<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<title>pursaklargundem &#45; : Cyber Security</title>
<link>https://pursaklargundem.com/rss/category/siber-guvenlik</link>
<description>pursaklargundem &#45; : Cyber Security</description>
<dc:language>en</dc:language>

<item>
<title>Critical Vulnerability in Grandstream GXP1600 IP Phones Endangers Business Meetings</title>
<link>https://pursaklargundem.com/critical-vulnerability-in-grandstream-gxp1600-ip-phones-endangers-business-meetings</link>
<guid>https://pursaklargundem.com/critical-vulnerability-in-grandstream-gxp1600-ip-phones-endangers-business-meetings</guid>
<description><![CDATA[ A critical vulnerability coded CVE-2026-2329 has been detected in Grandstream GXP1600 IP phones.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_699b3cb652bf2.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 22 Feb 2026 21:36:48 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How Grandstream GXP1600 vulnerability works, how SIP credentials are stolen, how business conversations are at risk, how to apply security update</media:keywords>
<content:encoded><![CDATA[<p>A critical vulnerability has been revealed in Grandstream GXP1600 IP phones. </p>
<p></p>
<p data-start="721" data-end="770"><strong data-start="721" data-end="768">Experts summarized the effects of the deficit as follows:</strong></p>
<ul data-start="771" data-end="1149">
<li data-start="771" data-end="859">
<p data-start="773" data-end="859">Attackers can obtain SIP credentials and local device account data.</p>
</li>
<li data-start="860" data-end="982">
<p data-start="862" data-end="982">It can reconfigure the device's SIP settings and route calls through a malicious SIP proxy.</p>
</li>
<li data-start="983" data-end="1149">
<p data-start="985" data-end="1149">The phone continues to ring normally, users do not notice any abnormalities, but all conversations pass through the attacker-controlled infrastructure.</p>
</li>
</ul>
<p data-start="1151" data-end="1283">The target audience of the vulnerability includes small and medium-sized businesses, law firms, sales teams and finance departments.</p>
<p data-start="1285" data-end="1540">Grandstream responsibly reported the vulnerability in January. </p>
<p data-start="1542" data-end="1720"><strong data-start="1542" data-end="1554"></strong></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Google Vulnerability Report: Risk of Accessing User Data via YouTube Revealed</title>
<link>https://pursaklargundem.com/google-vulnerability-report-risk-of-accessing-user-data-via-youtube-revealed</link>
<guid>https://pursaklargundem.com/google-vulnerability-report-risk-of-accessing-user-data-via-youtube-revealed</guid>
<description><![CDATA[ A security study published in 2025 revealed that a chain vulnerability between YouTube and some Google services could cause some information about user accounts to be disclosed.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_699896919c0bf.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 20 Feb 2026 21:06:58 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is YouTube vulnerability, what does Google Gaia ID do, how to report cyber security vulnerabilities, how much is the Google Bug Bounty reward</media:keywords>
<content:encoded><![CDATA[<p>In a technical report published by a security researcher, <strong data-start="548" data-end="640">Vulnerabilities related to data flow between some systems in YouTube and Google infrastructure</strong> tespit edildiği bildirildi. Araştırmada, özellikle kullanıcılar arası etkileşim mekanizmalarının, beklenmeyen biçimde bazı dahili kimlik bilgilerinin açığa çıkmasına yol açabildiği ifade edildi.</p>
<p></p>
<p data-start="837" data-end="1198"><strong data-start="837" data-end="886">“Internal Identity Information Could Be Exposed”</strong><br data-start="886" data-end="889">Araştırmacı, YouTube üzerindeki belirli işlemler sırasında <strong data-start="948" data-end="1043">Internal identifiers known as "Gaia ID" belonging to Google accounts can be obtained.</strong> belirtti. Raporda, bu kimliklerin tek başına doğrudan hassas veri içermediği ancak farklı servislerle birleştirildiğinde risk oluşturabileceği vurgulandı.</p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202602/image_870x_6998969ea9e7c.webp" alt=""></p>
<p data-start="1200" data-end="1610"><strong data-start="1200" data-end="1247">Chain Effect Between Different Services</strong><br data-start="1247" data-end="1250">Çalışmada, Google’ın farklı ürünleri arasında yer alan veri paylaşım mekanizmalarının, belirli senaryolarda <strong data-start="1358" data-end="1407">Can lead to unexpected data matches</strong> ifade edildi. Araştırmacı, “Farklı sistemlerin birlikte değerlendirilmesi, tek başına kritik görünmeyen açıkların birleşerek daha büyük bir riske dönüşmesine neden olabilir.” değerlendirmesinde bulundu.</p>
<p data-start="1612" data-end="1905"><strong data-start="1612" data-end="1649">Responsible Notification Process Operated</strong><br data-start="1649" data-end="1652">Araştırmanın 2024 yılı Eylül ayında Google’a iletildiği, şirketin kısa sürede durumu incelemeye aldığı aktarıldı. Güvenlik paneli tarafından yapılan değerlendirmede açığın <strong data-start="1824" data-end="1891">Highly effective but requires a certain technical complexity</strong> ifade edildi.</p>
<p data-start="1907" data-end="2131">Google yetkililerinin, bildirimin ardından ilgili sistemlerde güncellemeler yaptığı ve <strong data-start="1994" data-end="2033">The identified vulnerabilities were closed</strong> bildirildi. Sürecin tamamlanmasının ardından rapor, 2025 yılı Şubat ayında kamuoyuyla paylaşıldı.</p>
<p data-start="2133" data-end="2483"><strong data-start="2133" data-end="2165">Award and Evaluation Process</strong><br data-start="2165" data-end="2168">Güvenlik açığını bildiren araştırmacıya, Google’ın hata ödül programı kapsamında toplamda <strong data-start="2258" data-end="2300">Prizes worth more than 10 thousand dollars were given</strong> açıklandı. Panel değerlendirmesinde, açığın “yüksek etki” kategorisinde olduğu ancak belirli bir saldırı zinciri gerektirdiği için derecelendirmede bir kademe düşürüldüğü kaydedildi.</p>
<p data-start="2485" data-end="2813"><strong data-start="2485" data-end="2506">Warning from Experts</strong><br data-start="2506" data-end="2509">Siber güvenlik uzmanları, bu tür olayların <strong data-start="2552" data-end="2657">Even on major technology platforms, interactions between systems must be carefully audited.</strong> ortaya koyduğunu belirtti. Uzmanlar, kullanıcıların da hesap güvenliği için iki faktörlü doğrulama gibi önlemleri aktif kullanmasının önemine dikkat çekti.</p>
<p data-start="2815" data-end="2959"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Personal Data Protection Board Declared a Data Breach at Köfteci Yusuf Affecting 163 Thousand People</title>
<link>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-at-koefteci-yusuf-affecting-163-thousand-people</link>
<guid>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-at-koefteci-yusuf-affecting-163-thousand-people</guid>
<description><![CDATA[ Köfteci Yusuf Ready Food Cleaning Livestock Meat Products Entegre Gıda İthalat İhracat San.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_6997d11e3cbab.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 20 Feb 2026 08:36:54 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>köfteci yusuf data breach 2026, kvkk 2026/141 board decision, 163 thousand people data breach, payroll software sql database attack</media:keywords>
<content:encoded><![CDATA[<p><br>Personal Data Protection Authority, Köfteci Yusuf Ready Food Cleaning Livestock Meat Products Entegre Gıda İthalat İhracat San. </p>
<p></p>
<p data-start="850" data-end="1079">The relevant provision of the law states: "In case the processed personal data is obtained by others through illegal means, the data controller shall notify the relevant person and the Board of this situation as soon as possible." </p>
<p data-start="1081" data-end="1116"><strong data-start="1081" data-end="1116">Local SQL Database Encrypted</strong></p>
<p data-start="1118" data-end="1255">In the notification submitted to the Board by the company, it was stated that the violation started on 22.01.2026 and was detected on 23.01.2026.</p>
<p data-start="1257" data-end="1470">In the statement, "The local SQL database, which contains the data controller's payroll software and information systems where online food orders are managed, has been encrypted and access prevented by an external intervention." </p>
<p data-start="1472" data-end="1510"><strong data-start="1472" data-end="1510">Employees and Customers Affected</strong></p>
<p data-start="1512" data-end="1818">The group of contacts affected by the breach was reported to be employees and customers. </p>
<p data-start="1820" data-end="1911">It was stated that the identity, contact and personnel data of the employees were also within the scope of the violation.</p>
<p data-start="1913" data-end="2034">It was shared that a total of 163 thousand people, including 13 thousand employees and 150 thousand customers of the company, were affected by the breach.</p>
<p data-start="2036" data-end="2079"><strong data-start="2036" data-end="2079">Announcement Decision on the Website from the Board</strong></p>
<p data-start="2081" data-end="2305">It was announced that with the Decision of the Personal Data Protection Board dated 27.01.2026 and numbered 2026/141, it was decided to announce the data breach notification on the Authority's website. </p>
<p data-start="2307" data-end="2444"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Personal Data Protection Board Declared a Data Breach Affecting 3,700 People in Codeway&amp;apos;s &amp;quot;Chat &amp;amp;amp; Ask AI&amp;quot; Application</title>
<link>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-affecting-3700-people-in-codeways-chat-ask-ai-application-4222</link>
<guid>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-affecting-3700-people-in-codeways-chat-ask-ai-application-4222</guid>
<description><![CDATA[ It was reported that user data was accessed in the &quot;Chat &amp; Ask AI&quot; mobile application belonging to Codeway Digital Services Inc. between January 15-20, 2026 due to an authorization weakness in the Google Firebase infrastructure.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_6997d11e3cbab.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 20 Feb 2026 08:06:56 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>codeway data breach 2026, chat &amp; ask ai firebase vulnerability, kvkk 2026/139 board decision, 3 thousand 700 people data breach</media:keywords>
<content:encoded><![CDATA[<p><br>The Personal Data Protection Authority published a public announcement regarding the data breach that occurred at Codeway Digital Services Joint Stock Company. </p>
<p></p>
<p data-start="788" data-end="1015">The relevant provision of the law states: "In case the processed personal data is obtained by others through illegal means, the data controller shall notify the relevant person and the Board of this situation as soon as possible." </p>
<p data-start="1017" data-end="1052"><strong data-start="1017" data-end="1052">Firebase Authorization Vulnerability</strong></p>
<p data-start="1054" data-end="1221">In the notification sent to the Board by Codeway, it was stated that the violation occurred between 15.01.2026 and 20.01.2026 and was detected on 20.01.2026.</p>
<p data-start="1223" data-end="1549">In the statement, "Due to the weakness in the authorization configuration on Google Firebase services used as the database (Firestore) and file storage (Storage) infrastructure of the mobile application called 'Chat & Ask AI', the attacker or attackers gained access to user data and file pool." </p>
<p data-start="1551" data-end="1659">It was reported that the technical weakness was resolved and internal control and audit efforts regarding the data breach are continuing.</p>
<p data-start="1661" data-end="1704"><strong data-start="1661" data-end="1704">Email and Post Contents Affected</strong></p>
<p data-start="1706" data-end="1913">Personal data affected by the breach; </p>
<p data-start="1915" data-end="2069">It was stated that approximately 3,700 people were evaluated to have been affected by the violation, and studies are continuing to determine the exact number.</p>
<p data-start="2071" data-end="2114"><strong data-start="2071" data-end="2114">Announcement Decision on the Website from the Board</strong></p>
<p data-start="2116" data-end="2347">It was announced that with the Decision of the Personal Data Protection Board dated 27.01.2026 and numbered 2026/139, it was decided to announce the data breach notification on the Authority's website. </p>
