&lt;br/&gt;According to a warning from incident responders at JPCERT/CC, the most serious flaw opens the door for a remote attacker to disable the router’s firewall, execute commands, or alter configurations.&lt;br/&gt;&lt;br/&gt;“The developer states that attacks exploiting these vulnerabilities have been observed,” according to the JPCERT/CC alert.&lt;br/&gt;&lt;br/&gt;A separate bulletin from IO-Data documents three separate defects — CVE-2024-45841, CVE-2024-47133 and CVE-2024-52564 — and warns of additional information disclosure and command execution risks.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/i-o-data-confirms-zero-day-attacks-on-routers-full-patches-pending/&#34;&gt;https://www.securityweek.com/i-o-data-confirms-zero-day-attacks-on-routers-full-patches-pending/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #zeroday #iodata
    </content>
    <updated>2024-12-06T07:22:03Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdj4v36d6egr5vphcdn6q0stxsltl5z6m29lwl5dtakxdtyqmjxfqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85v2mugk</id>
    
      <title type="html">Europol Shuts Down Manson Market Fraud Marketplace, Seizes 50 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdj4v36d6egr5vphcdn6q0stxsltl5z6m29lwl5dtakxdtyqmjxfqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85v2mugk" />
    <content type="html">
      Europol Shuts Down Manson Market Fraud Marketplace, Seizes 50 Servers&lt;br/&gt;&lt;br/&gt;Europol on Thursday announced the shutdown of a clearnet marketplace called Manson Market that facilitated online fraud on a large scale.&lt;br/&gt;&lt;br/&gt;The operation, led by German authorities, has resulted in the seizure of more than 50 servers associated with the service and the arrest of two suspects. More than 200 terabytes of digital evidence have been collected.&lt;br/&gt;&lt;br/&gt;In addition, over 80 data storage devices, cell phones, computers, as well as cash and crypto assets worth more than €63,000 ($66,500) have been confiscated.&lt;br/&gt;&lt;br/&gt;Manson Market (&amp;#34;manson-market[.]pw&amp;#34;) is believed to have launched in 2022 as a way to peddle sensitive information that was illegally obtained from victims as part of phishing and vishing (voice phishing) schemes.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/europol-shuts-down-manson-market-fraud.html&#34;&gt;https://thehackernews.com/2024/12/europol-shuts-down-manson-market-fraud.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;BleepingComputer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/police-shuts-down-manson-cybercrime-market-fake-shops-arrests-key-suspects/&#34;&gt;https://www.bleepingcomputer.com/news/security/police-shuts-down-manson-cybercrime-market-fake-shops-arrests-key-suspects/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybercrime #mansonmarket
    </content>
    <updated>2024-12-06T07:19:23Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstcn0rgtt0kjwuq8l5fr2nft267c628n2f7njv0rkqgwugqln4vggzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p854e89u4</id>
    
      <title type="html">Mitel MiCollab zero-day flaw gets proof-of-concept exploit ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstcn0rgtt0kjwuq8l5fr2nft267c628n2f7njv0rkqgwugqln4vggzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p854e89u4" />
    <content type="html">
      Mitel MiCollab zero-day flaw gets proof-of-concept exploit&lt;br/&gt;&lt;br/&gt;Researchers have uncovered an arbitrary file read zero-day in the Mitel MiCollab collaboration platform, allowing attackers to access files on a server&amp;#39;s filesystem.&lt;br/&gt;&lt;br/&gt;Mitel MiCollab is an enterprise collaboration platform that consolidates various communication tools into a single application, offering voice and video calling, messaging, presence information, audio conferencing, mobility support, and team collaboration functionalities.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s utilized by various organizations, including large corporations, small to medium-sized enterprises, and companies operating on a remote or hybrid workforce model.&lt;br/&gt;&lt;br/&gt;The latest vulnerability in the product was discovered by researchers at watchTowr, who, despite having reported to the vendor since August, it remains unfixed after 90 days of being disclosed and waiting for a patch.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;BleepingComputer: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/mitel-micollab-zero-day-flaw-gets-proof-of-concept-exploit/&#34;&gt;https://www.bleepingcomputer.com/news/security/mitel-micollab-zero-day-flaw-gets-proof-of-concept-exploit/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/critical-mitel-micollab-flaw-exposes.html&#34;&gt;https://thehackernews.com/2024/12/critical-mitel-micollab-flaw-exposes.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #micollab #zeroday
    </content>
    <updated>2024-12-06T07:13:23Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9ecx3u70xzx3qagkdkg332ff86lz6ywlj2rxlvyahwardrhmgvnszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85aeh6n9</id>
    
      <title type="html">CISA Warns of Active Exploitation of Flaws in Zyxel, ProjectSend, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9ecx3u70xzx3qagkdkg332ff86lz6ywlj2rxlvyahwardrhmgvnszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85aeh6n9" />
    <content type="html">
      CISA Warns of Active Exploitation of Flaws in Zyxel, ProjectSend, and CyberPanel&lt;br/&gt;&lt;br/&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added multiple security flaws affecting products from Zyxel, North Grid Proself, ProjectSend, and CyberPanel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/cisa-warns-of-active-exploitation-of.html&#34;&gt;https://thehackernews.com/2024/12/cisa-warns-of-active-exploitation-of.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #kev #cisa&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nevent1qqsxjd044g2vuagfsmseze3a724q6xpqnksej79rwf7800shm3n0dygpz4mhxue69uhkummnw3ezummcw3ezuer9wchsygqkl5n0qqz57es4r34a0yj7mm6ptpss8tce63zlj0mx7h3ykdzz0gpsgqqqqqqsrm83u9&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;nevent1q…83u9&lt;/a&gt;&lt;/span&gt; &lt;/div&gt; CISA Warns of Zyxel Firewall Vulnerability Exploited in Attacks&lt;br/&gt;&lt;br/&gt;The US cybersecurity agency CISA on Tuesday warned that a path traversal vulnerability in multiple Zyxel firewall appliances has been exploited in the wild.&lt;br/&gt;&lt;br/&gt;The issue, tracked as CVE-2024-11667 (CVSS score of 7.5), is a high-severity flaw affecting the web management interface of Zyxel ATP, USG FLEX, and USG20(W)-VPN series devices.&lt;br/&gt;&lt;br/&gt;Successful exploitation of the security defect could allow an attacker to download or upload files using crafted URLs, a NIST advisory reads.&lt;br/&gt;&lt;br/&gt;“An attacker may gain unauthorized access to the system, steal credentials, and create backdoor VPN connections by exploiting the vulnerability,” Qualys warned on Tuesday.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/cisa-warns-of-zyxel-firewall-vulnerability-exploited-in-attacks/&#34;&gt;https://www.securityweek.com/cisa-warns-of-zyxel-firewall-vulnerability-exploited-in-attacks/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #zyxel #exploit &lt;/blockquote&gt;
    </content>
    <updated>2024-12-05T07:30:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs05rtdkh49wawzznu56ekt5ee4m7e0pkugywmldl5x2par2z3e4mczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85mvm776</id>
    
      <title type="html">Security Risks Persist in Open Source Ecosystem Significant ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs05rtdkh49wawzznu56ekt5ee4m7e0pkugywmldl5x2par2z3e4mczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85mvm776" />
    <content type="html">
      Security Risks Persist in Open Source Ecosystem&lt;br/&gt;&lt;br/&gt;Significant security risks continue to be prevalent in open source software practices, a new report by the Linux Foundation, OpenSSF and Harvard University has found.&lt;br/&gt;&lt;br/&gt;The CENSUS III project was based on 12 million observations of free and open source software (FOSS) libraries used in production apps at over 10,000 companies. It highlighted a number of concerning cybersecurity practices relating to open source software, which is widely used across all industries.&lt;br/&gt;&lt;br/&gt;The project aims to provide a clearer picture of the structural issues that threaten the FOSS ecosystem.&lt;br/&gt;&lt;br/&gt;- Ongoing Reliance on Outdated Python 2 Language &lt;br/&gt;- Lack of Standardized Naming for Software Components &lt;br/&gt;- Open Source Security Dependent on Handful of Contributors&lt;br/&gt;- Heavy Reliance on Individual Developer Accounts&lt;br/&gt;- Legacy Software Remains Prevalent&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.infosecurity-magazine.com/news/security-risks-open-source/&#34;&gt;https://www.infosecurity-magazine.com/news/security-risks-open-source/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#opensource #cybersecurity
    </content>
    <updated>2024-12-05T07:28:33Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstd9f7mnh5qaylvta7rcfwyr4vln76elhxfdq5d793azpr504645qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ea3f2a</id>
    
