Profile avatar
pithysecurity.bsky.social
I'm a geeky newsletter editor covering cybersecurity and information security news, including breaches, tutorials, and the latest exploits. Join me if you're a security pro, IT nerd, or anyone who loves digital privacy. PithySecurity.Substack.com
123 posts 553 followers 398 following
Regular Contributor
Active Commenter

Am I the only one who thinks $16.6B lost to cybercrime in 2024 is a low estimate? With so much unreported and hidden damage, the real number’s probably way higher! πŸ’»πŸ’Έ #CyberSecurity www.bleepingcomputer.com/news/securit...

🚨 People say they can't be tricked. Data says otherwise. Text scams rose to hundreds of millions πŸ’° in 2024. Watch out for fake package alerts πŸ“¦, job offers πŸ’Ό, fraud warnings 🚨, toll fee scams πŸš—, and wrong number tricks. πŸ“±πŸ”’ Report scams to the FTC! #CyberSecurity www.malwarebytes.com/blog/news/20...

🚨 Phishers are abusing Google OAuth to send ultra-convincing fake emails that pass Google’s DKIM checks - making them look 100% legit! Even pros were fooled. Stay sharp: always double-check URLs, even if the email looks official. #Phishing #Cybersecurity www.bleepingcomputer.com/news/securit...

πŸ”’πŸš« Oracle denies data breach claims after hacker alleges theft of 6 million records. Company stands firm on data security #CyberSecurity #DataProtection www.bleepingcomputer.com/news/securit...

You see this new botnet? 🚨 Eleven11bot emerges overnight, infecting 30,000+ webcams & video recorders πŸ“Ή, mostly in US πŸ‡ΊπŸ‡Έ. It delivers massive "hyper-volumetric" DDoS attacks πŸš€, consuming bandwidth in terabits per second πŸ“Š. A new era of cyber threats 🚨. #cybersecurity arstechnica.com/security/202...

🚨 Warning! 🚨 Scammers are impersonating PayPal using hacked ad accounts, exploiting a Google policy loophole πŸ€–. They create fake ads with official-looking PayPal URLs πŸ“Š, tricking users into giving personal info πŸ“. Stay vigilant πŸ‘€ verify URLs! πŸ’» #Cybersecurity www.malwarebytes.com/blog/scams/2...

🚨 AI Security Alert! πŸ€–πŸ”“ Nearly 12,000 API keys & passwords discovered in Common Crawl dataset used to train major AI models! 😱 This affects LLMs from tech giants like OpenAI, Google, Meta & more. Huge implications for #Cybersecurity #Privacy www.bleepingcomputer.com/news/securit...

New Linux Malware Alert: 'Auto-Color' 🎨 πŸ–₯️ Targets universities & gov orgs in N. America & Asia πŸ”“ Grants hackers full remote access πŸ•΅οΈ Evades detection with clever tricks πŸ”’ Requires root privileges Stay vigilant, Linux users! Patch & update! #CyberSecurity thehackernews.com/2025/02/new-...

🚨 ALERT: Predatory App Strikes Google Play! πŸ“±πŸ’Έ "Finance Simplified" app, part of SpyLoan family, downloaded 100K times πŸ“Š ⚠️ Masquerades as financial tool, but STEALS user data for blackmail πŸ•΅οΈβ€β™‚οΈ πŸ”“ Harvests contacts, photos, location & more πŸ“žπŸ“ΈπŸ—ΊοΈ #CyberSecurity www.malwarebytes.com/blog/news/20...

🚨 Alert: Massive botnet targets Microsoft 365! πŸ–₯️ Over 130K compromised devices launching coordinated password-spraying attacks on M365 accounts. 😱 C2 servers hosted by SharkTech (US) with links to Chinese cloud providers. πŸŒπŸ”’ #CyberSecurity www.helpnetsecurity.com/2025/02/24/b...

πŸ›οΈπŸ’» "Smart" bed vulnerability lets hackers access your entire network. They know when you're sleeping, awake, and can run any code they like. This is perfectly normal. Lol. (Does EVERYTHING have to be on the damn network?) #IoT #CyberSecurity #Fail www.tomshardware.com/tech-industr...

🌐 Heads up! X now blocks links to "Signal.me," the URL used for sharing your Signal account info. 🚫 Posting these links via public posts, direct messages, or profile bios results in error messages about spam or malware risks. 😱 #CyberSecurity #Privacy www.bleepingcomputer.com/news/securit...