<p data-start="2349" data-end="2473"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Personal Data Protection Board Declared a Data Breach Affecting 3,700 People in Codeway&amp;apos;s &amp;quot;Chat &amp;amp; Ask AI&amp;quot; Application</title>
<link>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-affecting-3700-people-in-codeways-chat-ask-ai-application</link>
<guid>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-affecting-3700-people-in-codeways-chat-ask-ai-application</guid>
<description><![CDATA[ It was reported that user data was accessed in the &quot;Chat &amp; Ask AI&quot; mobile application belonging to Codeway Digital Services Inc. between January 15-20, 2026 due to an authorization weakness in the Google Firebase infrastructure.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_6997d11e3cbab.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 20 Feb 2026 08:06:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>codeway data breach 2026, chat &amp; ask ai firebase vulnerability, kvkk 2026/139 board decision, 3 thousand 700 people data breach</media:keywords>
<content:encoded><![CDATA[<p>The Personal Data Protection Authority published a public announcement regarding the data breach that occurred at Codeway Digital Services Joint Stock Company. </p>
<p data-start="788" data-end="1015">The relevant provision of the law states: "In case the processed personal data is obtained by others through illegal means, the data controller shall notify the relevant person and the Board of this situation as soon as possible." </p>
<p data-start="1017" data-end="1052"><strong data-start="1017" data-end="1052">Firebase Authorization Vulnerability</strong></p>
<p data-start="1054" data-end="1221">In the notification sent to the Board by Codeway, it was stated that the violation occurred between 15.01.2026 and 20.01.2026 and was detected on 20.01.2026.</p>
<p data-start="1223" data-end="1549">In the statement, "Due to the weakness in the authorization configuration on Google Firebase services used as the database (Firestore) and file storage (Storage) infrastructure of the mobile application called 'Chat & Ask AI', the attacker or attackers gained access to user data and file pool." </p>
<p data-start="1551" data-end="1659">It was reported that the technical weakness was resolved and internal control and audit efforts regarding the data breach are continuing.</p>
<p data-start="1661" data-end="1704"><strong data-start="1661" data-end="1704">Email and Post Contents Affected</strong></p>
<p data-start="1706" data-end="1913">Personal data affected by the breach; </p>
<p data-start="1915" data-end="2069">It was stated that approximately 3,700 people were evaluated to have been affected by the violation, and studies are continuing to determine the exact number.</p>
<p data-start="2071" data-end="2114"><strong data-start="2071" data-end="2114">Announcement Decision on the Website from the Board</strong></p>
<p data-start="2116" data-end="2347">It was announced that with the Decision of the Personal Data Protection Board dated 27.01.2026 and numbered 2026/139, it was decided to announce the data breach notification on the Authority's website. </p>
<p data-start="2349" data-end="2473"></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Personal Data Protection Board Declared a Data Breach at Eurail B.V. Affecting 8 Thousand 823 Turkish Resident Passengers</title>
<link>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-at-eurail-bv-affecting-8-thousand-823-turkish-resident-passengers</link>
<guid>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-at-eurail-bv-affecting-8-thousand-823-turkish-resident-passengers</guid>
<description><![CDATA[ It was reported that the identity, passport, contact and travel information of 8 thousand 823 customers residing in Turkey who purchased train tickets were affected in the cyber attack on the systems of Netherlands-based Eurail B.V., which started on December 26, 2025 and was detected on January 5, 2026.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_6997d11e3cbab.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 20 Feb 2026 07:36:52 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>eurail data breach 2026, kvkk 2026/103 board decision, 8 thousand 823 people data breach, eurail passport and travel information leak</media:keywords>
<content:encoded><![CDATA[<p><br>The Personal Data Protection Authority published a public notice regarding the data breach at Eurail B.V. </p>
<p></p>
<p data-start="736" data-end="965">The relevant provision of the law states: "In case the processed personal data is obtained by others through illegal means, the data controller shall notify the relevant person and the Board of this situation as soon as possible." </p>
<p data-start="967" data-end="1005"><strong data-start="967" data-end="1005">Cyber ​​Attack Started on December 26</strong></p>
<p data-start="1007" data-end="1301">In the notification sent to the Board, it was stated that Eurail B.V., established and operating in the Netherlands, uses an agency distribution model for the sale of travel tickets around the world. </p>
<p data-start="1303" data-end="1504">It was reported that the violation started on 26.12.2025 and was detected on 05.01.2026. </p>
<p data-start="1506" data-end="1549"><strong data-start="1506" data-end="1549">Passport and Travel Information Affected</strong></p>
<p data-start="1551" data-end="1746">Personal data affected by the breach; </p>
<p data-start="1748" data-end="1993">Within the scope of contact data, address and place of residence, e-mail address and telephone number; </p>
<p data-start="1995" data-end="2124">It was stated that 8 thousand 823 people residing in Turkey were affected by the violation, and the relevant group of people were customers who purchased train tickets.</p>
<p data-start="2126" data-end="2311">Şirketin, ihlale ilişkin teknik inceleme ve ek araştırmalarının devam ettiği kaydedildi. İlgili kişilerin <a data-start="2232" data-end="2254" class="decorated-link cursor-pointer" rel="noopener">privacyhelp@eurrail.com<span aria-hidden="true" class="ms-0.5 inline-block align-middle leading-none"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" aria-hidden="true" data-rtl-flip="" class="block h-[0.75em] w-[0.75em] stroke-current stroke-[0.75]"></svg></span></a> e-posta adresi üzerinden bilgi alabilecekleri duyuruldu.</p>
<p data-start="2313" data-end="2356"><strong data-start="2313" data-end="2356">Announcement Decision on the Website from the Board</strong></p>
<p data-start="2358" data-end="2584">It was announced that with the Decision of the Personal Data Protection Board dated 27.01.2026 and numbered 2026/103, it was decided to announce the data breach notification on the Authority's website. </p>
<p data-start="2586" data-end="2724"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Personal Data Protection Board Declared a Data Breach at Uludağ Elektrik Including 899 Thousand Queries</title>
<link>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-at-uludag-elektrik-including-899-thousand-queries</link>
<guid>https://pursaklargundem.com/personal-data-protection-board-declared-a-data-breach-at-uludag-elektrik-including-899-thousand-queries</guid>
<description><![CDATA[ In the data breach that took place at Uludağ Elektrik Dağıtım AŞ on August 5, 2025 and was detected on August 18, it was reported that a data set containing subscriber data was found on the dark web.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_6997d11e3cbab.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 20 Feb 2026 07:06:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>uludağ electricity data breach 2025, kvkk 2025/2443 board decision, 899 thousand 890 query data breach, dark web subscriber information leak</media:keywords>
<content:encoded><![CDATA[<p><br>Personal Data Protection Authority published a public announcement regarding the data breach that occurred at Uludağ Elektrik Dağıtım AŞ. </p>
<p></p>
<p data-start="742" data-end="969">The relevant provision of the law states: "In case the processed personal data is obtained by others through illegal means, the data controller shall notify the relevant person and the Board of this situation as soon as possible." </p>
<p data-start="971" data-end="1010"><strong data-start="971" data-end="1010">Dataset Detected on Dark Web</strong></p>
<p data-start="1012" data-end="1163">In the notification sent to the Board by Uludağ Elektrik, it was stated that the violation occurred on 05.08.2025 and was detected on 18.08.2025.</p>
<p data-start="1165" data-end="1358">In the statement, "A data set containing information about data controller subscribers has been detected on a platform used by threat actors for file sharing on the dark web." </p>
<p data-start="1360" data-end="1667">It was reported that the data set in question contained a total of 57 data categories, including mostly technical data about a subscriber, such as subscriber number, name-surname, partial address, consumption information and meter information, but also personal data, and it was determined that the data overlapped with the records kept in the company system.</p>
<p data-start="1669" data-end="1716"><strong data-start="1669" data-end="1716">Illegal Login to SMS Verified System</strong></p>
<p data-start="1718" data-end="1972">Regarding the root cause of the breach, it was stated that it was evaluated that the system, which can only be accessed with the username, password and SMS verification code that must be received at each login, was illegally entered by malicious threat actors.</p>
<p data-start="1974" data-end="2187">It was stated that the exact number of people affected by the violation could not be determined, but the number of queries made was 899 thousand 890. </p>
<p data-start="2189" data-end="2327">Şirket, ilgili kişilerin veri ihlali hakkında bilgi almak için <a data-start="2252" data-end="2268" class="decorated-link cursor-pointer" rel="noopener">dpo@uedas.com.tr<span aria-hidden="true" class="ms-0.5 inline-block align-middle leading-none"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" aria-hidden="true" data-rtl-flip="" class="block h-[0.75em] w-[0.75em] stroke-current stroke-[0.75]"></svg></span></a> e-posta adresi üzerinden iletişime geçebileceğini duyurdu.</p>
<p data-start="2329" data-end="2353"><strong data-start="2329" data-end="2353">Announcement Decision from the Board</strong></p>
<p data-start="2355" data-end="2595">It was announced that with the Decision of the Personal Data Protection Board dated 25.12.2025 and numbered 2025/2443, it was decided to announce the data breach notification on the Authority's website. </p>
<p data-start="2597" data-end="2736"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Computers Can Be Hacked with One Click: Moltbot Clawdbot Vulnerability Rings Alarm Bells in Cyber ​​Security</title>
<link>https://pursaklargundem.com/computers-can-be-hacked-with-one-click-moltbot-clawdbot-vulnerability-rings-alarm-bells-in-cyber-security</link>
<guid>https://pursaklargundem.com/computers-can-be-hacked-with-one-click-moltbot-clawdbot-vulnerability-rings-alarm-bells-in-cyber-security</guid>
<description><![CDATA[ The critical vulnerability discovered in the Clawdbot infrastructure, known as Moltbot, allows users to remotely run code on their systems by simply clicking on a malicious link.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_6988a36e05358.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 08 Feb 2026 20:06:54 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>moltbot clawdbot one click vulnerability, cve-2026-25253 security risk, how does remote code execution happen, artificial intelligence cyber security discovery</media:keywords>
<content:encoded><![CDATA[<p>Moltbot or as it is commonly known <strong data-start="510" data-end="522">clawbot</strong> üzerinde tespit edilen kritik bir güvenlik açığının, kullanıcı etkileşimi sonrasında doğrudan <strong data-start="617" data-end="643">remote code execution</strong> imkânı sağladığı bildirildi. Açık, <strong data-start="679" data-end="697">CVE-2026-25253</strong> numarasıyla kayıt altına alındı.</p>
<p></p>
<p data-start="732" data-end="1036">Güvenlik açığının, uygulamada kullanılan <strong data-start="773" data-end="814">insecure object serialization processes</strong> ile birlikte <strong data-start="828" data-end="880">due to lack of effective sandbox isolation</strong> kaynaklandığı belirtildi. Bu durumun, saldırganların tek bir bağlantı üzerinden hedef sistemde keyfi komutlar çalıştırabilmesine olanak tanıdığı aktarıldı.</p>