      <title type="html">Pegasus Spyware Infections Proliferate Across iOS, Android ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstd9f7mnh5qaylvta7rcfwyr4vln76elhxfdq5d793azpr504645qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ea3f2a" />
    <content type="html">
      Pegasus Spyware Infections Proliferate Across iOS, Android Devices&lt;br/&gt;&lt;br/&gt;Researchers have discovered seven new Pegasus spyware infections targeting journalists, government officials, and corporate executives that started several years ago and span both iPhone and Android devices, demonstrating that the range of the notorious spyware may be even greater than once thought.&lt;br/&gt;&lt;br/&gt;Researchers from iVerify discovered multiple devices compromised by Israeli company NSO Group&amp;#39;s spyware via attacks initiated between 2021 and 2023 that affect Apple iPhone iOS versions 14, 15, and 16.6, as well as Android, they revealed in a blog post published on Dec. 4. The infections were discovered in May during a threat-hunting scan of 3,500 devices from iVerify users who opted in to the checks.&lt;br/&gt;&lt;br/&gt;Specifically, the investigation uncovered multiple Pegasus variants in five unique malware types across iOS and Android. The researchers detected forensic artifacts in diagnostic data, shutdown logs, and crash logs found on the devices.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.darkreading.com/endpoint-security/pegasus-spyware-infections-ios-android-devices&#34;&gt;https://www.darkreading.com/endpoint-security/pegasus-spyware-infections-ios-android-devices&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #pegasus #spyware
    </content>
    <updated>2024-12-05T07:22:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz2uz74frnmmk7h60a29rsqscaltzzsv3ed3hwu87mjhnrepu3e9szyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85yh3g3j</id>
    
      <title type="html">Six password takeaways from the updated NIST cybersecurity ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz2uz74frnmmk7h60a29rsqscaltzzsv3ed3hwu87mjhnrepu3e9szyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85yh3g3j" />
    <content type="html">
      Six password takeaways from the updated NIST cybersecurity framework&lt;br/&gt;&lt;br/&gt;Password security is changing — and updated guidelines from the National Institute of Standards and Technology (NIST) reject outdated practices in favor of more effective protections. &lt;br/&gt;&lt;br/&gt;Don&amp;#39;t have time to read the 35,000-word guidelines? No problem. Here are the six takeaways from NIST’s new guidance that your organization needs to know to create password policies that work.&lt;br/&gt;&lt;br/&gt;1. Password length &amp;gt; password complexity &lt;br/&gt;2. Facilitate longer passwords&lt;br/&gt;3. Implement MFA&lt;br/&gt;4. Avoid frequent password changes&lt;br/&gt;5. Prevent the use of already-breached passwords&lt;br/&gt;6. Discontinue password hints and other knowledge-based recovery&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/six-password-takeaways-from-the-updated-nist-cybersecurity-framework/&#34;&gt;https://www.bleepingcomputer.com/news/security/six-password-takeaways-from-the-updated-nist-cybersecurity-framework/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #password #passwordpolicy&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nevent1qqsz9r6f0uzsd47l4qxfgzdep028qskx08yrsugha732mk9yn5sna2cpzpmhxue69uhkummnw3ezumt0d5hsygqkl5n0qqz57es4r34a0yj7mm6ptpss8tce63zlj0mx7h3ykdzz0gpsgqqqqqqsuurkpd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;nevent1q…rkpd&lt;/a&gt;&lt;/span&gt; &lt;/div&gt; How to Plan a New (and Improved!) Password Policy for Real-World Security Challenges&lt;br/&gt;&lt;br/&gt;Many organizations struggle with password policies that look strong on paper but fail in practice because they&#39;re too rigid to follow, too vague to enforce, or disconnected from real security needs. &lt;br/&gt;&lt;br/&gt;Password policy must be strict enough to protect your systems, flexible enough for daily work, and precise enough to be enforced consistently. Let&#39;s explore five strategies for building a password policy that works in the real world.&lt;br/&gt;&lt;br/&gt;1. Build compliant password practices&lt;br/&gt;2. Review your existing password obligations&lt;br/&gt;3. Create a policy based on real data&lt;br/&gt;4. Put some muscle in your password policy&lt;br/&gt;5. Create password standards that stick&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/how-to-plan-new-and-improved-password.html&#34;&gt;https://thehackernews.com/2024/12/how-to-plan-new-and-improved-password.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #password #passwordpolicy &lt;/blockquote&gt;
    </content>
    <updated>2024-12-05T07:20:54Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2jqwavvwyg9usuut39az5ndvfv6kkrz2t796h72r5cgxqjjz0akgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p856cewat</id>
    
      <title type="html">Largest German Crime Marketplace Taken Down, Administrator ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2jqwavvwyg9usuut39az5ndvfv6kkrz2t796h72r5cgxqjjz0akgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p856cewat" />
    <content type="html">
      Largest German Crime Marketplace Taken Down, Administrator Arrested&lt;br/&gt;&lt;br/&gt;Authorities in Germany on Tuesday announced the takedown of Crimenetwork, which they describe as the largest German-speaking online marketplace for the underground economy.&lt;br/&gt;&lt;br/&gt;Crimenetwork has been around since 2012, being used to trade various types of illegal goods and services, including stolen information, drugs and counterfeit documents. Authorities said the platform had over 100,000 buyers and 100 sellers, most of them likely from German-speaking countries.&lt;br/&gt;&lt;br/&gt;Investigators determined that nearly $100 million in Bitcoin and Monero cryptocurrencies were transferred through Crimenetwork between 2018 and 2024. Operators received a commission of 1-5% from each sale. &lt;br/&gt;&lt;br/&gt;German police arrested an alleged administrator of the platform on Monday, seizing evidence, vehicles, and cryptocurrency worth roughly €1 million. &lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/largest-german-crime-marketplace-taken-down-administrator-arrested/&#34;&gt;https://www.securityweek.com/largest-german-crime-marketplace-taken-down-administrator-arrested/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#darknetmarketplace #dnm #crimenetrwork&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nevent1qqsyph0a7as9khjf4gpd3sjwk75s8aglw66t7rutsvppq9rucc9tnyqpz4mhxue69uhkummnw3ezummcw3ezuer9wchsygqkl5n0qqz57es4r34a0yj7mm6ptpss8tce63zlj0mx7h3ykdzz0gpsgqqqqqqssyjy3w&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;nevent1q…jy3w&lt;/a&gt;&lt;/span&gt; &lt;/div&gt; Europol Dismantles Criminal Messaging Service MATRIX in Major Global Takedown&lt;br/&gt;&lt;br/&gt;Europol on Tuesday announced the takedown of an invite-only encrypted messaging service called MATRIX that&#39;s created by criminals for criminal purposes.&lt;br/&gt;&lt;br/&gt;The joint operation, conducted by French and Dutch authorities under the moniker Passionflower, comes in the aftermath of an investigation that was launched in 2021 after the messaging service was discovered on the phone of a criminal convicted for the murder of a Dutch journalist Peter R. de Vries.&lt;br/&gt;&lt;br/&gt;This allowed authorities to intercept messages being sent via the service for a period of three months, amassing a total of more than 2.3 million messages in 33 languages. The messages, Europol said, are associated with serious crimes such as international drug trafficking, arms trafficking, and money laundering.&lt;br/&gt;&lt;br/&gt;It&#39;s worth noting at this stage that MATRIX is different from the open-source, decentralized messaging app of the same name (&#34;matrix[.]org&#34;). Also known by other names such as Mactrix, Totalsec, X-quantum, and Q-safe, it had at least 8,000 user accounts globally, who paid anywhere between $1,360 and $1,700 in cryptocurrency for a Google Pixel phone and a six-month subscription to the service installed on it.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/europol-dismantles-criminal-messaging.html&#34;&gt;https://thehackernews.com/2024/12/europol-dismantles-criminal-messaging.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #matrix &lt;/blockquote&gt;
    </content>
    <updated>2024-12-05T07:17:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyph0a7as9khjf4gpd3sjwk75s8aglw66t7rutsvppq9rucc9tnyqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ze8re4</id>
    
