home.social

#securityland — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityland, aggregated by home.social.

fetched live
  1. Belgium and the UK signed a defense MoU last week that doesn't involve new aircraft or satellites — but it matters.

    QinetiQ has been handed a mandate to help Belgium build a sovereign Joint Electromagnetic Warfare Support Center, modeled on the UK's SOCIETAS program.

    Read More: security.land/belgium-takes-co

    #SecurityLand #GeoSphere #EU #UK #Belgium #ElectronicWarfare #Military #Government

  2. After years of delays and political wrangling, Poland's NIS2-implementing cybersecurity law is finally live. Here's what changed on April 3, and what comes next for tens of thousands of Polish businesses.

    Read More: security.land/polands-new-cybe

    #SecurityLand #GeoSphere #Cybersecurity #EU #NIS2 #Poland #SME #Government

  3. Spain is becoming a European cyber powerhouse. With a projected €3 billion market valuation by year-end, the surge is fueled by mandatory EU compliance—and a desperate race to find qualified professionals.

    Read More: security.land/spain-cybersecur

    #SecurityLand #News #Cybersecurity #Spain #Market #EU #NIS2 #Europe

  4. Forbidden Hyena is now using AI-generated code to deploy the BlackReaperRAT against Russian energy & retail sectors. By leveraging AI-generated PowerShell scripts and a new custom Trojan—BlackReaperRAT—this group has transitioned from ideological protests to sophisticated corporate extortion.

    Read More: security.land/ai-crafted-chaos

    #SecurityLand #CyberSecurity #Russia #ForbiddenHyena #AI #Ransomware #CriticalInfrastructure

  5. A new global survey of 750 CISOs by Absolute Security has uncovered a critical "recovery reality gap" that is redefining modern security priorities. The data reveals a sobering truth: not a single organization reported being able to fully restore business operations within 24 hours of a major cyber incident.

    Read More: security.land/the-24-hour-reco

    #SecurityLand #BusinessShield #CyberSecurity #CISO #MTTR #AbsoluteSecurity #CyberResilience #CyberDefense #Research

  6. CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.

    Read More: security.land/freebsd-ipv6-fla

    #SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE

  7. A five-month spearphishing operation discovered by Socket has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.

    Read More: security.land/npm-registry-wea

    #SecurityLand #Cybersecurity #Research #NPM #Phishing #CriticalInfrastructure #AiTM #Spearphishing #Dev

  8. The NCS Guide 2025 is here, and it finally solves the funding gap. With a new 6-phase lifecycle and a mandate for Quantum/AI foresight, this is the definitive playbook for digital sovereignty.

    #SecurityLand #BusinessShield #Government #Cybersecurity #AI #Quantum #DigitalSovereignty #NCSGuide #NCS2025

    Read More: security.land/ncs-guide-2025-3

  9. Zscaler ThreatLabz documents BlindEagle APT's sophisticated attack on Colombian government infrastructure using steganography, compromised email accounts, and dual malware deployment (Caminho + DCRat). The September 2025 campaign demonstrates evolved tradecraft including Discord CDN abuse and fileless execution chains.

    #SecurityLand #ThreatHorizon #Zscaler #BlindEagle #Colombia #Government #Ecuador #APT #RAT #Malware

    Read More: security.land/blindeagle-colom

  10. Australian Strategic Policy Institute research reveals how Chinese vision-language models systematically embed political censorship across multiple architectural layers. Testing of Qwen, Ernie, GLM, and DeepSeek shows 70%+ refusal rates for sensitive topics via certain providers, with language-dependent filtering that reshapes historical narratives.

    #SecurityLand #GeoSphere #ASPI #Research #Australia #China #AI #LLM #Qwen #DeepSeek

    Read More: security.land/china-ai-surveil

  11. New research from ISC2 reveals a critical shift in cybersecurity workforce challenges. Their 2025 Cybersecurity Workforce Study surveyed 16,029 professionals globally and found that 88% of organizations experienced security incidents directly caused by skills deficits in the past year.

    #SecurityLand #News #Research #ISC2 #Cybersecurity #Workforce #Study #SecurityIncident #CybersecurityJobs

    Read More: security.land/isc2-2025-workfo

  12. New infrastructure analysis from Censys reveals how the pro-Russian hacktivist group NoName057(16) maintains DDoSia operations through rapid server rotation. Monitoring since mid-2025 shows an average of 6 control servers active simultaneously, but with a mean lifespan of only 2.53 days.

    #SecurityLand #ThreatHorizon #Research #Censys #DDoSia #DDoS #DDoSAttack #NoName057 #Ukraine #Russia #Hacktivism

    Read More: security.land/ddosia-infrastru

  13. Russia's telecommunications oversight authority has escalated its campaign against WhatsApp, warning the Meta-owned platform faces a total shutdown unless it complies with Moscow's regulatory framework.

    #SecurityLand #GeoSphere #Meta #WhatsApp #Privacy #Security #WhatsAppBan #Russia #Government

    Read More: security.land/russia-threatens

  14. 🚨 The OpenAI/Mixpanel breach is not just a "vendor issue"—it's a systemic failure. We analyzed 3 years of security incidents at OpenAI and compared them to the fortified architectures of Google Gemini and Anthropic Claude.

    #SecurityLand #ExpertDecode #AI #SecurityBreach #Cyberattack #OpenAI #ChatGPT #Claude #Gemini #SpearPhishing #Business #Enterprise #Mixpanel

    Read More: security.land/openai-mixpanel-

  15. Multiple London councils are responding to a major cyber incident that has disrupted IT systems and phone lines across several boroughs. Kensington and Chelsea, Westminster, and potentially Hammersmith and Fulham councils have activated emergency protocols while working with the National Cyber Security Centre.