<p data-start="1038" data-end="1365"><strong data-start="1038" data-end="1085">Without Downloading Anything, Without Any Warnings</strong><br>Uzmanlar, açığın istismarı için <strong data-start="1118" data-end="1158">no file download required</strong>, <strong data-start="1160" data-end="1212">A multi-stage exploit chain is not used</strong> ve kullanıcıya <strong data-start="1228" data-end="1278">No security warnings are displayed</strong> vurguladı. Bağlantıya tıklanmasının ardından kodun doğrudan çalıştırıldığı kaydedildi.</p>
<p data-start="1367" data-end="1723"><strong data-start="1367" data-end="1404">Artificial Intelligence Detected It in Two Hours</strong><br>Zafiyetin dikkat çeken yönlerinden biri de keşif süreci oldu. Açığın, <strong data-start="1475" data-end="1506">an autonomous artificial intelligence agent</strong> tarafından uçtan uca analiz edilerek doğrulandığı, sürecin iki saatten kısa sürdüğü ifade edildi. Bu gelişmenin, yapay zekânın siber güvenlik alanındaki etkinliğine dair yeni bir dönemi işaret ettiği değerlendirildi.</p>
<p data-start="1725" data-end="1925">Authorities stated that institutions and individuals using systems connected to Moltbot/Clawdbot should examine network traffic, isolate relevant components and investigate possible traces of attack.</p>
<p data-start="1927" data-end="2073"><strong data-start="1927" data-end="1939"></strong></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>The person who opened this e&#45;mail sent under the name of PTT was burned. Card information is being captured through a customs duty trap.</title>
<link>https://pursaklargundem.com/the-person-who-opened-this-e-mail-sent-under-the-name-of-ptt-was-burned-card-information-is-being-captured-through-a-customs-duty-trap</link>
<guid>https://pursaklargundem.com/the-person-who-opened-this-e-mail-sent-under-the-name-of-ptt-was-burned-card-information-is-being-captured-through-a-customs-duty-trap</guid>
<description><![CDATA[ A new detail has emerged in the fake e-mails titled &quot;Customs duty must be paid for your shipment&quot; sent using the PTT name.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202602/image_870x580_69834bf57ca20.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 04 Feb 2026 18:36:56 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>ptt fake customs duty mail, ptt fraud link, customs duty phishing attack, constant contact fake ptt mail</media:keywords>
<content:encoded><![CDATA[<p>It was determined that citizens were tried to be defrauded with fake e-mails prepared using the PTT name and logo. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202602/image_870x_698349adf142c.webp" alt=""></p>
<p></p>
<p data-start="805" data-end="1188"><strong data-start="805" data-end="841">Suspicious Link Details Revealed</strong><br>Sahte e-postada yer alan “Ödemeyi Tamamla” butonuna tıklayan kullanıcıların, <strong data-start="919" data-end="943">i6ome8hbb.cc.rs6.net</strong> uzantılı, PTT ile hiçbir bağlantısı bulunmayan bir adrese yönlendirildiği tespit edildi. Bağlantının, Constant Contact altyapısı üzerinden gizlenmiş şekilde sunulduğu ve kullanıcıyı sahte ödeme sayfasına yönlendirmeyi amaçladığı ifade ediliyor.</p>
<p data-start="1190" data-end="1558"><strong data-start="1190" data-end="1235">Addresses Originating from Abroad Are Alarming</strong><br>In the sender address of the e-mail:<a data-start="1268" data-end="1307" class="decorated-link cursor-pointer" rel="noopener">info-santedicola.com@shared1.ccsend.com<span aria-hidden="true" class="ms-0.5 inline-block align-middle leading-none"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" aria-hidden="true" data-rtl-flip="" class="block h-[0.75em] w-[0.75em] stroke-current stroke-[0.75]"></svg></span></a>” ibaresinin yer aldığı, mesajın alt bölümünde ise ABD’ye ait açık adres bilgilerinin bulunduğu görüldü. Siber güvenlik uzmanları, bu tür <strong data-start="1445" data-end="1500">Addresses originating from abroad and looking corporate</strong>emphasizes that it is frequently used in phishing attacks.</p>
<p data-start="1560" data-end="1851"><strong data-start="1560" data-end="1599">Purpose Credit Card and Personal Data</strong><br>According to experts, credit card information, identity data and bank information are targeted on pages opened via fake links. </p>
<p data-start="1853" data-end="2193"><strong data-start="1853" data-end="1891">Does Not Match PTT's Practices</strong><br>PTT’nin resmî uygulamalarında gümrük vergisi bildirimlerinin e-posta yoluyla ve üçüncü taraf bağlantılar üzerinden yapılmadığı belirtiliyor. Kurumun, ödemelerin yalnızca <strong data-start="2062" data-end="2113">official website, e-Government and PTT branches</strong> aracılığıyla gerçekleştirildiğini daha önce kamuoyuna duyurduğu hatırlatılıyor.</p>
<p data-start="2195" data-end="2460"><strong data-start="2195" data-end="2228">Warning from Authorities to Citizens</strong><br>Cyber ​​security experts emphasize that such emails should never be opened, links should not be clicked, and payment information should not be entered. </p>
<p data-start="2462" data-end="2598"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Google Account Recovery Vulnerability Revealed: Any User&amp;apos;s Phone Number Could Be Leaked</title>
<link>https://pursaklargundem.com/google-account-recovery-vulnerability-revealed-any-users-phone-number-could-be-leaked</link>
<guid>https://pursaklargundem.com/google-account-recovery-vulnerability-revealed-any-users-phone-number-could-be-leaked</guid>
<description><![CDATA[ A security researcher has revealed that the phone number of any Google user can be detected under certain conditions, thanks to a vulnerability in Google&#039;s username recovery system, which works without JavaScript.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202601/image_870x580_697bc346e8755.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 30 Jan 2026 00:36:54 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is the google account recovery vulnerability, how did the google phone number leak occur, google botguard security vulnerability, has the google no js form been closed</media:keywords>
<content:encoded><![CDATA[<p>A security researcher discovered a long-unnoticed vulnerability in the Google account recovery infrastructure. <strong data-start="585" data-end="665">The phone number of any Google user can be leaked.</strong> açıkladı. Açık, Google’ın JavaScript devre dışı bırakıldığında da çalışan <strong data-start="740" data-end="772">username recovery form</strong> üzerinden istismar edilebildi.</p>
<p></p>
<p data-start="805" data-end="1146">The researcher found that this form, which runs even when JavaScript is turned off, verifies whether a phone number matches a specific name-surname through specific HTTP requests. </p>
<p data-start="1148" data-end="1492"><strong data-start="1148" data-end="1185">Two-Step Verification Mechanism</strong><br>In the first stage, a session key was generated with the phone number entered in the account recovery form. </p>
<p data-start="1494" data-end="1824">Başlangıçta IP bazlı hız sınırlaması ve captcha engeliyle karşılaşan araştırmacı, <strong data-start="1576" data-end="1609">BotGuard verification token</strong>He stated that these obstacles were overcome by taking the form with JavaScript and integrating it into the form without JavaScript. </p>
<p data-start="1826" data-end="2129"><strong data-start="1826" data-end="1861">IPv6 and Large-Scale Trials</strong><br>In the research, it was noted that by taking advantage of the width offered by IPv6 address spaces, a different IP was used for each request, thus speed limitations were neutralized. </p>
<p data-start="2131" data-end="2441"><strong data-start="2131" data-end="2183">Country Code and Name Information Could Also Be Detected</strong><br>Telefon numarasının ülke kodu, Google’ın “şifremi unuttum” akışında gösterdiği maskeli numara formatları üzerinden belirlenebildi. Araştırmacı, bu formatların Google’ın kullandığı açık kaynaklı <strong data-start="2378" data-end="2396">libphonenumber</strong> kütüphanesiyle birebir örtüştüğünü belirtti.</p>
<p data-start="2443" data-end="2684">Kullanıcının ad ve soyad bilgisine ise Google Looker Studio üzerinden ulaşıldı. Araştırmacı, oluşturulan bir belgenin hedef kullanıcıya devredilmesiyle, <strong data-start="2596" data-end="2674">the user's name is displayed on the home page without any interaction</strong> kaydetti.</p>
<p data-start="2686" data-end="3025"><strong data-start="2686" data-end="2740">“Possibility of Abuse Was Said Low, Reward Increased”</strong><br>Açık, 14 Nisan 2025’te Google’a bildirildi. Google, ilk değerlendirmede istismar olasılığını düşük bularak sınırlı bir ödül verdi. Araştırmacının itirazı sonrası yapılan yeniden değerlendirmede ise etkinin yüksek olduğu kabul edilerek ödül toplam <strong data-start="2988" data-end="3003">5 thousand dollars</strong> seviyesine çıkarıldı.</p>
<p data-start="3027" data-end="3259">Google, 22 Mayıs 2025 itibarıyla geçici önlemlerin devreye alındığını, 6 Haziran 2025’te ise <strong data-start="3120" data-end="3203">Username recovery form without JavaScript is completely disabled</strong> doğruladı. Açık, 9 Haziran 2025’te kamuoyuna açıklandı.</p>
<p data-start="3261" data-end="3426"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Hardware Alarm on Google Nest Wifi Pro Highest privilege level compromised on Qualcomm IPQ5018 with EM Glitching</title>
<link>https://pursaklargundem.com/hardware-alarm-on-google-nest-wifi-pro-highest-privilege-level-compromised-on-qualcomm-ipq5018-with-em-glitching</link>
<guid>https://pursaklargundem.com/hardware-alarm-on-google-nest-wifi-pro-highest-privilege-level-compromised-on-qualcomm-ipq5018-with-em-glitching</guid>
<description><![CDATA[ In their study on the Qualcomm IPQ5018 SoC used in the Google Nest Wifi Pro device, security researchers Cristofaro Mune and Niek Timmers revealed that it is possible to execute code at the Secure Monitor level with an electromagnetic fault injection attack.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202601/image_870x580_6975543ae6569.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 25 Jan 2026 04:06:55 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>google nest wifi pro em glitching attack, qualcomm ipq5018 vulnerability, secure monitor el3 hijacking, emfi hardware attack</media:keywords>
<content:encoded><![CDATA[<p><br>Google Nest Wifi Pro cihazlarında kullanılan <strong data-start="588" data-end="623">Qualcomm IPQ5018 system-chip</strong>, elektromanyetik hata enjeksiyonu saldırılarına karşı yeterli fiziksel direnç göstermediği ortaya çıktı. Güvenlik araştırmacıları <strong data-start="754" data-end="789">Cristofaro Mune and Niek Timmers</strong>, yürüttükleri çok aşamalı çalışmada, cihazın en yüksek ayrıcalık seviyesi olan <strong data-start="869" data-end="891">EL3 Secure Monitor</strong> bağlamında keyfi kod yürütmeyi başardıklarını açıkladı.</p>
<p></p>
<p data-start="949" data-end="1356">Araştırma, üç bölüm halinde yayımlandı. İlk bölümde çipin <strong data-start="1007" data-end="1052">Characterization against EMFI attacks</strong>, ikinci bölümde <strong data-start="1069" data-end="1132">Getting random reads and writes in Secure Monitor</strong>, üçüncü bölümde ise <strong data-start="1153" data-end="1191">Persistent code execution at EL3 level</strong> ayrıntıları paylaşıldı. Araştırmacılar, “Amaç, donanım tabanlı güvenlik mekanizmalarının gerçek dünyada ne kadar dayanıklı olduğunu ölçmekti.” ifadelerini kullandı.</p>
<p data-start="1358" data-end="1752"><strong data-start="1358" data-end="1410">How Electromagnetic Fault Injection Works</strong><br>The EMFI method is based on applying very short-term and high-energy electromagnetic pulses to the processor. </p>
<p data-start="1754" data-end="2217"><strong data-start="1754" data-end="1794">Secure Monitor Checks Bypassed</strong><br>Çalışmanın ikinci aşamasında, Secure Monitor tarafından uygulanan adres doğrulama mekanizmalarının hedef alındığı aktarıldı. Normal şartlarda yalnızca izin verilen bellek alanlarına erişim sağlayan <strong data-start="1993" data-end="2015">is_allowed_address</strong> benzeri kontrollerin, doğru zamanlamayla yapılan EMFI saldırıları sonucunda devre dışı bırakılabildiği kaydedildi. Bu sayede, <strong data-start="2142" data-end="2191">Random 32 bit read and write in EL3 context</strong> yapılabildiği vurgulandı.</p>