      <title type="html">Europol Dismantles Criminal Messaging Service MATRIX in Major ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyph0a7as9khjf4gpd3sjwk75s8aglw66t7rutsvppq9rucc9tnyqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ze8re4" />
    <content type="html">
      Europol Dismantles Criminal Messaging Service MATRIX in Major Global Takedown&lt;br/&gt;&lt;br/&gt;Europol on Tuesday announced the takedown of an invite-only encrypted messaging service called MATRIX that&amp;#39;s created by criminals for criminal purposes.&lt;br/&gt;&lt;br/&gt;The joint operation, conducted by French and Dutch authorities under the moniker Passionflower, comes in the aftermath of an investigation that was launched in 2021 after the messaging service was discovered on the phone of a criminal convicted for the murder of a Dutch journalist Peter R. de Vries.&lt;br/&gt;&lt;br/&gt;This allowed authorities to intercept messages being sent via the service for a period of three months, amassing a total of more than 2.3 million messages in 33 languages. The messages, Europol said, are associated with serious crimes such as international drug trafficking, arms trafficking, and money laundering.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s worth noting at this stage that MATRIX is different from the open-source, decentralized messaging app of the same name (&amp;#34;matrix[.]org&amp;#34;). Also known by other names such as Mactrix, Totalsec, X-quantum, and Q-safe, it had at least 8,000 user accounts globally, who paid anywhere between $1,360 and $1,700 in cryptocurrency for a Google Pixel phone and a six-month subscription to the service installed on it.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/europol-dismantles-criminal-messaging.html&#34;&gt;https://thehackernews.com/2024/12/europol-dismantles-criminal-messaging.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #matrix
    </content>
    <updated>2024-12-05T07:14:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz9r6f0uzsd47l4qxfgzdep028qskx08yrsugha732mk9yn5sna2czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85kp5vsu</id>
    
      <title type="html">How to Plan a New (and Improved!) Password Policy for Real-World ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz9r6f0uzsd47l4qxfgzdep028qskx08yrsugha732mk9yn5sna2czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85kp5vsu" />
    <content type="html">
      How to Plan a New (and Improved!) Password Policy for Real-World Security Challenges&lt;br/&gt;&lt;br/&gt;Many organizations struggle with password policies that look strong on paper but fail in practice because they&amp;#39;re too rigid to follow, too vague to enforce, or disconnected from real security needs. &lt;br/&gt;&lt;br/&gt;Password policy must be strict enough to protect your systems, flexible enough for daily work, and precise enough to be enforced consistently. Let&amp;#39;s explore five strategies for building a password policy that works in the real world.&lt;br/&gt;&lt;br/&gt;1. Build compliant password practices&lt;br/&gt;2. Review your existing password obligations&lt;br/&gt;3. Create a policy based on real data&lt;br/&gt;4. Put some muscle in your password policy&lt;br/&gt;5. Create password standards that stick&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/how-to-plan-new-and-improved-password.html&#34;&gt;https://thehackernews.com/2024/12/how-to-plan-new-and-improved-password.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #password #passwordpolicy
    </content>
    <updated>2024-12-05T07:10:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9wvkw7tk630gzcadqxwe58klxhhesqvpzfxpa7kfe273pm7pttuczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85c7dr0s</id>
    
      <title type="html">Russian hackers hijack Pakistani hackers&amp;#39; servers for their ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9wvkw7tk630gzcadqxwe58klxhhesqvpzfxpa7kfe273pm7pttuczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85c7dr0s" />
    <content type="html">
      Russian hackers hijack Pakistani hackers&amp;#39; servers for their own attacks&lt;br/&gt;&lt;br/&gt;The notorious Russian cyber-espionage group Turla is hacking other hackers, hijacking the Pakistani threat actor Storm-0156&amp;#39;s infrastructure to launch their own covert attacks on already compromised networks.&lt;br/&gt;&lt;br/&gt;Using this tactic, Turla (aka &amp;#34;Secret Blizzard&amp;#34;) accessed networks Storm-0156 had previously breached, like in Afghan and Indian government organizations, and deployed their malware tools.&lt;br/&gt;&lt;br/&gt;According to a report from Lumen&amp;#39;s Black Lotus Labs, which tracked this campaign since January 2023 with the help of Microsoft&amp;#39;s Threat Intelligence Team, the Turla operation has been underway since December 2022.&lt;br/&gt;&lt;br/&gt;Turla (aka Secret Blizzard) is a Russian state-sponsored hacking group linked to Center 16 of Russia&amp;#39;s Federal Security Service (FSB), the unit responsible for the interception, decoding, and collection of data from foreign targets.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/russian-turla-hackers-hijack-pakistani-apt-servers-for-cyber-espionage-attacks/&#34;&gt;https://www.bleepingcomputer.com/news/security/russian-turla-hackers-hijack-pakistani-apt-servers-for-cyber-espionage-attacks/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #turla #espionage
    </content>
    <updated>2024-12-05T07:06:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsttqcl3kx8ru9ecv63l9sh3mlntk8jdxdv82mcnyty5r5gu4j73xczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85q2typ8</id>
    
      <title type="html">New DroidBot Android malware targets 77 banking, crypto apps A ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsttqcl3kx8ru9ecv63l9sh3mlntk8jdxdv82mcnyty5r5gu4j73xczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85q2typ8" />
    <content type="html">
      New DroidBot Android malware targets 77 banking, crypto apps&lt;br/&gt;&lt;br/&gt;A new Android banking malware named &amp;#39;DroidBot&amp;#39; attempts to steal credentials for over 77 cryptocurrency exchanges and banking apps in the UK, Italy, France, Spain, and Portugal.&lt;br/&gt;&lt;br/&gt;According to Cleafy researchers who discovered the new Android malware, DroidBot has been active since June 2024 and operates as a malware-as-a-service (MaaS) platform, selling the tool for $3,000/month.&lt;br/&gt;&lt;br/&gt;At least 17 affiliate groups have been identified using malware builders to customize their payloads for specific targets.&lt;br/&gt;&lt;br/&gt;DroidBot&amp;#39;s developers, who appear to be Turkish, provide affiliates with all the tools required to conduct attacks. This includes the malware builder, command and control (C2) servers, and a central administration panel from which they can control their operations, retrieve stolen data, and issue commands.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/new-droidbot-android-malware-targets-77-banking-crypto-apps/&#34;&gt;https://www.bleepingcomputer.com/news/security/new-droidbot-android-malware-targets-77-banking-crypto-apps/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #android #malware
    </content>
    <updated>2024-12-05T07:01:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvn9rc7kcajfkc8c6fpad66mu97ptwmrkjj9m70sn5adgt6lchxgczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85vrfef4</id>
    
      <title type="html">Android’s December 2024 Security Update Patches 14 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvn9rc7kcajfkc8c6fpad66mu97ptwmrkjj9m70sn5adgt6lchxgczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85vrfef4" />
    <content type="html">
      Android’s December 2024 Security Update Patches 14 Vulnerabilities&lt;br/&gt;&lt;br/&gt;Google on Tuesday announced patches for 14 high-severity vulnerabilities as part of Android’s December 2024 security update, including a remote code execution flaw in the System component.&lt;br/&gt;&lt;br/&gt;The first part of the update, which arrives on devices as the 2024-12-01 security patch level, resolves six security defects in the Framework and System components, five of which could allow attackers to elevate privileges.&lt;br/&gt;&lt;br/&gt;According to Google’s advisory, however, the sixth of these bugs, which is tracked as CVE-2024-43767 and impacts System, is the most severe issue, as it could lead to remote code execution (RCE) with no additional execution privileges needed.&lt;br/&gt;&lt;br/&gt;Fixes for these defects were included in updated Android 12, 12L, 13, 14, and 15 versions and the source code for these patches has been released to the Android Open Source Project (AOSP) repository.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/androids-december-2024-security-update-patches-14-vulnerabilities/&#34;&gt;https://www.securityweek.com/androids-december-2024-security-update-patches-14-vulnerabilities/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #android
    </content>
    <updated>2024-12-05T06:58:33Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxjd044g2vuagfsmseze3a724q6xpqnksej79rwf7800shm3n0dygzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85y089t2</id>
    