    #SecurityLand #News #Cyberattack #London #UK #CyberIncident #Government

    Read More: security.land/london-councils-

  16. North Korea now has military-grade AI: facial recognition for surveillance, real-time voice cloning for deception ops, and drone-mounted tracking systems. A South Korean security institute warns published research shows only "the tip of the iceberg" of actual capabilities.

    #SecurityLand #GeoSphere #Research #AI #NorthKorea #SouthKorea #Security #VoiceCloning #Technology #Military

    Read More: security.land/north-korea-mili

  17. Machina Record is bringing together Japan's top cybersecurity minds for the Cyber Intelligence Summit 2025 in Tokyo (Nov 5-7). Leaders from Mizuho, MUFG, Sumitomo Mitsui, Panasonic, Rakuten, and Japan's Ministry of Defense will share exclusive insights on AI-driven threats, state-sponsored attacks, and next-gen defense strategies.

    #SecurityLand #News #Cybersecurity #Japan #ThreatIntelligence #CyberIntelligenceSummit #Cybercrime #Cyberdefense #Government

    Read More: security.land/global-experts-t

  18. A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.

    #SecurityLand #CyberWatch #OpenAI #ChatGPT #Radware #Vulnerability #ShadowLeak

    Read More: security.land/zero-click-chatg

  19. 🚨 Sophisticated "Shai-Hulud" worm compromises 187+ NPM packages in devastating supply chain attack. The self-replicating malware steals dev credentials and publicly exposes them on GitHub. CrowdStrike among victims. JavaScript ecosystem under siege.

    #SecurityLand #CyberWatch #CyberSecurity #NPM #SupplyChain #ShaiHulud #Github #Javascript

    Read More: security.land/npm-under-attack

  20. Atlantic Council comprehensive analysis of 561 entities across 46 countries reveals systematic accountability gaps in the global commercial spyware market. Research exposes how broker networks and complex investment structures enable surveillance technologies to target journalists, human rights defenders, and civil society while evading oversight mechanisms.

    #SecurityLand #GeoSphere #Spyware #ShadowEconomy #Surveillance #Tech #SpywareMarket

    Read More: security.land/the-shadow-econo

  21. pgAdmin CVE-2025-9636 vulnerability enables OAuth session hijacking, threatening PostgreSQL database security. Database administrators must prioritize pgAdmin 9.8 upgrade immediately. Essential reading for cybersecurity professionals.

    #SecurityLand #CyberWatch #Cybersecurity #PostgreSQL #DatabaseSecurity #CVE #OAuth #pgAdmin

    Read More: security.land/critical-pgadmin

  22. Cybercriminals are weaponizing AI to execute sophisticated attacks autonomously. New threat intelligence report from Anthropic reveals how machine learning models now perform network penetration, generate ransomware, and scale fraud operations beyond human capabilities.

    #SecurityLand #EmergingTech #Anthropic #Cybersecurity #AI #ThreatIntelligence #InfoSec

    Read More: security.land/anthropic-threat

  23. European Union Agency for Cybersecurity (ENISA) comprehensive analysis reveals critical vulnerabilities in Europe's managed security services market. With 51% of MSS providers under non-EU control and organizations investing <10% in security, Europe faces serious cybersecurity challenges. Key findings on digital sovereignty risks ahead.

    #SecurityLand hashtag#BusinessShield #Cybersecurity #ENISA #DigitalSovereignty #EuropeanSecurity #EU #ManagedSecurity

    Read More: security.land/european-mss-mar

  24. The U.S. House of Representatives made a bold move, banning WhatsApp on all government devices due to cybersecurity risks. What does this mean for data privacy, national security, and the future of digital communication? Dive into our comprehensive analysis.

    #SecurityLand #GeoSphere #WhatsAppBan #Cybersecurity #GovernmentSecurity #DataPrivacy #Government

    Read More: security.land/from-personal-ch

  25. 🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.

    #SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS

    security.land/critical-securit

  26. Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.

    #SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology

    Read More: security.land/multiple-securit

  27. CISA has issued an urgent advisory about six actively exploited vulnerabilities affecting Ivanti EPMM, Zimbra, Output Messenger, and other enterprise systems. Learn which systems are at risk and what actions your organization should take immediately to protect critical infrastructure.

    #SecurityLand #CyberWatch #CISA #Vulnerability #Ivanti #EPMM #Zimbra #OutputMessenger #EnterpriseSecurity #SecurityExploit #CriticalInfrastructure #Government

    Read More: security.land/us-government-wa

  28. Pwn2Own Berlin concludes with Singapore's STAR Labs claiming the "Master of Pwn" title and $320,000! Ethical hackers uncovered 28 zero-day vulnerabilities across AI platforms, virtualization software, and operating systems, demonstrating how security competitions drive industry improvement.

    #SecurityLand #News #Cybersecurity #Event #Pwn2Own #ZeroDay #Vulnerability #Research #OffensiveCon

    Read More: security.land/pwn2own-berlin-s

  29. 🚨 A critical vulnerability (CVE-2025-47275) in the Auth0 SDK exposes Symfony, Laravel, and WordPress users to brute-force session attacks. Okta has released patches—learn how to protect your application now.

    #SecurityLand #CyberWatch #Auth0 #Okta #PHP #Laravel #WordPress #Symfony #Vulnerability #Patch

    Read More: security.land/critical-vulnera