<p data-start="2219" data-end="2628"><strong data-start="2219" data-end="2254">XPU Configuration Changed</strong><br>Araştırmanın en kritik aşamasında, TrustZone adres alanlarını koruyan <strong data-start="2325" data-end="2350">XPU configuration</strong> yeniden programlanabildiği belirtildi. Araştırmacılar, “Tek bir başarılı glitch, Secure Monitor içinde keyfi uzunlukta kod yürütmek için yeterli.” ifadesini kullandı. Bu durumun, cihazın en korumalı yazılım katmanının tamamen kontrol altına alınması anlamına geldiği aktarıldı.</p>
<p data-start="2630" data-end="3004"><strong data-start="2630" data-end="2656">Attack is Difficult but Possible</strong><br>Araştırmacılar, saldırının pratikte yüksek beceri, hassas ekipman ve uzun deneme süreleri gerektirdiğini belirtti. Ortalama başarı süresinin <strong data-start="2798" data-end="2818">30 to 40 minutes</strong> arasında değiştiği, çok sayıda yeniden başlatma ve zamanlama denemesi gerektiği kaydedildi. Buna rağmen, elde edilen sonucun teorik değil, pratik olarak uygulanabilir olduğu vurgulandı.</p>
<p data-start="3006" data-end="3416"><strong data-start="3006" data-end="3038">Hardware Security Discussion</strong><br>The study revealed that software measures alone may not be sufficient in embedded network devices. </p>
<p data-start="3418" data-end="3565"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Critical Vulnerability Revealed in macOS: “TCC Protection Can Be Completely Bypassed”</title>
<link>https://pursaklargundem.com/critical-vulnerability-revealed-in-macos-tcc-protection-can-be-completely-bypassed</link>
<guid>https://pursaklargundem.com/critical-vulnerability-revealed-in-macos-tcc-protection-can-be-completely-bypassed</guid>
<description><![CDATA[ The critical vulnerability detected in Apple&#039;s desktop operating system macOS and tracked with the code CVE-2025-43530 allows attackers to completely disable the Transparency, Consent and Control mechanism.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202601/image_870x580_696f20919c86b.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 20 Jan 2026 10:36:55 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is macos tcc vulnerability, how does cve-2025-43530 work, macos 26.2 security update, apple tcc bypass vulnerability</media:keywords>
<content:encoded><![CDATA[<p>Detected in Apple's macOS operating system <strong data-start="530" data-end="555">critical vulnerability</strong>, kullanıcı gizliliğini korumak amacıyla geliştirilen <strong data-start="609" data-end="653">Transparency, Consent, and Control (TCC)</strong> mekanizmasının tamamen aşılmasına yol açtı. <strong data-start="698" data-end="716">CVE-2025-43530</strong> olarak kayda geçen zafiyetin, herhangi bir yönetici yetkisi gerektirmeden istismar edilebildiği bildirildi.</p>
<p></p>
<p data-start="826" data-end="1169"><strong data-start="826" data-end="868">Exploitation via VoiceOver Framework</strong><br>Güvenlik araştırmacıları, açığın <strong data-start="902" data-end="927">VoiceOver framework</strong> ve <strong data-start="931" data-end="950">com.apple.scrod</strong> adlı sistem servisi üzerinden tetiklendiğini belirtti. Bu yöntemle saldırganların, Apple tarafından imzalanmış süreçlere kod enjekte edebildiği ve bu süreçler aracılığıyla <strong data-start="1123" data-end="1155">Can run AppleScript</strong> ifade edildi.</p>
<p data-start="1171" data-end="1641"><strong data-start="1171" data-end="1212">Full TCC Overrun with TOCTOU Race Condition</strong><br>İstismarın temelinde, <strong data-start="1235" data-end="1273">Time-of-Check-Time-of-Use (TOCTOU)</strong> türü bir yarış koşulunun yer aldığı kaydedildi. Kod enjeksiyonu ile bu yarış koşulunun birlikte kullanılması sonucunda, saldırganların <strong data-start="1409" data-end="1538">It can interact with the Finder, read files, access the microphone, and run arbitrary AppleScript commands.</strong> aktarıldı. Tüm bu işlemlerin kullanıcıya herhangi bir bildirim gönderilmeden gerçekleştiği vurgulandı.</p>
<p data-start="1643" data-end="1974"><strong data-start="1643" data-end="1683">Apple: Open Closed with macOS 26.2</strong><br>Apple, güvenlik açığının <strong data-start="1709" data-end="1723">macOS 26.2</strong> sürümünde giderildiğini duyurdu. Şirket, <strong data-start="1765" data-end="1806">com.apple.private.accessibility.scrod</strong> yetkisinin artık <strong data-start="1824" data-end="1847">transaction audit token</strong> üzerinden doğrulandığını ve bu sayede hem kod enjeksiyonu açığının hem de TOCTOU penceresinin ortadan kaldırıldığını açıkladı.</p>
<p data-start="1976" data-end="2294"><strong data-start="1976" data-end="2012">Update Call to Users</strong><br>Apple, kullanıcıların sistemlerini en kısa sürede güncellemelerini önerdi. Güncellemenin, <strong data-start="2103" data-end="2148">macOS → System Settings → Software Update</strong> adımları izlenerek yapılabileceği hatırlatıldı. Güvenlik uzmanları, açığın kapsamı nedeniyle güncellemenin geciktirilmemesi gerektiğini belirtti.</p>
<p data-start="2296" data-end="2430"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Information Security Expert Mustafa Yılmaz: “2025 cyber attacks directly threatened economic stability and national security”</title>
<link>https://pursaklargundem.com/information-security-expert-mustafa-yilmaz-2025-cyber-attacks-directly-threatened-economic-stability-and-national-security</link>
<guid>https://pursaklargundem.com/information-security-expert-mustafa-yilmaz-2025-cyber-attacks-directly-threatened-economic-stability-and-national-security</guid>
<description><![CDATA[ In the evaluation made by Information Security Expert Mustafa Yılmaz, it was emphasized that the large-scale cyber attacks experienced around the world in 2025 no longer target only information systems but also global supply chains, heavy industry, aviation and public infrastructures.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202601/image_870x580_696c2900c124a.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 18 Jan 2026 22:06:56 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the biggest cyber attacks in 2025, supply chain cyber risks, artificial intelligence-supported cyber attacks, cyber resilience strategies</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="673" data-end="691">Information Security Specialist Mustafa Yılmaz</strong>shared the analysis of global cyber attacks experienced in 2025. </p>
<p data-start="954" data-end="1479"><strong data-start="954" data-end="1010">Supply Chain Crisis in the UK Retail Industry</strong><br>Nisan 2025’te Marks & Spencer, Co-op ve Harrods’a yönelik düzenlenen fidye yazılımı saldırıları, yılın en çok ses getiren olayları arasında yer aldı. Scattered Spider bağlantılı saldırganların üçüncü taraf bir hizmet sağlayıcısını hedef aldığına dikkat çeken Yılmaz, “Tek bir tedarikçi zafiyeti, tüm sektörü domino etkisiyle felç edebiliyor.” dedi. Marks & Spencer’ın vergi öncesi kârının altı ayda <strong data-start="1410" data-end="1457">From £391.9 million to £3.4 million</strong> düştüğü hatırlatıldı.</p>
<p data-start="1481" data-end="1829"><strong data-start="1481" data-end="1528">Production at Jaguar Land Rover Stopped for Five Weeks</strong><br>It was stated that the attack on Jaguar Land Rover in August 2025 was recorded as the costliest cyber incident in British history. </p>
<p data-start="1831" data-end="2136"><strong data-start="1831" data-end="1874">The Cost of Digital Dependency in Aviation</strong><br>An attack on Collins Aerospace's vMUSE systems in March 2025 caused serious disruptions at more than 20 airports across Europe. </p>
<p data-start="2138" data-end="2448"><strong data-start="2138" data-end="2174">Municipal Systems Collapsed in the USA</strong><br>In July 2025, St. </p>
<p data-start="2450" data-end="2803"><strong data-start="2450" data-end="2498">The First Autonomous Cyber ​​Attack Supported by Artificial Intelligence</strong><br>Referring to the report published by Anthropic in November 2025, Yılmaz said, "The first large-scale cyber attack carried out by artificial intelligence with its own decisions, without human intervention, has been documented." </p>
<p data-start="2805" data-end="3027">Yılmaz summarized the common message of the attacks in 2025 with the following words: "Third party risks, cloud integrations, operational technology security and identity management are now at the center of cyber defense."</p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​Security Expert Mustafa Yılmaz: “2025 cyber attacks directly threatened economic stability and national security”</title>
<link>https://pursaklargundem.com/cyber-security-expert-mustafa-yilmaz-2025-cyber-attacks-directly-threatened-economic-stability-and-national-security</link>
<guid>https://pursaklargundem.com/cyber-security-expert-mustafa-yilmaz-2025-cyber-attacks-directly-threatened-economic-stability-and-national-security</guid>
<description><![CDATA[ In the evaluation made by Cyber ​​Security Expert Mustafa Yılmaz, it was emphasized that the large-scale cyber attacks experienced around the world in 2025 no longer target only information systems but also global supply chains, heavy industry, aviation and public infrastructures.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202601/image_870x580_696c2900c124a.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 18 Jan 2026 04:36:55 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the biggest cyber attacks in 2025, supply chain cyber risks, artificial intelligence-supported cyber attacks, cyber resilience strategies</media:keywords>
<content:encoded><![CDATA[<p><br>Siber Güvenlik ve Bilgi Güvenliği Yönetim Sistemleri uzmanı <strong data-start="673" data-end="691">Mustafa Yilmaz</strong>shared the analysis of global cyber attacks experienced in 2025. </p>
<p></p>
<p data-start="954" data-end="1479"><strong data-start="954" data-end="1010">Supply Chain Crisis in the UK Retail Industry</strong><br>Nisan 2025’te Marks & Spencer, Co-op ve Harrods’a yönelik düzenlenen fidye yazılımı saldırıları, yılın en çok ses getiren olayları arasında yer aldı. Scattered Spider bağlantılı saldırganların üçüncü taraf bir hizmet sağlayıcısını hedef aldığına dikkat çeken Yılmaz, “Tek bir tedarikçi zafiyeti, tüm sektörü domino etkisiyle felç edebiliyor.” dedi. Marks & Spencer’ın vergi öncesi kârının altı ayda <strong data-start="1410" data-end="1457">From £391.9 million to £3.4 million</strong> düştüğü hatırlatıldı.</p>
<p data-start="1481" data-end="1829"><strong data-start="1481" data-end="1528">Production at Jaguar Land Rover Stopped for Five Weeks</strong><br>It was stated that the attack on Jaguar Land Rover in August 2025 was recorded as the costliest cyber incident in British history. </p>
<p data-start="1831" data-end="2136"><strong data-start="1831" data-end="1874">The Cost of Digital Dependency in Aviation</strong><br>An attack on Collins Aerospace's vMUSE systems in March 2025 caused serious disruptions at more than 20 airports across Europe. </p>
<p data-start="2138" data-end="2448"><strong data-start="2138" data-end="2174">Municipal Systems Collapsed in the USA</strong><br>In July 2025, St. </p>
<p data-start="2450" data-end="2803"><strong data-start="2450" data-end="2498">The First Autonomous Cyber ​​Attack Supported by Artificial Intelligence</strong><br>Referring to the report published by Anthropic in November 2025, Yılmaz said, "The first large-scale cyber attack carried out by artificial intelligence with its own decisions, without human intervention, has been documented." </p>
<p data-start="2805" data-end="3027">Yılmaz summarized the common message of the attacks in 2025 with the following words: "Third party risks, cloud integrations, operational technology security and identity management are now at the center of cyber defense."</p>
<p data-start="3029" data-end="3180"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Dark Web Informer announces NordVPN claim: “Salesforce database and API keys leaked”</title>
<link>https://pursaklargundem.com/dark-web-informer-announces-nordvpn-claim-salesforce-database-and-api-keys-leaked</link>
<guid>https://pursaklargundem.com/dark-web-informer-announces-nordvpn-claim-salesforce-database-and-api-keys-leaked</guid>
<description><![CDATA[ Cybersecurity monitoring platform Dark Web Informer claimed that a development server containing Salesforce and Jira data belonging to NordVPN was compromised.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202601/image_870x580_695b0cff3f931.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 05 Jan 2026 04:36:55 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>nordvpn data leak claim, dark web informer nordvpn news, salesforce api key leak, vpn company cyber attack</media:keywords>
<content:encoded><![CDATA[<p>Cyber ​​threat intelligence account <strong data-start="512" data-end="533">Dark Web Informer</strong>, NordVPN’e yönelik ciddi bir veri sızıntısı iddiasını kamuoyuna duyurdu. Paylaşıma göre, <strong data-start="623" data-end="633">“1011”</strong> takma adlı bir tehdit aktörü, NordVPN’in geliştirme ortamına yetkisiz erişim sağladığını ve kritik sistem verilerini ele geçirdiğini öne sürdü.</p>