      <title type="html">CISA Warns of Zyxel Firewall Vulnerability Exploited in Attacks ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxjd044g2vuagfsmseze3a724q6xpqnksej79rwf7800shm3n0dygzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85y089t2" />
    <content type="html">
      CISA Warns of Zyxel Firewall Vulnerability Exploited in Attacks&lt;br/&gt;&lt;br/&gt;The US cybersecurity agency CISA on Tuesday warned that a path traversal vulnerability in multiple Zyxel firewall appliances has been exploited in the wild.&lt;br/&gt;&lt;br/&gt;The issue, tracked as CVE-2024-11667 (CVSS score of 7.5), is a high-severity flaw affecting the web management interface of Zyxel ATP, USG FLEX, and USG20(W)-VPN series devices.&lt;br/&gt;&lt;br/&gt;Successful exploitation of the security defect could allow an attacker to download or upload files using crafted URLs, a NIST advisory reads.&lt;br/&gt;&lt;br/&gt;“An attacker may gain unauthorized access to the system, steal credentials, and create backdoor VPN connections by exploiting the vulnerability,” Qualys warned on Tuesday.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/cisa-warns-of-zyxel-firewall-vulnerability-exploited-in-attacks/&#34;&gt;https://www.securityweek.com/cisa-warns-of-zyxel-firewall-vulnerability-exploited-in-attacks/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #zyxel #exploit
    </content>
    <updated>2024-12-05T06:56:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswwrykjrhu73njaxpwnnxs62tm647xq9uh9vurtzmn6fw8c6gk7cszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ql64ly</id>
    
      <title type="html">Researchers Uncover Backdoor in Solana&amp;#39;s Popular Web3[.]js ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswwrykjrhu73njaxpwnnxs62tm647xq9uh9vurtzmn6fw8c6gk7cszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85ql64ly" />
    <content type="html">
      Researchers Uncover Backdoor in Solana&amp;#39;s Popular Web3[.]js npm Library&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers are alerting to a software supply chain attack targeting the popular @solana/web3[.]js npm library that involved pushing two malicious versions capable of harvesting users&amp;#39; private keys with an aim to drain their cryptocurrency wallets.&lt;br/&gt;&lt;br/&gt;The attack has been detected in versions 1.95.6 and 1.95.7. Both these versions are no longer available for download from the npm registry. The package is widely used, attracting over 400,000 weekly downloads.&lt;br/&gt;&lt;br/&gt;&amp;#34;These compromised versions contain injected malicious code that is designed to steal private keys from unsuspecting developers and users, potentially enabling attackers to drain cryptocurrency wallets,&amp;#34; Socket said in a report.&lt;br/&gt;&lt;br/&gt;@solana/web3[.]js is an npm package that can be used to interact with the Solana JavaScript software development kit (SDK) for building Node[.]js and web apps.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;The Hacker News: &lt;a href=&#34;https://thehackernews.com/2024/12/researchers-uncover-backdoor-in-solanas.html&#34;&gt;https://thehackernews.com/2024/12/researchers-uncover-backdoor-in-solanas.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;SecurityWeek:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/solana-web3-js-library-backdoored-in-supply-chain-attack/&#34;&gt;https://www.securityweek.com/solana-web3-js-library-backdoored-in-supply-chain-attack/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;BleepingComputer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/solana-web3js-library-backdoored-to-steal-secret-private-keys/&#34;&gt;https://www.bleepingcomputer.com/news/security/solana-web3js-library-backdoored-to-steal-secret-private-keys/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #solana #malware #c2
    </content>
    <updated>2024-12-05T06:51:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf9mgsqgjhkpmcs24wujrxwd0s3nahmp7ytjtwj9u6wjyd9g9uyvczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85cazjq2</id>
    
      <title type="html">Critical SailPoint IdentityIQ Vulnerability Exposes Files to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf9mgsqgjhkpmcs24wujrxwd0s3nahmp7ytjtwj9u6wjyd9g9uyvczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85cazjq2" />
    <content type="html">
      Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access&lt;br/&gt;&lt;br/&gt;A critical security vulnerability has been disclosed in SailPoint&amp;#39;s IdentityIQ identity and access management (IAM) software that allows unauthorized access to content stored within the application directory.&lt;br/&gt;&lt;br/&gt;The flaw, tracked as CVE-2024-10905, has a CVSS score of 10.0, indicating maximum severity. It affects IdentityIQ versions 8.2. 8.3, 8.4, and other previous versions.&lt;br/&gt;&lt;br/&gt;IdentityIQ &amp;#34;allows HTTP access to static content in the IdentityIQ application directory that should be protected,&amp;#34; according to a description of the flaw on NIST&amp;#39;s National Vulnerability Database (NVD).&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/critical-sailpoint-identityiq.html&#34;&gt;https://thehackernews.com/2024/12/critical-sailpoint-identityiq.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #identityq
    </content>
    <updated>2024-12-04T07:08:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs03rd9s8s4ed4p8ckvdy8rmvkwnmthawwj5tsjzsd477vhjpjrz9czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xs2dxh</id>
    
      <title type="html">With Threats to Encryption Looming, Signal’s Meredith Whittaker ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs03rd9s8s4ed4p8ckvdy8rmvkwnmthawwj5tsjzsd477vhjpjrz9czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85xs2dxh" />
    <content type="html">
      With Threats to Encryption Looming, Signal’s Meredith Whittaker Says ‘We’re Not Changing’&lt;br/&gt;&lt;br/&gt;At WIRED’s The Big Interview event, the president of the Signal Foundation talked about secure communications as critical infrastructure and the need for a new funding paradigm for tech.&lt;br/&gt;&lt;br/&gt;The secure messaging app Signal is famous for knowing as little about its users as possible. The app isn’t hoarding metadata, tracking you, or showing you ads—in other words, it’s not monetizing user data. Instead, the Signal Foundation is a nonprofit. Its president, Meredith Whittaker, sees a massive shift underway and an “invitation for action” as the monoliths of Big Tech lose popularity and the old economics of Silicon Valley become brittle.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.wired.com/story/big-interview-meredith-whittaker-signal-2024/&#34;&gt;https://www.wired.com/story/big-interview-meredith-whittaker-signal-2024/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#signal #privacy
    </content>
    <updated>2024-12-04T07:03:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspg78nd5zu5lhdf7cj93f36alc5dp806t05mqm2avu4yppsyn794czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85gc3j7a</id>
    
      <title type="html">Veeam warns of critical RCE bug in Service Provider Console Veeam ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspg78nd5zu5lhdf7cj93f36alc5dp806t05mqm2avu4yppsyn794czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85gc3j7a" />
    <content type="html">
      Veeam warns of critical RCE bug in Service Provider Console&lt;br/&gt;&lt;br/&gt;Veeam released security updates today to address two Service Provider Console (VSPC) vulnerabilities, including a critical remote code execution (RCE) discovered during internal testing.&lt;br/&gt;&lt;br/&gt;VSPC, described by the company as a remote-managed BaaS (Backend as a Service) and DRaaS (Disaster Recovery as a Service) platform, is used by service providers to monitor the health and security of customer backups, as well as manage their Veeam-protected virtual, Microsoft 365, and public cloud workloads.&lt;br/&gt;&lt;br/&gt;The first security flaw fixed today (tracked as CVE-2024-42448 and rated with a 9.9/10 severity score) enables attackers to execute arbitrary code on unpatched servers from the VSPC management agent machine.&lt;br/&gt;&lt;br/&gt;Veeam also patched a high-severity vulnerability (CVE-2024-42449) that can let attackers steal the NTLM hash of the VSPC server service account and use the gained access to delete files on the VSPC server.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;BleepingComputer: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-rce-bug-in-service-provider-console/&#34;&gt;https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-rce-bug-in-service-provider-console/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hackers News: &lt;a href=&#34;https://thehackernews.com/2024/12/veeam-issues-patch-for-critical-rce.html&#34;&gt;https://thehackernews.com/2024/12/veeam-issues-patch-for-critical-rce.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #rce #veeam
    </content>
    <updated>2024-12-04T07:01:04Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszt6q89nyjqca59lhknvtrvujtxz507ldevlvrd6jl34ynf3hc6vczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p850krfs7</id>
    