πŸš¨πŸ”’ Microsoft is ending its Defender 'Privacy Protection' VPN feature by Feb 28! πŸ“† The decision is due to low usage, and Microsoft plans to focus on other features πŸ“ˆ. Users will need to find alternative VPNs for secure browsing 🌐. #VPN #CyberSecurity www.bleepingcomputer.com/news/microso...

🧠 Hackers are exploiting Google’s Gemini AI to boost attack efficiency. πŸ’» State-sponsored APT groups, primarily from Iran and China, use it for research, reconnaissance, and productivity gains rather than novel AI-driven attacks. πŸ” #CyberSecurity #AI www.bleepingcomputer.com/news/securit...

🚨 Google's Shocking App Security Blitz: Blocked 2.36 MILLION risky Android apps & banned 158K malicious developer accounts! πŸ›‘οΈ AI-powered threat detection keeps your phone safe. Stay protected! πŸ€– #CyberSecurity #AI #Google security.googleblog.com/2025/01/how-...

🚨 DeepSeek AI database breach: Over 1M log lines & secret keys exposed. Wiz researchers found unsecured ClickHouse DB allowing full access. DeepSeek fixed the issue, but potential data theft unknown. This reveals DRASTIC risk of AI data protection. #cybersecurity thehackernews.com/2025/01/deep...

🚨 Critical vulnerability in Brave Browser (CVE-2025-23086) allows malicious sites to pose as trusted sources during file transfers. Affects versions 1.70.x-1.73.x. Update to the latest version ASAP! 1. Update to v1.74.48+ 2. Check for open redirects #CyberSecurity hackread.com/brave-deskto...

Can you believe this? Facebook flags Linux topics as 'cybersecurity threats', blocking posts & users. DistroWatch among major affected sites. Irony: FB runs on Linux & seeks Linux devs. Wild tech censorship incoming! 🐧 #Tech #Linux www.tomshardware.com/software/lin...

Good god... Have you seen THIS? 😱 Nearly 1 million Americans' sensitive data exposed in massive healthcare breach! Names, SSNs, medical info all compromised. Privacy nightmare unfolding! 🚨 #DataBreach #CyberSecurity #Privacy dailyhodl.com/2024/12/21/r...

🦠⚠️ Beware of the new Glutton malware! 😱 Targeting popular PHP frameworks Laravel & ThinkPHP, this sneaky backdoor is causing chaos across the globe! 🌍 Chinese hackers suspected πŸ‡¨πŸ‡³ Watch out devs! πŸ›‘οΈ #CyberSecurity #Malware thehackernews.com/2024/12/new-...

πŸ”“πŸš¨ 4.8 MILLION healthcare records exposed! Canadian company Care1 left patient dataβ€”including eye exam results and personal health infoβ€”open for anyone to see. πŸ₯πŸ’» Security researcher Jeremiah Fowler found the breach. Protect your data, people! πŸ” #CyberSecurity www.malwarebytes.com/blog/news/20...

πŸ±β€πŸ‘€ New Linux threat: Pumakit rootkit! 🚨 Multi-component malware with dropper, memory-resident executables, kernel module & userland rootkit. Stealthy, advanced, and in the wild 🌐 Targeting critical systems 🎯 #CyberSecurity #Linux www.bleepingcomputer.com/news/securit...

🚫 Firefox is saying goodbye to the Do Not Track toggle! πŸ‘‹ Turns out, nobody was listening anyway! πŸ˜‚ When Firefox 135 drops in Feb, it’ll be one less feature to worry about.πŸ”’ Time to embrace the Global Privacy Control instead! πŸ•΅οΈβ€β™‚οΈ #Privacy #Firefox #ByeByeDNT go.theregister.com/feed/www.the...

🚨 Alert: 300K+ Prometheus servers exposed! πŸ”“ Credentials & API keys leaking online. 😱 DoS & RCE attacks possible. πŸ›‘οΈ Secure your servers now! #Cybersecurity #Vulnerability #InfoSec thehackernews.com/2024/12/2960...

⏰ Researchers cracked Microsoft Azure MFA... in just one hour! 😳 Rate limit login attack exploited. Unlimited failed sign-in attempts? Oops! 400M+ Microsoft 365 seats were at risk. Don't worry, it's fixed now! πŸ›‘οΈ #CyberSecurity #MFA #RateLimit www.darkreading.com/cyberattacks...

🚨 Chinese hacker charged for exploiting zero-day in 81,000 Sophos firewalls! πŸ‡¨πŸ‡³πŸ‘¨β€πŸ’» Guan Tianfeng (aka gbigmao) allegedly breached devices globally in 2020. 🌎 US gov unseals charges of computer & wire fraud conspiracy. πŸ›οΈ #Cybersecurity #Hacking thehackernews.com/2024/12/us-c...