<p><img src="https://cumha.com.tr/uploads/images/202601/image_870x_695b0a81880d6.webp" alt=""></p>
<p data-start="779" data-end="1063"><strong data-start="779" data-end="812">Shared on Dark Web Forum</strong><br>Dark Web Informer tarafından aktarılan bilgilere göre, sızdırıldığı iddia edilen veriler bir dark web forumunda satışa veya paylaşıma açıldı. Tehdit aktörü, ele geçirilen bilgilerin <strong data-start="995" data-end="1045">NordVPN's Salesforce database contents</strong> olduğunu savundu.</p>
<p data-start="1065" data-end="1328"><strong data-start="1065" data-end="1099">Claimed Access via Brute Force</strong><br>Paylaşımda, saldırganın <strong data-start="1124" data-end="1221">brute-forced a misconfigured NordVPN development server</strong> ileri sürüldü. Bu sunucuda Salesforce ve Jira sistemlerine ait bilgilerin birlikte tutulduğu iddia edildi.</p>
<p data-start="1330" data-end="1606"><strong data-start="1330" data-end="1366">Allegedly Leaked Data</strong><br>Dark Web Informer reported that the following information was obtained through the samples the threat actor claimed to have shared:<br>10+ database source codes, Salesforce API keys, Jira access tokens, and additional sensitive technical information.</p>
<p><img src="https://cumha.com.tr/uploads/images/202601/image_870x_695b0a8dec95d.webp" alt=""></p>
<p data-start="1608" data-end="1909"><strong data-start="1608" data-end="1636">SQL Dumps Shared</strong><br>Forumda yayınlanan örnek SQL dökümlerinde, <strong data-start="1680" data-end="1713">“salesforce_api_step_details”</strong> ve <strong data-start="1717" data-end="1731">“api_keys”</strong> tablolarına ait yapılar ile ayrıntılı veritabanı şema bilgilerinin yer aldığı öne sürüldü. Bu örneklerin, iddiaların gerçekliğini desteklemek amacıyla paylaşıldığı ifade edildi.</p>
<p data-start="1911" data-end="2207"><strong data-start="1911" data-end="1952">Official Statement from NordVPN is Expected</strong><br>Sızıntı iddialarına ilişkin olarak NordVPN tarafından şu ana kadar kamuoyuna yansımış resmî bir açıklama bulunmuyor. Uzmanlar, iddiaların doğrulanması hâlinde bunun <strong data-start="2118" data-end="2195">It may have important consequences in terms of trust in VPN services.</strong> belirtiyor.</p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Critical Process After the Cyber ​​Attack at Aras Cargo: Tracking Screens Are Back in Use as Systems Are Gradually Opened</title>
<link>https://pursaklargundem.com/critical-process-after-the-cyber-attack-at-aras-cargo-tracking-screens-are-back-in-use-as-systems-are-gradually-opened</link>
<guid>https://pursaklargundem.com/critical-process-after-the-cyber-attack-at-aras-cargo-tracking-screens-are-back-in-use-as-systems-are-gradually-opened</guid>
<description><![CDATA[ Aras Kargo shared with the public updated information about the improvement efforts carried out after the cyber attack targeting its servers on November 30, 2025.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202512/image_870x580_693356130e70e.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 09 Dec 2025 11:36:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>aras cargo cyber attack description, why is the aras cargo tracking system not opening, has cargo distribution started again, aras cargo branch operations status</media:keywords>
<content:encoded><![CDATA[<p><br data-start="680" data-end="683">Aras Kargo published a new statement regarding the technical processes carried out after the cyber attack targeting its servers on November 30, 2025. </p>
<p></p>
<p data-start="966" data-end="1246"><strong data-start="966" data-end="1015">Cargo Tracking Systems Reopened</strong><br data-start="1015" data-end="1018">Şirket, kargo takip ekranlarının <strong data-start="1051" data-end="1090">As of 1 December 2025 at 17.30</strong> kullanılabilir hâle geldiğini bildirdi. Açıklamada, “Bu kapsamda kargo takip ekranlarımızdaki veriler en kısa sürede güncellenecektir.” ifadeleri yer aldı.</p>
<p data-start="1248" data-end="1621"><strong data-start="1248" data-end="1290">Temporary Slowdowns and Outages Warning</strong><br data-start="1290" data-end="1293">Aras Kargo, iyileştirme sürecinin devam ettiği dönemde anlık sistem yavaşlamaları ve erişim kesintilerinin görülebileceğini belirterek, ekiplerin <strong data-start="1439" data-end="1455">24/7 operation</strong> yürüttüğünü aktardı. Yapılan açıklamada, “Tüm hizmetlerimizi en hızlı ve güvenli şekilde eski hâline getirebilmek için ekiplerimiz aralıksız çalışmaktadır.” denildi.</p>
<p data-start="1623" data-end="1964"><strong data-start="1623" data-end="1668">Distribution and Branch Operations Restarted</strong><br data-start="1668" data-end="1671">Announcing that distribution operations have been reactivated, the company stated that temporary interruptions in data flow may affect delivery times. </p>
<p data-start="1966" data-end="2274"><strong data-start="1966" data-end="2009">Work Continues for Full Normalization</strong><br data-start="2009" data-end="2012">Aras Kargo stated that its technical teams continue their improvement efforts to ensure that all systems operate at full capacity. </p>
<p data-start="2276" data-end="2440"><strong data-start="2276" data-end="2288"></strong></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Konya Informatics Association President Mustafa Yılmaz: “The first autonomous artificial intelligence cyber attack in history has officially occurred”</title>
<link>https://pursaklargundem.com/konya-informatics-association-president-mustafa-yilmaz-the-first-autonomous-artificial-intelligence-cyber-attack-in-history-has-officially-occurred</link>
<guid>https://pursaklargundem.com/konya-informatics-association-president-mustafa-yilmaz-the-first-autonomous-artificial-intelligence-cyber-attack-in-history-has-officially-occurred</guid>
<description><![CDATA[ In the report published by Anthropic on November 17, 2025, it was documented that the China-based hacker group GTG-1002 carried out an almost completely autonomous artificial intelligence-supported cyber attack for the first time in history using the Claude Code model.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202512/image_870x580_6935e4b95f50a.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 09 Dec 2025 11:06:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is artificial intelligence autonomous attack, how was Claude code manipulated, what did the gtg1002 attack target, mustafa yılmaz artificial intelligence warning</media:keywords>
<content:encoded><![CDATA[<p>Anthropic company's security report dated November 17, 2025 revealed that the Chinese hacker group GTG-1002 turned the Claude Code model, known as a software development assistant, into an autonomous attack tool. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202512/image_870x_6935e5286d902.webp" alt=""></p>
<p></p>
<p data-start="1099" data-end="1476"><strong data-start="1099" data-end="1145">Human Contribution Decreased to 10 Percent</strong><br data-start="1145" data-end="1148">According to the report, the model automatically coordinated 80 to 90 percent of tactical processes in operations against a wide range of targets, from large technology companies to financial institutions and chemical production facilities. </p>
<p data-start="1478" data-end="1787">Konya Bilişim Derneği Siber Güvenlik Birim Başkanı <strong data-start="1529" data-end="1547">Mustafa Yilmaz</strong>, in its assessment, “The first autonomous, artificial intelligence, cyber attack in history has officially occurred.” </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202512/image_870x_6935e525040a2.webp" alt=""></p>
<p data-start="1789" data-end="2173"><strong data-start="1789" data-end="1836">Bypassed Ethics Protocols with Social Engineering</strong><br data-start="1836" data-end="1839">One of the notable findings of the report was that attackers bypassed the security restrictions of artificial intelligence not through technical vulnerabilities but through social engineering methods. </p>
<p data-start="2175" data-end="2409">Anthropic experts stated that the model carries out critical steps in the target systems on its own, adopting this role as a real task. </p>
<p data-start="2411" data-end="2770"><strong data-start="2411" data-end="2472">Attackers' Power Isn't in New Code, It's in AI Coordination</strong><br data-start="2472" data-end="2475">The report stated that attackers preferred open source and widespread penetration testing tools instead of producing new malware. </p>
<p data-start="2772" data-end="2987">This approach demonstrated that state-level cyber capabilities are now accessible to small groups. </p>
<p data-start="2989" data-end="3352"><strong data-start="2989" data-end="3025">Artificial Intelligence Necessity in Defense</strong><br data-start="3025" data-end="3028">Anthropic security team announced that they again used the Claude model in the analysis of the attack. </p>
<p data-start="3354" data-end="3506"><strong data-start="3354" data-end="3366"></strong></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Android 0&#45;click RCE vulnerability CVE&#45;2025&#45;48593: Google issues critical security alert</title>
<link>https://pursaklargundem.com/android-0-click-rce-vulnerability-cve-2025-48593-google-issues-critical-security-alert</link>
<guid>https://pursaklargundem.com/android-0-click-rce-vulnerability-cve-2025-48593-google-issues-critical-security-alert</guid>
<description><![CDATA[ Google has reported a 0-click remote code execution vulnerability (CVE-2025-48593, A-374746961) in the System component.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202511/image_870x580_69118a886f385.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 10 Nov 2025 09:49:53 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Android 0click RCE vulnerability, cve2025-48593 details, Android 16 EOP vulnerability, Google security update recommendations</media:keywords>
<content:encoded><![CDATA[<p data-start="776" data-end="1054">Google, System bileşeninde keşfedilen ve kullanıcı müdahalesi olmadan tetiklenebilen kritik bir uzaktan kod çalıştırma (RCE) zafiyetini <strong data-start="933" data-end="965">CVE-2025-48593 (A-374746961)</strong> olarak duyurdu. Açığın etkilendiği sürümler Android 13, 14, 15 ve 16 olarak açıklandı.</p>
<p data-start="1056" data-end="1393"><strong data-start="1056" data-end="1088">Technical Details of the Vulnerability</strong><br data-start="1088" data-end="1091">Google tarafından yayımlanan özet rapora göre, açığın kök nedeni hatalı input-parsing sürecinde oluşan <strong data-start="1194" data-end="1238">memory corruption (heap/stack corruption)</strong> olarak değerlendiriliyor. Bu durum, kötü niyetli verilerin sistem servisleri veya arka plan işlemleri aracılığıyla işlenmesi sırasında tetiklenebiliyor.</p>
<p data-start="1395" data-end="1727"><strong data-start="1395" data-end="1431">Attack Vectors and Domain</strong><br data-start="1431" data-end="1434">Saldırganların özel hazırlanmış paketler veya <strong data-start="1480" data-end="1520">sideloaded malicious APKs</strong> kullanarak cihazlarda uzaktan kod çalıştırma yetkisi elde edebildiği bildirildi. Açığın, IPC/Binder çağrıları, medya ve ağ parser’ları gibi arka plan bileşenleri üzerinden tetiklenebilmesi dikkat çekiyor.</p>
<p data-start="1729" data-end="2021"><strong data-start="1729" data-end="1769">Other Related Vulnerability: CVE-2025-48581</strong><br data-start="1769" data-end="1772">Google ayrıca Android 16 sürümünde tespit edilen yüksek riskli bir <strong data-start="1839" data-end="1868">escalation of privilege (EoP)</strong> zafiyetini <strong data-start="1880" data-end="1912">CVE-2025-48581 (A-428945391)</strong> koduyla duyurdu. Bu zafiyetin RCE açığıyla birlikte zincirleme olarak kullanılabileceği değerlendiriliyor.</p>
<p data-start="2023" data-end="2362"><strong data-start="2023" data-end="2068">Warning and Safety Recommendations for Users</strong><br data-start="2068" data-end="2071">Uzmanlar, bu tür “0-click” saldırıların kullanıcıdan herhangi bir etkileşim gerektirmediği için özellikle tehlikeli olduğunu belirtiyor. Google, kullanıcıların <strong data-start="2231" data-end="2291">install official security updates without waiting</strong>, ayrıca <strong data-start="2300" data-end="2352">Do not install applications from unknown sources</strong> önerdi.</p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>40,000 Active SIM Cards were Seized in the “SIMCARTEL” Operation Organized Across Europe</title>