      <title type="html">Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszt6q89nyjqca59lhknvtrvujtxz507ldevlvrd6jl34ynf3hc6vczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p850krfs7" />
    <content type="html">
      Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and Email Defenses:&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have called attention to a novel phishing campaign that leverages corrupted Microsoft Office documents and ZIP archives as a way to bypass email defenses.&lt;br/&gt;&lt;br/&gt;&amp;#34;The ongoing attack evades #antivirus software, prevents uploads to sandboxes, and bypasses Outlook&amp;#39;s spam filters, allowing the malicious emails to reach your inbox,&amp;#34; ANY[.]RUN said in a series of posts on X.&lt;br/&gt;&lt;br/&gt;The malicious activity entails sending emails containing ZIP archives or Office attachments that are intentionally corrupted in such a way that they cannot be scanned by security tools. These messages aim to trick users into opening the attachments with false promises of employee benefits and bonuses.&lt;br/&gt;&lt;br/&gt;In other words, the corrupted state of the files means that they are not flagged as suspicious or malicious by email filters and antivirus software. However, the attack still works because it takes advantage of the built-in recovery mechanisms of programs like Word, Outlook, and WinRAR to relaunch such damaged files in recovery mode&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/hackers-use-corrupted-zips-and-office.html&#34;&gt;https://thehackernews.com/2024/12/hackers-use-corrupted-zips-and-office.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #malware
    </content>
    <updated>2024-12-04T06:57:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspm4w9d2farjgjw7y2y2yyqmv6lzcxqd62fth0rh2yen6ltrhhcygzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85pwj4sa</id>
    
      <title type="html">New EU Regulation Establishes European ‘Cybersecurity Shield’ ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspm4w9d2farjgjw7y2y2yyqmv6lzcxqd62fth0rh2yen6ltrhhcygzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85pwj4sa" />
    <content type="html">
      New EU Regulation Establishes European ‘Cybersecurity Shield’&lt;br/&gt;&lt;br/&gt;The Council of the European Union on Monday announced the adoption of two new laws meant to improve the overall cybersecurity across the EU.&lt;br/&gt;&lt;br/&gt;The two new laws in the cybersecurity package establish a cybersecurity shield that calls for member states to cooperate in detecting and responding to cyberattacks, and amend the EU’s Cybersecurity Act (CSA) of 2019 to ensure adequate security standards for managed security services.&lt;br/&gt;&lt;br/&gt;The first legislative act (PDF) establishes a European Cybersecurity Alert System, a pan-European network of cyberhubs that creates “coordinated detection and situational awareness capabilities, reinforcing the Union’s threat detection and information-sharing capabilities”.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.securityweek.com/new-eu-regulation-establishes-european-cybersecurity-shield/&#34;&gt;https://www.securityweek.com/new-eu-regulation-establishes-european-cybersecurity-shield/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #eu
    </content>
    <updated>2024-12-04T06:53:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfzulxcclqwzhv3dnac3wv0qzwpvaknrldjgskfhaajypm6zpxjcczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85qvefva</id>
    
      <title type="html">Cloudflare’s developer domains increasingly abused by threat ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfzulxcclqwzhv3dnac3wv0qzwpvaknrldjgskfhaajypm6zpxjcczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85qvefva" />
    <content type="html">
      Cloudflare’s developer domains increasingly abused by threat actors&lt;br/&gt;&lt;br/&gt;Cloudflare&amp;#39;s &amp;#39;pages.dev&amp;#39; and &amp;#39;workers.dev&amp;#39; domains, used for deploying web pages and facilitating serverless computing, are being increasingly abused by cybercriminals for phishing and other malicious activities.&lt;br/&gt;&lt;br/&gt;According to cybersecurity firm Fortra, the abuse of these domains has risen between 100% and 250% compared to 2023.&lt;br/&gt;&lt;br/&gt;The researchers believe the use of these domains is aimed at improving the legitimacy and effectiveness of these malicious campaigns, taking advantage of Cloudflare&amp;#39;s trusted branding, service reliability, low usage costs, and reverse proxying options that complicate detection.&lt;br/&gt;&lt;br/&gt;Cloudflare Pages is a platform designed for front-end developers to build, deploy, and host fast, scalable websites directly on Cloudflare&amp;#39;s global Content Delivery Network (CDN).&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/cloudflares-developer-domains-increasingly-abused-by-threat-actors/&#34;&gt;https://www.bleepingcomputer.com/news/security/cloudflares-developer-domains-increasingly-abused-by-threat-actors/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #phishing #cloudflare
    </content>
    <updated>2024-12-04T06:51:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswrvpkt8nzw3wve3c2t4hhd59wps5d8cd8agwgav4d5gnukn82wggzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85q6umns</id>
    
      <title type="html">Exploit released for critical WhatsUp Gold RCE flaw, patch now A ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswrvpkt8nzw3wve3c2t4hhd59wps5d8cd8agwgav4d5gnukn82wggzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85q6umns" />
    <content type="html">
      Exploit released for critical WhatsUp Gold RCE flaw, patch now&lt;br/&gt;&lt;br/&gt;A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon as possible.&lt;br/&gt;&lt;br/&gt;The flaw is tracked as CVE-2024-8785 (CVSS v3.1 score: 9.8) and was discovered by Tenable in mid-August 2024. It exists in the NmAPI[.]exe process in WhatsUp Gold versions from 2023.1.0 and before 24.0.1.&lt;br/&gt;&lt;br/&gt;When launched, NmAPI[.]exe provides a network management API interface for WhatsUp Gold, listening for and processing incoming requests.&lt;br/&gt;&lt;br/&gt;Due to insufficient validation of incoming data, attackers could send specially crafted requests to modify or overwrite sensitive Windows registry keys that control where WhatsUp Gold configuration files are read from.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/exploit-released-for-critical-whatsup-gold-rce-flaw-patch-now/&#34;&gt;https://www.bleepingcomputer.com/news/security/exploit-released-for-critical-whatsup-gold-rce-flaw-patch-now/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #rce #whatsup
    </content>
    <updated>2024-12-04T06:47:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp446wfyeckt0ftvj9yjmxtp33en0x7ad2fjfyshc8x07cpd5qhhczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85vrh4gm</id>
    
      <title type="html">Cisco Warns of Exploitation of Decade-Old ASA WebVPN ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp446wfyeckt0ftvj9yjmxtp33en0x7ad2fjfyshc8x07cpd5qhhczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85vrh4gm" />
    <content type="html">
      Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability&lt;br/&gt;&lt;br/&gt;Cisco on Monday updated an advisory to warn customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA).&lt;br/&gt;&lt;br/&gt;The vulnerability, tracked as CVE-2014-2120 (CVSS score: 4.3), concerns a case of insufficient input validation in ASA&amp;#39;s WebVPN login page that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a targeted user of the appliance.&lt;br/&gt;&lt;br/&gt;&amp;#34;An attacker could exploit this vulnerability by convincing a user to access a malicious link,&amp;#34; Cisco noted in an alert released in March 2014.&lt;br/&gt;&lt;br/&gt;As of December 2, 2024, the networking equipment major has revised its bulletin to note that it has become aware of &amp;#34;additional attempted exploitation&amp;#34; of the vulnerability in the wild.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/cisco-warns-of-exploitation-of-decade.html&#34;&gt;https://thehackernews.com/2024/12/cisco-warns-of-exploitation-of-decade.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #xss #webvpn
    </content>
    <updated>2024-12-04T06:42:54Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp0mf6hv3dn063aahc7hr0euyaurtje8r69d5ny9lp7rc49qnytvqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85mkwwrw</id>
    