<link>https://pursaklargundem.com/40000-active-sim-cards-were-seized-in-the-simcartel-operation-organized-across-europe</link>
<guid>https://pursaklargundem.com/40000-active-sim-cards-were-seized-in-the-simcartel-operation-organized-across-europe</guid>
<description><![CDATA[ In the international operation called &quot;SIMCARTEL&quot;, based in Latvia, under the coordination of Europol and Eurojust, a giant SIM farm network used for fraudulent purposes was brought down.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202510/image_870x580_68fbc27371de6.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 31 Oct 2025 09:41:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is simcartel operation, europol simbox raid, sim farm fraud, sim card use in fake accounts</media:keywords>
<content:encoded><![CDATA[<p>As part of a large-scale cybercrime operation carried out in Europe <strong data-start="704" data-end="745">SIM farm network codenamed “SIMCARTEL”</strong> ortaya çıkarıldı. Europol ve Eurojust koordinasyonunda yürütülen çalışmada, Letonya Devlet Polisi öncülüğünde Avusturya, Estonya ve Finlandiya kolluk birimleri eş zamanlı baskınlar düzenledi. Operasyon, 10 Ekim 2025 tarihinde icra edildi ve kamuoyuna 17–20 Ekim tarihleri arasında duyuruldu.</p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68fbc21aa791a.webp" alt=""></p>
<p></p>
<p data-start="1041" data-end="1527"><strong data-start="1041" data-end="1093">1,200 SIM-Boxes and 40,000 Active Cards Seized</strong><br data-start="1093" data-end="1096">Authorities announced that the network makes international calls appear local by using tens of thousands of SIM cards placed in SIM-box devices in different countries, and that it plays an active role in identity concealment, fake investment and phishing scams. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68fbc2193002d.webp" alt=""></p>
<p data-start="1529" data-end="1969"><strong data-start="1529" data-end="1568">Fake Account Network in More than 80 Countries</strong><br data-start="1568" data-end="1571">Europol açıklamasına göre, ağ 80’den fazla ülkenin telefon numaralarıyla yaklaşık <strong data-start="1653" data-end="1696">49 to 50 million fake online accounts</strong> oluşturmayı mümkün kıldı. Bu hesapların kimlik hırsızlığı, dolandırıcılık ve yasa dışı finansman faaliyetlerinde kullanıldığı değerlendiriliyor. Sadece Avusturya ve Letonya’da 3.200’den fazla vaka tespit edilirken, zararın toplamda 5 milyon euroya yaklaştığı bildirildi.</p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68fbc21787a42.webp" alt=""></p>
<p data-start="1971" data-end="2196"><strong data-start="1971" data-end="1994">Sites Seized</strong><br data-start="1994" data-end="1997">Yetkililer, suçta kullanılan <strong data-start="2026" data-end="2042">gogetsms.com</strong> ve <strong data-start="2046" data-end="2060">apisim.com</strong> alan adlarına el koydu. Bu platformların, ağ üyelerine sahte numara üretimi ve SMS kimlik doğrulama hizmetleri sunduğu tespit edildi.</p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68fbc215eab1b.webp" alt=""></p>
<p data-start="2198" data-end="2496"><strong data-start="2198" data-end="2248">International Cooperation and the Course of the Investigation</strong><br data-start="2248" data-end="2251">Europol provided operational support, while Eurojust carried out judicial coordination. </p>
<p data-start="2498" data-end="2790"><strong data-start="2498" data-end="2529">A Blow to the Cybercrime Economy</strong><br data-start="2529" data-end="2532">Experts state that the operation is an important step in dismantling "cybercrime-as-a-service" structures. </p>
<p data-start="2792" data-end="2924"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Common SMS fraud disguised as HGS debt warning: Personal data is targeted with a 795 TL mobile payment link</title>
<link>https://pursaklargundem.com/common-sms-fraud-disguised-as-hgs-debt-warning-personal-data-is-targeted-with-a-795-tl-mobile-payment-link</link>
<guid>https://pursaklargundem.com/common-sms-fraud-disguised-as-hgs-debt-warning-personal-data-is-targeted-with-a-795-tl-mobile-payment-link</guid>
<description><![CDATA[ Fake SMS messages sent to citizens claiming to have HGS debt and requesting payment of 795 TL by October 14, 2025, are reaching citizens.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202510/image_870x580_68ed188c7be92.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 13 Oct 2025 18:22:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Is this SMS real, What happens if I click on the link, How can I be protected, To whom should I complain</media:keywords>
<content:encoded><![CDATA[<p data-start="792" data-end="1124">In the SMS sent under the guise of traffic toll notification, it is stated that the vehicle owner has an unpaid HGS debt of 795.00 TL. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68ed16e6a1c9b.webp" alt=""></p>
<p data-start="1126" data-end="1672">The user who clicks on the short link in the SMS is first directed to the fake page opened in the mobile browser. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68ed16d601ead.webp" alt=""></p>
<p data-start="1674" data-end="1964"><br data-start="1693" data-end="1696">Cyber ​​security researcher and journalist Ebubekir Bastama stated that during the examination, he found that the site was only opened on mobile devices and that a phone number was requested at the first stage. </p>
<p data-start="1966" data-end="2237">This Fake SMS was detected by a citizen who was trained by Bastama. </p>
<p data-start="1966" data-end="2237">An example of the SMS text is as follows:<br data-start="2889" data-end="2892">"Dear Vehicle Owner, According to the system records, the highway toll for your vehicle has not been paid because your HGS balance is insufficient. To avoid being penalized, please complete your payment by October 14, 2025. Unpaid Amount: 795.00 TL Payment Link: https:[//]kgminfo[.]cc/gv?qr=3urgOi"<br data-start="3186" data-end="3189">In the mobile browser that clicks on the link, the phone number is requested at the first stage; </p>
<p data-start="3420" data-end="3565">Messages that come with the names of official institutions but cannot be verified should not be relied upon. </p>
<ul data-start="3566" data-end="4052">
<li data-start="3566" data-end="3632">
<p data-start="3568" data-end="3632">Never click on the incoming link and delete the message.</p>
</li>
<li data-start="3633" data-end="3701">
<p data-start="3635" data-end="3701">Blocking the sending number and reporting it to the mobile operator.</p>
</li>
<li data-start="3702" data-end="3801">
<p data-start="3704" data-end="3801">If the phone number and card information are entered, immediately contact the bank and have the card blocked.</p>
</li>
</ul>
<p data-start="4054" data-end="4537"><br data-start="4073" data-end="4076">Official institutions generally do not request payment directly through short links within SMS. </p>
<p data-start="4539" data-end="4627"></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>South Korea Government Data Center Fire: 858 TB permanent data loss, 709 public systems affected</title>
<link>https://pursaklargundem.com/south-korea-government-data-center-fire-858-tb-permanent-data-loss-709-public-systems-affected</link>
<guid>https://pursaklargundem.com/south-korea-government-data-center-fire-858-tb-permanent-data-loss-709-public-systems-affected</guid>
<description><![CDATA[ On September 26, 2025, a fire broke out at the National Information Resources Service (NIRS) data center in Daejeon, South Korea, completely destroying the country&#039;s G-Drive cloud system.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202510/image_870x580_68ea7a6197a93.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 11 Oct 2025 18:46:52 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What was the reason for the 858 TB data loss, to what extent were public services affected, why was there no backup in the G-Drive system, what technical findings does the investigation focus on</media:keywords>
<content:encoded><![CDATA[<h1>South Korea NIRS Data Center Fire: 858 TB Data Loss and 709 Utility Outages</h1>
<p>The fire that occurred on the evening of September 26, 2025, at the government data center of the National Information Resources Service (NIRS) in Daejeon, South Korea, caused serious disruptions in the country's digital infrastructure. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68ea7af725960.webp" alt=""></p>
<h2>First findings of the fire</h2>
<p>According to initial findings, the incident started as a result of a malfunction in the lithium-ion batteries in the energy storage area. </p>
<h2>709 public services affected</h2>
<p>709 online public services were temporarily stopped after the fire. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68ea7af842659.webp" alt=""></p>
<h2>Lack of backup increased the scale of the crisis</h2>
<p>Most of the losses were due to the G-Drive system not having an external backup infrastructure. </p>
<h2>Investigation focused on battery-induced scenario</h2>
<p>Police and technical teams are continuing their investigation to confirm that the fire was caused by lithium-ion batteries. </p>
<h2>Official reactions and measures taken</h2>
<p>President Lee Jae-myung visited the data center after the incident and ordered to strengthen redundancy standards. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202510/image_870x_68ea7af95de53.webp" alt=""></p>
<h2>Expert opinions</h2>
<p>Experts emphasized that "cloud systems are not immune from physical risks." </p>
<h2>timeline</h2>
<ul>
<li>
<p><strong>September 26, 2025:</strong> Yangın 20.15 civarında başladı, hızla yayıldı.</p>
</li>
<li>
<p><strong>September 27, 2025:</strong> Yangın kontrol altına alındı.</p>
</li>
<li>
<p><strong>October 1, 2025:</strong> G-Drive verilerinin kurtarılamadığı kesinleşti.</p>
</li>
<li>
<p><strong>October 10, 2025:</strong> Kurtarma oranı %30,6’ya ulaştı.</p>
</li>
</ul><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Critical vulnerability in WordPress &amp;quot;Service Finder&amp;quot; theme: Attackers can take over administrator accounts</title>
<link>https://pursaklargundem.com/critical-vulnerability-in-wordpress-service-finder-theme-attackers-can-take-over-administrator-accounts</link>
<guid>https://pursaklargundem.com/critical-vulnerability-in-wordpress-service-finder-theme-attackers-can-take-over-administrator-accounts</guid>
<description><![CDATA[ A critical vulnerability detected in the reservation module of the &quot;Service Finder&quot; theme used on WordPress-based sites allows attackers to access administrator accounts without authentication.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202510/image_870x580_68e8ca6960676.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 10 Oct 2025 12:00:47 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Which versions does the vulnerability detected in the Service Finder theme affect, ​​How do attackers exploit this vulnerability, From which IP addresses were attack attempts detected, What steps should users take to protect their systems</media:keywords>
<content:encoded><![CDATA[<p>A critical security vulnerability has been detected in the reservation module in the WordPress theme “Service Finder”. </p>
<p></p>
<p data-start="874" data-end="1216">According to experts, the vulnerability is caused by the malfunction of the function called “service_finder_switch_back()”. </p>
<p data-start="1218" data-end="1446">Cyber ​​security researchers state that the vulnerability in question allows malicious people to change content, update passwords, add malicious code or use the site in phishing and malware campaigns.</p>
<p data-start="1448" data-end="1810"><strong data-start="1448" data-end="1473">Domain and Risks</strong><br data-start="1473" data-end="1476">The vulnerability affects all versions of the “Service Finder” theme up to version 6.0. </p>
<p data-start="1812" data-end="2076">According to security reports, requests from IP addresses 5.189.221.98, 185.109.21.157, 192.121.16.196, 194.68.32.71 and 178.125.204.198 were detected in the attack attempts. </p>
<p data-start="2078" data-end="2430"><strong data-start="2078" data-end="2107">Precautions to be Taken</strong><br data-start="2107" data-end="2110">Experts recommend switching to version 6.0 or later of the theme, reviewing all user accounts and permissions, and activating plugins such as firewall (WAF) or Wordfence. </p>
<p data-start="2432" data-end="2575">If the system is planned to be restored from backup, it is necessary to ensure that the backups used are taken from a clean and reliable source.</p>
<p data-start="2577" data-end="2832"><strong data-start="2577" data-end="2589"></strong></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>US Secret Service 100 thousand SIM cards around the UN General Assembly collapsed the secret communication network</title>
<link>https://pursaklargundem.com/us-secret-service-100-thousand-sim-cards-around-the-un-general-assembly-collapsed-the-secret-communication-network</link>
<guid>https://pursaklargundem.com/us-secret-service-100-thousand-sim-cards-around-the-un-general-assembly-collapsed-the-secret-communication-network</guid>
<description><![CDATA[ The US Secret Service organized an operation for a telecommunication network with capacity to target world leaders during the United Nations General Assembly in New York.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68d31c792f687.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 24 Sep 2025 01:22:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>The capacity of the US Secret Service had the capacity, the devices concentrated on the vicinity of the UN General Assembly, which actors behind this secret system are being investigated and the judicial investigation will reveal the results</media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="590" data-end="899">The US Secret Service carried out a critical operation for the security of the United Nations (UN) General Assembly in New York. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202509/image_870x_68d31c8ba1386.webp" alt=""></p>
<p data-start="901" data-end="1292"><strong data-start="901" data-end="922">Threat capacity</strong><br data-start="922" data-end="925">Authorities, the seized system is able to send 30 million SMS per minute. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202509/image_870x_68d31c8d2a116.webp" alt=""></p>
<p data-start="1294" data-end="1530"><strong data-start="1294" data-end="1335">Concentration around the UN General Assembly</strong><br data-start="1335" data-end="1338">Most of the devices identified in the operation were found around the region where the UN General Assembly was held. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202509/image_870x_68d31c8eb4c9a.webp" alt=""></p>
<p data-start="1532" data-end="1868"><strong data-start="1532" data-end="1575">Nation-State and Criminal Organizations Connection</strong><br data-start="1575" data-end="1578">US officials announced that the judicial investigation continued and the first findings pointed to the connection between nation-state-backed threat actors and organized crime groups. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202509/image_870x_68d31c9026abe.webp" alt=""></p>
<p data-start="1870" data-end="2144"><strong data-start="1870" data-end="1901">The perpetrator remains uncertainty</strong><br data-start="1901" data-end="1904">Although Russia, China and Israel were mentioned in some circles after the operation, US officials did not officially point out any country. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202509/image_870x_68d31c916f982.webp" alt=""></p>
<p data-start="2146" data-end="2376"><strong data-start="2146" data-end="2180">Multi -layer measures of the USA</strong><br data-start="2180" data-end="2183">In addition to the Secret Service, the FBI, the Ministry of Internal Security (DHS) and the New York police reportedly participated in the operation. </p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202509/image_870x_68d31c92787fb.webp" alt=""></p>
<p data-start="2378" data-end="2673"><strong data-start="2378" data-end="2408">Forensic Investigation Continues</strong><br data-start="2408" data-end="2411">Investigations on the seized devices will reveal which country or organizations are connected to the system and the dimension of the planned attacks. </p>
<p data-start="2675" data-end="2926"><strong data-start="2675" data-end="2687"></strong></p><br><p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>AppCloud debate is growing on Samsung Galaxy phones, the critical zero&#45;day deficit CV&#45;2025&#45;21043 with security concerns doubled</title>
<link>https://pursaklargundem.com/appcloud-debate-is-growing-on-samsung-galaxy-phones-the-critical-zero-day-deficit-cv-2025-21043-with-security-concerns-doubled</link>
<guid>https://pursaklargundem.com/appcloud-debate-is-growing-on-samsung-galaxy-phones-the-critical-zero-day-deficit-cv-2025-21043-with-security-concerns-doubled</guid>
<description><![CDATA[ The Lebanese-based SMEX claimed that the pre-impact application called “Appcloud ında on the Galaxy A and M series devices sold in Samsung&#039;s Mena market could lead to confidentiality violations.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68cf27f503d00.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 21 Sep 2025 01:21:53 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is AppCloud and why is it discussed, Samsung uses this application in which markets, CV-2025-21043 deficit which risks, what to do to protect their devices</media:keywords>
<content:encoded><![CDATA[<p data-start="600" data-end="984"><strong data-start="600" data-end="631">Appcloud allegations from SMEX</strong><br data-start="631" data-end="634">The Lebanese-based digital rights organization SMEX suggested that the “Appcloud” component came in front-of-the-side and difficult to remove on the Galaxy A and M series phones sold by Samsung especially in the West Asia and North Africa (MENA) market. </p>
<p data-start="986" data-end="1285">Appcloud draws attention with the cooperation of Ironsource with Samsung in the Mena market within the scope of the “Aura” ecosystem (Israel -based company unity in 2022). </p>
<p data-start="1287" data-end="1637"><strong data-start="1287" data-end="1317">Samsung's response is uncertain</strong><br data-start="1317" data-end="1320">Although Samsung's general privacy policies are open to the public, there is no direct and technical explanation for SMEX's claims. </p>
<p data-start="1639" data-end="2054"><strong data-start="1639" data-end="1682">Critical Open on Galaxy Devices</strong><br data-start="1682" data-end="1685">While the discussions continued, Samsung announced that it has closed the zero-day deficit with CV-2025-21043 coded with the September 2025 security update. </p>
<p data-start="2056" data-end="2421"><strong data-start="2056" data-end="2111">The NSO Group decision increases public sensitivity</strong><br data-start="2111" data-end="2114">In the US case in May 2025, NSO Group was sentenced to 168 million dollars compensation for activities targeting WhatsApp users. </p>
<p data-start="2423" data-end="2865"><strong data-start="2423" data-end="2453">Recommendations for users</strong><br data-start="2453" data-end="2456">Experts suggest Samsung users to upgrade their devices to the most up-to-date software and control front-high applications such as Appcloud. </p>
<p data-start="2867" data-end="3075"><strong data-start="2867" data-end="2879"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>USA, Lockergoga, Megacortex and Nefim ransom Software Manager Ukrainian Hacker accused Hacker</title>
<link>https://pursaklargundem.com/usa-lockergoga-megacortex-and-nefim-ransom-software-manager-ukrainian-hacker-accused-hacker</link>
<guid>https://pursaklargundem.com/usa-lockergoga-megacortex-and-nefim-ransom-software-manager-ukrainian-hacker-accused-hacker</guid>
<description><![CDATA[ The US Department of Justice blamed the Ukrainian citizen Volodymyr Viktorovich Tymoshchuk, who managed the ransom software operations that caused millions of dollars of damage to hundreds of companies.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68c311f813831.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 11 Sep 2025 21:32:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Tymoshchuk managed which ransom software operations, in which period, which companies were affected, how he earned income in the nephew operation, the United States directed the accusations and how much award he announced</media:keywords>
<content:encoded><![CDATA[<p><br data-start="436" data-end="439">The US Department of Justice accused the Ukrainian citizen Volodymyr Viktorovich Tymoshchuk (Nicknames: Deadforz, Boba, Msfv, Farnetwork) of Lockergoga, Megacortex and Nefilim ransom software operations.</p>
<p></p>
<p data-start="660" data-end="967">According to the prosecution certificates, Tymoshchuk, between July 2019 and June 2020 more than 250 US companies and many victims around the world infiltrated the network of Lockergoga and Megacortex attacks. </p>
<p data-start="969" data-end="1254">It is claimed that Tymoshchuk, who was said to have managed the ransom software operation from July 2020 to October 2021, provided access to his partners and received 20 %of the ransom income. </p>
<p data-start="1256" data-end="1495">In November 2023, the Cyber ​​Security Company Group-CIP reported Tymoshchuk with other ransom software groups such as JSworm, Karma, Nokoyawa and Nemty and showed that it played a role in the supply of elements in Russian forums.</p>
<p data-start="1497" data-end="1812">“Tymoshchuk is a series of ransom software criminals targeting major American companies, health institutions and international industrial organizations, T </p>
<p data-start="1814" data-end="1995">In September 2022, free password solvents were released for Lockergoga and Megacortex with international cooperation, and the victims were allowed to save their data without paying ransom.</p>
<p data-start="1997" data-end="2323">Tymoshchuk; bilgisayar dolandırıcılığı için iki komplo, korunan bilgisayarlara zarar vermek için üç suçlama, yetkisiz erişim ve gizli bilgileri ifşa etme tehdidiyle yargılanacak. ABD Dışişleri Bakanlığı, Tymoshchuk veya suç ortaklarının yakalanmasına yönelik bilgi sağlayanlara <strong data-start="2275" data-end="2306">Rewards up to 11 million dollars</strong> teklif ediyor.</p>
<p data-start="2325" data-end="2543"><strong data-start="2325" data-end="2337"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Adobe, Magento e&#45;commerce platform critical &amp;quot;Sessionreaper&amp;quot; joined the vulnerability</title>
<link>https://pursaklargundem.com/adobe-magento-e-commerce-platform-critical-sessionreaper-joined-the-vulnerability</link>
<guid>https://pursaklargundem.com/adobe-magento-e-commerce-platform-critical-sessionreaper-joined-the-vulnerability</guid>
<description><![CDATA[ Adobe, Magento and Commerce platforms seized session data by seizing the CV-2025-54236, which made it possible to control customer accounts.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68c311fdcb3df.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 11 Sep 2025 21:31:53 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How the Sessionreper is running, which Magento versions were affected, Adobe activated measures, store managers urgently need to take steps</media:keywords>
<content:encoded><![CDATA[<p><br data-start="418" data-end="421">Adobe has released an emergency update for a critical vulnerability on e-commerce solutions Commerce and Magento Open Source platforms. </p>
<p></p>
<p data-start="745" data-end="1023">According to Sansec, a cyber security company, Adobe informed its selected customers about the security vulnerability on September 4 and announced that it would publish a patch on 9 September. </p>
<p data-start="1025" data-end="1274">Adobe announced that there is no finding on the security bulletin so far. </p>
<p data-start="1276" data-end="1485">Researchers stressed that the deficit is especially effective in store installations where the session data is stored in the file system. </p>
<p data-start="1487" data-end="1814"><strong data-start="1487" data-end="1517">Update advice now</strong><br data-start="1517" data-end="1520">Adobe released the patch directly as a downloadable package and advised the managers to test and disperse without wasting time. </p>
<p data-start="1816" data-end="2048">Sansec, SessionReaper açığının yakın geçmişteki <strong data-start="1864" data-end="1879">Cosmicssting</strong>, <strong data-start="1881" data-end="1896">Trojanorder</strong>, <strong data-start="1898" data-end="1916">Ambionics Sqli</strong> ve <strong data-start="1920" data-end="1932">Shoplift</strong> vakalarıyla aynı ciddiyet seviyesinde olduğunu ve otomasyon yoluyla kitlesel istismara uygun olduğunu belirtiyor.</p>
<p data-start="2050" data-end="2189">Researchers did not share the technical details of the deficit, but the attack was watching a similar model with last year's Cosmicssting.</p>
<p data-start="2191" data-end="2388"><strong data-start="2191" data-end="2203"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Anti&#45;SPAM error in Microsoft: Exchange Online and Teams users could not access secure links</title>