      <title type="html">760,000 Employee Records From Several Major Firms Leaked Online ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp0mf6hv3dn063aahc7hr0euyaurtje8r69d5ny9lp7rc49qnytvqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85mkwwrw" />
    <content type="html">
      760,000 Employee Records From Several Major Firms Leaked Online&lt;br/&gt;&lt;br/&gt;The information of more than 760,000 employees of several major organizations emerged online on Monday morning after a threat actor dumped it on a popular hacking forum.&lt;br/&gt;&lt;br/&gt;The data apparently originates from last year’s massive MOVEit hack, in which a zero-day vulnerability in Progress Software’s file transfer software was used to steal sensitive information from thousands of organizations.&lt;br/&gt;&lt;br/&gt;Roughly 2,800 organizations and close to 100 million individuals were affected by the attack, which is believed to have been carried out by the Russia-linked Cl0p ransomware gang.&lt;br/&gt; &lt;a href=&#34;https://www.securityweek.com/760000-employee-records-from-several-major-firms-leaked-online/&#34;&gt;https://www.securityweek.com/760000-employee-records-from-several-major-firms-leaked-online/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #databreach #moveit
    </content>
    <updated>2024-12-04T06:38:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqj520whu2sfjtas75v84jpw55xlkmtlwfker86eu36u0tgjt9j7gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85wjpyrm</id>
    
      <title type="html">Horns&amp;amp;Hooves Campaign Delivers RATs via Fake Emails and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqj520whu2sfjtas75v84jpw55xlkmtlwfker86eu36u0tgjt9j7gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85wjpyrm" />
    <content type="html">
      Horns&amp;amp;Hooves Campaign Delivers RATs via Fake Emails and JavaScript Payloads&lt;br/&gt;&lt;br/&gt;A newly discovered malware campaign has been found to target private users, retailers, and service businesses mainly located in Russia to deliver NetSupport RAT and BurnsRAT.&lt;br/&gt;&lt;br/&gt;The campaign, dubbed Horns&amp;amp;Hooves by Kaspersky, has hit more than 1,000 victims since it began around March 2023. The end goal of these attacks is to leverage the access afforded by these trojans to install stealer malware such as Rhadamanthys and Meduza.&lt;br/&gt;&lt;br/&gt;&amp;#34;Recent months have seen a surge in mailings with lookalike email attachments in the form of a ZIP archive containing JScript scripts,&amp;#34; security researcher Artem Ushkov said in a Monday analysis. &amp;#34;The script files [are] disguised as requests and bids from potential customers or partners.&amp;#34;&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/12/horns-campaign-delivers-rats-via-fake.html&#34;&gt;https://thehackernews.com/2024/12/horns-campaign-delivers-rats-via-fake.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #malware
    </content>
    <updated>2024-12-03T14:20:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszgpu2h5e246g8jlf3gu3pn66u30fa4vw79ndgszhwg725du8dyzszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p853lnrat</id>
    
      <title type="html">Hackers Stole $1.49 Billion in Cryptocurrency to Date in 2024 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszgpu2h5e246g8jlf3gu3pn66u30fa4vw79ndgszhwg725du8dyzszyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p853lnrat" />
    <content type="html">
      Hackers Stole $1.49 Billion in Cryptocurrency to Date in 2024&lt;br/&gt;&lt;br/&gt;Nearly $1.49 billion in cryptocurrency losses have been registered to date in 2024, mainly due to hacking incidents, a new report from web3 bug bounty platform Immunefi shows.&lt;br/&gt;&lt;br/&gt;The total year-to-date losses have dropped compared to last year, when they surpassed $1.75 billion during the period, and were mainly driven by losses of over $359 million in May and of more than $282 million in July.&lt;br/&gt;&lt;br/&gt;In November, cryptocurrency losses surpassed $71 million, mainly due to hacks ($70,996,200), with only a small percentage lost to rug pulls ($25,300). Total losses were 79% lower compared to November 2023, when they exceeded $343 million.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/hackers-stole-1-49-billion-in-cryptocurrency-to-date-in-2024/&#34;&gt;https://www.securityweek.com/hackers-stole-1-49-billion-in-cryptocurrency-to-date-in-2024/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #cryptocurrency #defi
    </content>
    <updated>2024-12-03T14:17:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxfsx0psf6lwyrepxq6xvh8pqxdqfd83hk3rppp0krvdvqmhgwt5gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8585u7wd</id>
    
      <title type="html">BootKitty UEFI malware exploits LogoFAIL to infect Linux systems ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxfsx0psf6lwyrepxq6xvh8pqxdqfd83hk3rppp0krvdvqmhgwt5gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8585u7wd" />
    <content type="html">
      BootKitty UEFI malware exploits LogoFAIL to infect Linux systems&lt;br/&gt;&lt;br/&gt;The recently uncovered &amp;#39;Bootkitty&amp;#39; Linux UEFI bootkit exploits the LogoFAIL flaw, tracked as CVE-2023-40238, to target computers running on vulnerable firmware.&lt;br/&gt;&lt;br/&gt;This is confirmed by firmware security firm Binarly, which discovered LogoFAIL in November 2023 and warned about its potential to be used in actual attacks.&lt;br/&gt;&lt;br/&gt;Bootkitty and LogoFAIL connection&lt;br/&gt;Bootkitty was discovered by ESET, who published a report last week, noting that it is the first UEFI bootkit specifically targeting Linux. However, at this time, it is more of an in-development UEFI malware that only works on specific Ubuntu versions, rather than a widespread threat.&lt;br/&gt;&lt;br/&gt;LogoFAIL is a set of flaws in the image-parsing code of UEFI firmware images used by various hardware vendors, exploitable by malicious images or logos planted on the EFI System Partition (ESP).&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/bootkitty-uefi-malware-exploits-logofail-to-infect-linux-systems/&#34;&gt;https://www.bleepingcomputer.com/news/security/bootkitty-uefi-malware-exploits-logofail-to-infect-linux-systems/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #linux #uefi
    </content>
    <updated>2024-12-03T14:13:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspefzje83epx6xpx4flc9zhzl7jnz9llageatqtw2m78h6t09n5sqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rn7hmx</id>
    
      <title type="html">SpyLoan Android malware on Google Play installed 8 million times ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspefzje83epx6xpx4flc9zhzl7jnz9llageatqtw2m78h6t09n5sqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85rn7hmx" />
    <content type="html">
      SpyLoan Android malware on Google Play installed 8 million times&lt;br/&gt;&lt;br/&gt;A new set of 15 SpyLoan Android malware apps with over 8 million installs was discovered on Google Play, targeting primarily users from South America, Southeast Asia, and Africa.&lt;br/&gt;&lt;br/&gt;The apps were discovered by McAfee, a member of the &amp;#39;App Defense Alliance,&amp;#39; and have now been removed from Android&amp;#39;s official app store.&lt;br/&gt;&lt;br/&gt;However, their presence on Google Play is indicative of the threat actors&amp;#39; persistence, as even recent law enforcement actions against SpyLoan operators have not curbed the issue, says McAfee.&lt;br/&gt;&lt;br/&gt;The last major &amp;#34;SpyLoan cleanup&amp;#34; on Google Play was in December 2023, when over a dozen apps that had amassed 12 million downloads were removed.&lt;br/&gt;&lt;br/&gt;See more&lt;br/&gt;BleepingComputer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/spyloan-android-malware-on-google-play-installed-8-million-times/&#34;&gt;https://www.bleepingcomputer.com/news/security/spyloan-android-malware-on-google-play-installed-8-million-times/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/12/8-million-android-users-hit-by-spyloan.html&#34;&gt;https://thehackernews.com/2024/12/8-million-android-users-hit-by-spyloan.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #android #malware
    </content>
    <updated>2024-12-03T14:06:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgzzzg7988xg3nmp2mu37lmvxt5hwlp2zgkdvy95qa8lm8ezlee0czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85fy5hxj</id>
    
      <title type="html">Location tracking of phones is out of control. Here’s how to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgzzzg7988xg3nmp2mu37lmvxt5hwlp2zgkdvy95qa8lm8ezlee0czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85fy5hxj" />
    <content type="html">
      Location tracking of phones is out of control. Here’s how to fight back.&lt;br/&gt;&lt;br/&gt;Unique IDs assigned to Android and iOS devices threaten your privacy. Who knew?&lt;br/&gt;&lt;br/&gt;You likely have never heard of Babel Street or Location X, but chances are good that they know a lot about you and anyone else you know who keeps a phone nearby around the clock.&lt;br/&gt;&lt;br/&gt;Reston, Virginia-located Babel Street is the little-known firm behind Location X, a service with the capability to track the locations of hundreds of millions of phone users over sustained periods of time.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;&lt;a href=&#34;https://arstechnica.com/information-technology/2024/10/phone-tracking-tool-lets-government-agencies-follow-your-every-move/&#34;&gt;https://arstechnica.com/information-technology/2024/10/phone-tracking-tool-lets-government-agencies-follow-your-every-move/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#privacy #tracking #mobile
    </content>
    <updated>2024-12-01T07:56:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy6wdw0j8zejudvvez456t7wcrfvljur7extpetmqr3vdh8wt779qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8552utnw</id>
    
      <title type="html">Zello asks users to reset passwords after security incident Zello ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy6wdw0j8zejudvvez456t7wcrfvljur7extpetmqr3vdh8wt779qzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8552utnw" />
    <content type="html">
      Zello asks users to reset passwords after security incident&lt;br/&gt;&lt;br/&gt;Zello is warning customers to reset their passwords if their account was created before November 2nd in what appears to be another security breach.&lt;br/&gt;&lt;br/&gt;Zello is a mobile service with 140 million users that allows first responders, hospitality services, transportation, and family and friends to communicate via their mobile phones using a push-to-talk app.&lt;br/&gt;&lt;br/&gt;Over the past two weeks, numerous people have received security notices from Zello on November 15th asking them to reset their app password.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/zello-asks-users-to-reset-passwords-after-security-incident/&#34;&gt;https://www.bleepingcomputer.com/news/security/zello-asks-users-to-reset-passwords-after-security-incident/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #zello
    </content>
    <updated>2024-11-28T23:45:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszpd2qyqtjww472w8h3x6sy9v6v76gv2w5auyxj6al09fzvwrd2fgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8560xar0</id>
    
      <title type="html">U.S. Telecom Giant T-Mobile Detects Network Intrusion Attempts ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszpd2qyqtjww472w8h3x6sy9v6v76gv2w5auyxj6al09fzvwrd2fgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p8560xar0" />
    <content type="html">
      U.S. Telecom Giant T-Mobile Detects Network Intrusion Attempts from Wireline Provider&lt;br/&gt;&lt;br/&gt;U.S. telecom service provider T-Mobile said it recently detected attempts made by bad actors to infiltrate its systems in recent weeks but noted that no sensitive data was accessed.&lt;br/&gt;&lt;br/&gt;These intrusion attempts &amp;#34;originated from a wireline provider&amp;#39;s network that was connected to ours,&amp;#34; Jeff Simon, chief security officer at T-Mobile, said in a statement. &amp;#34;We see no instances of prior attempts like this.&amp;#34;&lt;br/&gt;&lt;br/&gt;The company further said its security defenses prevented the threat actors from disrupting its services or obtaining customer information. It has since confirmed that it cut off connectivity to the unnamed provider&amp;#39;s network. It did not explicitly attribute the activity to any known threat actor or group, but noted that it has shared its findings with the U.S. government.&lt;br/&gt;&lt;br/&gt;See more&lt;br/&gt;The Hacker News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/11/us-telecom-giant-t-mobile-detects.html&#34;&gt;https://thehackernews.com/2024/11/us-telecom-giant-t-mobile-detects.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Bleeping Computer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/chinese-hackers-breached-t-mobiles-routers-to-scope-out-network/&#34;&gt;https://www.bleepingcomputer.com/news/security/chinese-hackers-breached-t-mobiles-routers-to-scope-out-network/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;SecurityWeek:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/t-mobile-shares-more-information-on-china-linked-cyberattack/&#34;&gt;https://www.securityweek.com/t-mobile-shares-more-information-on-china-linked-cyberattack/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity 
    </content>
    <updated>2024-11-28T23:44:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrfwsasg894z2x9vjve9c02am0n6rpeka5n6s00wdtu9w2rxnft2czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85lr5dnp</id>
    
      <title type="html">#nevent1q…zspd</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrfwsasg894z2x9vjve9c02am0n6rpeka5n6s00wdtu9w2rxnft2czyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85lr5dnp" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg8dcf6jyleavednzq0u0x3q5ga6z23nffdag4wxhme4nwd8lqzvqwnk7s5&#39;&gt;nevent1q…k7s5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nevent1qqsfxuaveetq478ft0ycf5zqqzahl245luzky6tn98e6fr4yz63q0xcpz4mhxue69uhkummnw3ezummcw3ezuer9wchsygpplt8hdyv0kg7gfsdujdr7pgdt4z9lxsh9xjvs9hctnum7n0nnzqpsgqqqqqqscxzspd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;nevent1q…zspd&lt;/a&gt;&lt;/span&gt; &lt;/div&gt; We&#39;re calling on the Tor &amp; Internet freedom community to help scale up WebTunnel bridges. Ever thought about running a Tor bridge? Now is the time! Our goal is to deploy 200 new WebTunnel bridges by the end of this year to open secure access for users in Russia.🕸️🌉 &lt;a href=&#34;https://blog.torproject.org/call-for-webtunnel-bridges/&#34;&gt;https://blog.torproject.org/call-for-webtunnel-bridges/&lt;/a&gt; &lt;/blockquote&gt;
    </content>
    <updated>2024-11-28T23:37:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg8dcf6jyleavednzq0u0x3q5ga6z23nffdag4wxhme4nwd8lqzvqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p857ddga2</id>
    
      <title type="html">Tor needs 200 new WebTunnel bridges to fight censorship The Tor ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg8dcf6jyleavednzq0u0x3q5ga6z23nffdag4wxhme4nwd8lqzvqzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p857ddga2" />
    <content type="html">
      Tor needs 200 new WebTunnel bridges to fight censorship&lt;br/&gt;&lt;br/&gt;The Tor Project has put out an urgent call to the privacy community asking volunteers to help deploy 200 new WebTunnel bridges by the end of the year to fight government censorship.&lt;br/&gt;&lt;br/&gt;Currently, the Tor Project operates 143 WebTunnel bridges, which help users in heavily censored regions bypass internet access restrictions and website blocks.&lt;br/&gt;&lt;br/&gt;This comes in response to increasing censorship in Russia, which Tor says currently impacts the browser&amp;#39;s built-in censorship circumvention mechanisms, including obfs4 connections and Snowflake.&lt;br/&gt;&lt;br/&gt;The Tor Project believes that setting up more WebTunnel bridges is the best response to this censorship escalation, as analyzing new tactics and developing workarounds takes time, leaving users vulnerable and isolated from the free internet.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/tor-needs-200-new-webtunnel-bridges-to-fight-censorship/&#34;&gt;https://www.bleepingcomputer.com/news/security/tor-needs-200-new-webtunnel-bridges-to-fight-censorship/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#tor #privacy #censorship
    </content>
    <updated>2024-11-28T23:37:08Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0xvw4aupw2kum3p7nfeu4gen57haznmve3wvlueau88suaz752dgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85v4ludn</id>
    
      <title type="html">Police bust pirate streaming service making €250 million per ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0xvw4aupw2kum3p7nfeu4gen57haznmve3wvlueau88suaz752dgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85v4ludn" />
    <content type="html">
      Police bust pirate streaming service making €250 million per month&lt;br/&gt;&lt;br/&gt;An international law enforcement operation has dismantled a pirate streaming service that served over 22 million users worldwide and made €250 million ($263M) per month.&lt;br/&gt;&lt;br/&gt;Italy&amp;#39;s Postal and Cybersecurity Police Service announced the action, codenamed &amp;#34;Taken Down,&amp;#34; stating they worked with Eurojust, Europol, and many other European countries, making this the largest takedown of its kind in Italy and internationally.&lt;br/&gt;&lt;br/&gt;&amp;#34;More than 270 Postal Police officers, in collaboration with foreign law enforcement, carried out 89 searches in 15 Italian regions and 14 additional searches in the United Kingdom, the Netherlands, Sweden, Switzerland, Romania, Croatia, and China, involving 102 individuals,&amp;#34; reads the announcement.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://www.bleepingcomputer.com/news/technology/police-bust-pirate-streaming-service-making-250-million-per-month/&#34;&gt;https://www.bleepingcomputer.com/news/technology/police-bust-pirate-streaming-service-making-250-million-per-month/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#pirate #streaming
    </content>
    <updated>2024-11-28T23:30:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp2lhwmqehln8n6lxtf5ewd8xdkv7klz0rc6qgcj8lqh3ra25csvgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85z7r33s</id>
    
      <title type="html">ProjectSend Vulnerability Exploited in the Wild Threat actors are ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp2lhwmqehln8n6lxtf5ewd8xdkv7klz0rc6qgcj8lqh3ra25csvgzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85z7r33s" />
    <content type="html">
      ProjectSend Vulnerability Exploited in the Wild&lt;br/&gt;&lt;br/&gt;Threat actors are likely exploiting ProjectSend servers unpatched against a vulnerability that was publicly disclosed roughly a year and a half ago, VulnCheck warns.&lt;br/&gt;&lt;br/&gt;An open source application written in PHP, ProjectSend is designed for file sharing, enabling users to create client groups, assign user roles, and access statistics, detailed logs, notifications, and more.&lt;br/&gt;&lt;br/&gt;The exploited issue, tracked as CVE-2024-11680 (CVSS score of 9.8), is described as an improper authentication vulnerability that could allow remote, unauthenticated attackers to modify the application’s configuration.&lt;br/&gt;&lt;br/&gt;Attackers could send crafted HTTP requests to the options[.]php endpoint to create rogue accounts, upload webshells, and potentially embed malicious JavaScript code, a NIST advisory reads.&lt;br/&gt;&lt;br/&gt;See more:  &lt;a href=&#34;https://www.securityweek.com/projectsend-vulnerability-exploited-in-the-wild/&#34;&gt;https://www.securityweek.com/projectsend-vulnerability-exploited-in-the-wild/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #php
    </content>
    <updated>2024-11-28T23:28:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqxx4nhrlkrqwt94wjp0yym32pyd9xete7k2ktcq2qeelcc7na0dczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p858z9rc6</id>
    
      <title type="html">APT-C-60 Hackers Exploit StatCounter and Bitbucket in SpyGlace ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqxx4nhrlkrqwt94wjp0yym32pyd9xete7k2ktcq2qeelcc7na0dczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p858z9rc6" />
    <content type="html">
      APT-C-60 Hackers Exploit StatCounter and Bitbucket in SpyGlace Malware Campaign&lt;br/&gt;&lt;br/&gt;The threat actor known as APT-C-60 has been linked to a cyber attack targeting an unnamed organization in Japan that used a job application-themed lure to deliver the SpyGlace backdoor.&lt;br/&gt;&lt;br/&gt;That&amp;#39;s according to findings from JPCERT/CC, which said the intrusion leveraged legitimate services like Google Drive, Bitbucket, and StatCounter. The attack was carried out around August 2024.&lt;br/&gt;&lt;br/&gt;&amp;#34;In this attack, an email purporting to be from a prospective employee was sent to the organization&amp;#39;s recruiting contact, infecting the contact with malware,&amp;#34; the agency said.&lt;br/&gt;&lt;br/&gt;See more: &lt;a href=&#34;https://thehackernews.com/2024/11/apt-c-60-exploits-wps-office.html&#34;&gt;https://thehackernews.com/2024/11/apt-c-60-exploits-wps-office.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #malware
    </content>
    <updated>2024-11-28T23:26:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfhhltc4q2nll59zq3eh6hr0af38cans6676plhrs4jzxaprzu45gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85mthsws</id>
    
      <title type="html">New NachoVPN attack uses rogue VPN servers to install malicious ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfhhltc4q2nll59zq3eh6hr0af38cans6676plhrs4jzxaprzu45gzyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85mthsws" />
    <content type="html">
      New NachoVPN attack uses rogue VPN servers to install malicious updates&lt;br/&gt;&lt;br/&gt;A set of vulnerabilities dubbed &amp;#34;NachoVPN&amp;#34; allows rogue VPN servers to install malicious updates when unpatched Palo Alto and SonicWall SSL-VPN clients connect to them.&lt;br/&gt;&lt;br/&gt;AmberWolf security researchers found that threat actors can trick potential targets into connecting their SonicWall NetExtender and Palo Alto Networks GlobalProtect VPN clients to attacker-controlled VPN servers using malicious websites or documents in social engineering or phishing attacks.&lt;br/&gt;&lt;br/&gt;Threat actors can use the rogue VPN endpoints to steal the victims&amp;#39; login credentials, execute arbitrary code with elevated privileges, install malicious software via updates, and launch code-signing forgery or man-in-the-middle attacks by installing malicious root certificates.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;Bleeping Computer: &lt;a href=&#34;https://www.bleepingcomputer.com/news/security/new-nachovpn-attack-uses-rogue-vpn-servers-to-install-malicious-updates/&#34;&gt;https://www.bleepingcomputer.com/news/security/new-nachovpn-attack-uses-rogue-vpn-servers-to-install-malicious-updates/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;SecurityWeek:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/new-vpn-attack-demonstrated-against-palo-alto-networks-sonicwall-products/&#34;&gt;https://www.securityweek.com/new-vpn-attack-demonstrated-against-palo-alto-networks-sonicwall-products/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity 
    </content>
    <updated>2024-11-28T01:58:29Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxrymhw56u7kspfexqrh2qn6kmpqxyjm5f8p8q56rhl5zmr03nwwczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85t9r86s</id>
    
      <title type="html">Firefox and Windows zero-days exploited by Russian RomCom hackers ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxrymhw56u7kspfexqrh2qn6kmpqxyjm5f8p8q56rhl5zmr03nwwczyqt06fhsqp20vc23c67hjf0daaq4scgr4uvag30e8an0tcjtx3p85t9r86s" />
    <content type="html">
      Firefox and Windows zero-days exploited by Russian RomCom hackers&lt;br/&gt;&lt;br/&gt;Russian-based RomCom cybercrime group chained two zero-day vulnerabilities in recent attacks targeting Firefox and Tor Browser users across Europe and North America.&lt;br/&gt;&lt;br/&gt;The first flaw (CVE-2024-9680) is a use-after-free bug in Firefox&amp;#39;s animation timeline feature that allows code execution in the web browser&amp;#39;s sandbox. Mozilla patched this vulnerability on October 9, 2024, one day after ESET reported it.&lt;br/&gt;&lt;br/&gt;The second zero-day exploited in this campaign is a privilege escalation flaw (CVE-2024-49039) in the Windows Task Scheduler service, allowing attackers to execute code outside the Firefox sandbox. Microsoft addressed this security vulnerability earlier this month, on November 12.&lt;br/&gt;&lt;br/&gt;RomCom abused the two vulnerabilities as a zero-day chain exploit, which helped them gain remote code execution without requiring user interaction. Their targets only had to visit an attacker-controlled and maliciously crafted website that downloaded and executed the RomCom backdoor on their system.&lt;br/&gt;&lt;br/&gt;See more:&lt;br/&gt;Bleeping Computer:&lt;br/&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/firefox-and-windows-zero-days-exploited-by-russian-romcom-hackers/&#34;&gt;https://www.bleepingcomputer.com/news/security/firefox-and-windows-zero-days-exploited-by-russian-romcom-hackers/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The Hackers News:&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2024/11/romcom-exploits-zero-day-firefox-and.html&#34;&gt;https://thehackernews.com/2024/11/romcom-exploits-zero-day-firefox-and.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;SecurityWeek:&lt;br/&gt;&lt;a href=&#34;https://www.securityweek.com/russian-apt-chained-firefox-and-windows-zero-days-against-us-and-european-targets/&#34;&gt;https://www.securityweek.com/russian-apt-chained-firefox-and-windows-zero-days-against-us-and-european-targets/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#cybersecurity #zeroday #firefox
    </content>
    <updated>2024-11-28T01:53:24Z</updated>
  </entry>

</feed>