<link>https://pursaklargundem.com/anti-spam-error-in-microsoft-exchange-online-and-teams-users-could-not-access-secure-links</link>
<guid>https://pursaklargundem.com/anti-spam-error-in-microsoft-exchange-online-and-teams-users-could-not-access-secure-links</guid>
<description><![CDATA[ Microsoft has been dealing with the Anti-SPAM engine error that has been affecting Exchange Online and Teams users since September 5th.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68c31201cb491.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 11 Sep 2025 21:30:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How the anti-SPAM error in Microsoft appeared, how many URL was affected by this situation, the company has applied temporary solutions, similar problems have been experienced before</media:keywords>
<content:encoded><![CDATA[<p><br data-start="504" data-end="507">Microsoft has announced that it is facing an anti-SPAM error that prevents connection access in Exchange Online and Microsoft Teams services. </p>
<p></p>
<p data-start="777" data-end="1030">Due to the error, users could not access the confirmed connections to be safe, while some e-mails have been quarantined. </p>
<p data-start="1032" data-end="1282">According to Microsoft's statement, more than 6,000 URL has been affected. </p>
<p data-start="1284" data-end="1637"><strong data-start="1284" data-end="1309">Partial solution was applied</strong><br data-start="1309" data-end="1312">Microsoft engineers have released a correction that allows synchronizing no longer quarantine. </p>
<p data-start="1639" data-end="1870">The company reported that the problem has been eliminated to a great extent, but that the work continues to eliminate the remaining effects until the root cause analysis was completed. </p>
<p data-start="1872" data-end="2239"><strong data-start="1872" data-end="1912">Similar problems have happened before</strong><br data-start="1912" data-end="1915">In 2025, Microsoft has faced similar errors in Exchange online service. </p>
<p data-start="2241" data-end="2434"><strong data-start="2241" data-end="2253"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>SAP closed the critical command running deficit in Netweaver: CVSS 10/10 level of security was resolved</title>
<link>https://pursaklargundem.com/sap-closed-the-critical-command-running-deficit-in-netweaver-cvss-1010-level-of-security-was-resolved</link>
<guid>https://pursaklargundem.com/sap-closed-the-critical-command-running-deficit-in-netweaver-cvss-1010-level-of-security-was-resolved</guid>
<description><![CDATA[ SAP corrected 21 new weaknesses in the September security bulletin.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68c31205bbe7d.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 11 Sep 2025 21:29:54 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>SAP Netweaver CV-2025-42944 How to run the vulnerability, which other critical deficits have been removed with September 2025 updates, the high-risk weaknesses in SAP products are attractive for the attackers, the system managers should be applied urgently</media:keywords>
<content:encoded><![CDATA[<p><br data-start="461" data-end="464">Kurumsal yazılım üreticisi SAP, Eylül 2025 güvenlik güncellemeleri kapsamında ürünlerinde tespit edilen 21 güvenlik açığını giderdi. En dikkat çekici sorun, <strong data-start="621" data-end="656">Netweaver RMIP4 Servercore 7.50</strong> sürümünde keşfedilen ve <strong data-start="681" data-end="695">CVSS 10/10</strong> puanıyla maksimum şiddette değerlendirilen <strong data-start="739" data-end="757">CV-2025-42944</strong> oldu.</p>
<p></p>
<p data-start="767" data-end="1195">Bu zafiyet, <strong data-start="779" data-end="807">Insecure Deserialization</strong> (güvensiz serileştirme) sorunundan kaynaklanıyor. Kimliği doğrulanmamış bir saldırgan, RMI-P4 protokolü üzerinden kötü amaçlı Java nesneleri göndererek hedef sistemde keyfi komut çalıştırabiliyor. RMI-P4, NetWeaver AS Java bileşenlerinde SAP içi iletişim ve yönetim için kullanılıyor. Yanlış yapılandırmalar nedeniyle bu portun internetten erişilebilir durumda olması, riski artırıyor.</p>
<p data-start="1197" data-end="1224"><strong data-start="1197" data-end="1222">Other critical explanations:</strong></p>
<ul data-start="1225" data-end="1652">
<li data-start="1225" data-end="1453">
<p data-start="1227" data-end="1453"><strong data-start="1227" data-end="1257">CV-2025-42922 (CVSS 9.9):</strong> NetWeaver AS Java (Deploy Web Service) bileşeninde hatalı dosya işlemleri. Kimliği doğrulanmış düşük yetkili saldırgan, zararlı dosyalar yükleyerek tam sistem ele geçirme riski oluşturabiliyor.</p>
</li>
<li data-start="1454" data-end="1652">
<p data-start="1456" data-end="1652"><strong data-start="1456" data-end="1486">CV-2025-42958 (CVSS 9.1):</strong> Kimlik doğrulama eksikliğinden kaynaklanan açık, yetkisiz yüksek ayrıcalıklı kullanıcıların hassas verileri okumasına, değiştirmesine veya silmesine imkân tanıyor.</p>
</li>
</ul>
<p data-start="1654" data-end="1720">SAP would also eliminate the following deficits that were highly evaluated:</p>
<ul data-start="1721" data-end="2045">
<li data-start="1721" data-end="1806">
<p data-start="1723" data-end="1806"><strong data-start="1723" data-end="1765">CV-2025-42933 (SAP Business One Sld):</strong> Hassas verilerin güvensiz depolanması.</p>
</li>
<li data-start="1807" data-end="1931">
<p data-start="1809" data-end="1931"><strong data-start="1809" data-end="1853">CV-2025-42929 (SLT Replication Server):</strong> Eksik girdi doğrulama nedeniyle replike edilen verilerin manipüle edilmesi.</p>
</li>
<li data-start="1932" data-end="2045">
<p data-start="1934" data-end="2045"><strong data-start="1934" data-end="1963">CV-2025-42916 (S/4hana):</strong> Temel bileşenlerde eksik girdi doğrulama ile yetkisiz veri manipülasyonu riski.</p>
</li>
</ul>
<p data-start="2047" data-end="2379">SAP ürünleri, kritik iş süreçlerinde kullanıldıkları ve yüksek değerli veriler barındırdıkları için siber tehdit aktörlerinin sıkça hedefinde bulunuyor. Nitekim bu ayın başında, <strong data-start="2225" data-end="2263">S/4Hana, Business One and Netweaver</strong> ürünlerini etkileyen <strong data-start="2285" data-end="2303">CV-2025-42957</strong> kod enjeksiyonu açığının aktif şekilde istismar edildiği ortaya çıkmıştı.</p>
<p data-start="2381" data-end="2529"><strong data-start="2381" data-end="2406">To system managers</strong>, CV-2025-42944, CV-2025-42922 and CV-2025-42958 are recommended to apply the patches as soon as possible.</p>
<p data-start="2531" data-end="2809"><strong data-start="2531" data-end="2543"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Plex called on users to reset their passwords after data violation</title>
<link>https://pursaklargundem.com/plex-called-on-users-to-reset-their-passwords-after-data-violation</link>
<guid>https://pursaklargundem.com/plex-called-on-users-to-reset-their-passwords-after-data-violation</guid>
<description><![CDATA[ Media Broadcasting Platform Plex announced that e-mail addresses, user names and hashly passwords have been leaked as a result of unauthorized access to a database.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68c313005afa9.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 11 Sep 2025 21:26:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Which user information was leaked in the Plex data violation, which measures are proposed for the safety of passwords, what did the company have done to limit the effects of the attack, did Plex experience a similar data violation in the past</media:keywords>
<content:encoded><![CDATA[<p><br data-start="438" data-end="441">Plex released a security warning after a new cyber attack affecting user data. </p>
<p></p>
<p data-start="660" data-end="1065">Veri ihlali bildirimine göre saldırganlar, <strong data-start="703" data-end="795">e-mail addresses, user names, authentication information and hashtily passwords</strong> erişti. Plex, parolaların en iyi güvenlik uygulamalarına uygun şekilde hashlenmiş olduğunu ve üçüncü taraflarca doğrudan okunamayacağını belirtti. Ancak kullanılan algoritma paylaşılmadığı için saldırganların bu hashleri kırmayı deneyebileceği ihtimali gündeme geldi.</p>
<p data-start="1067" data-end="1425">Kullanıcılara, <strong data-start="1082" data-end="1099">plex.tv/reset</strong> adresinden parolalarını sıfırlamaları ve “Parola değişikliğinden sonra bağlı cihazlardan çıkış yap” seçeneğini işaretlemeleri önerildi. Bu adım, mevcut oturumları kapatarak hesapların kötüye kullanılmasını önleyecek. SSO kullananların ise <strong data-start="1339" data-end="1359">plex.tv/security</strong> üzerinden tüm cihazlardan çıkış yapmaları gerektiği bildirildi.</p>
<p data-start="1427" data-end="1634">Plex ayrıca kullanıcılara ek güvenlik için <strong data-start="1470" data-end="1509">Authority with two factors (2FA)</strong> etkinleştirmelerini hatırlattı ve hiçbir zaman e-posta yoluyla parola veya kredi kartı bilgisi talep etmediğini vurguladı.</p>
<p data-start="1636" data-end="1862">While the company did not share technical details about how the attack took place, the method that caused a violation was removed. </p>
<p data-start="1864" data-end="2056">This is not the first time Plex users had to reset their passwords. </p>
<p data-start="2058" data-end="2290"><strong data-start="2058" data-end="2070"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>DDOS Protection Provider in Europe was targeted with an attack at 1.5 billion packages/seconds</title>
<link>https://pursaklargundem.com/ddos-protection-provider-in-europe-was-targeted-with-an-attack-at-15-billion-packagesseconds</link>
<guid>https://pursaklargundem.com/ddos-protection-provider-in-europe-was-targeted-with-an-attack-at-15-billion-packagesseconds</guid>
<description><![CDATA[ A DDOS reduction service provider in Europe has been subjected to a huge service blocking attack that reached 1.5 billion packages per second.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68c3117e0b917.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 11 Sep 2025 21:20:53 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>DDOS attack was carried out by which methods, how many packages/seconds of the attack, how the fastnetmon intervened in the attack, which measures are recommended at ISP level</media:keywords>
<content:encoded><![CDATA[<p><br data-start="408" data-end="411">A DDOS reduction provider operating in Europe has been targeted with one of the largest package -based attacks on the public so far. </p>
<p></p>
<p data-start="638" data-end="1049">The attack was carried out through IoT devices and microtic routers seized from more than 11 thousand different networks worldwide. </p>
<p data-start="1051" data-end="1282">While the name of the targeted customer was not announced, it was stated that the institution in question was a “DDOS Scrubing” provider using methods such as package control, speed limitation, captcha and anomaly detection to filter DDOS traffic.</p>
<p data-start="1284" data-end="1605">The incident took place after Cloudflare announced that it had stopped the world's largest DDOS attack at 11.5 TBPS bandwidth and 5.1 billion packets/seconds. </p>
<p data-start="1607" data-end="2076">Fastnetmon Founder Pavel Odintsov stressed that the remarkable aspect of the attack is the abuse of daily network devices in large -scale attacks. </p>
<p data-start="2078" data-end="2271"><strong data-start="2078" data-end="2090"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>Akira ransom software, Sonicwall SSLVPN re &#45;targeting the security vulnerability leaks to the networks</title>
<link>https://pursaklargundem.com/akira-ransom-software-sonicwall-sslvpn-re-targeting-the-security-vulnerability-leaks-to-the-networks</link>
<guid>https://pursaklargundem.com/akira-ransom-software-sonicwall-sslvpn-re-targeting-the-security-vulnerability-leaks-to-the-networks</guid>
<description><![CDATA[ The Akira ransom software group exploits the critical CV-2024-40766 vulnerability discovered last year on Sonicwall devices and released.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202509/image_870x580_68c311488933f.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 11 Sep 2025 21:16:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Akira ransom software targeting Sonicwall devices, CV-2024-40766 which versions affect, which security measures should be taken against attacks, Sonicwall&#039;s latest security warning is the advice.</media:keywords>
<content:encoded><![CDATA[<p><br data-start="412" data-end="415">Akira ransom software group has started to use the CV-2024-40766 vulnerability in Sonicwall SSLVPN products. </p>
<p></p>
<p data-start="687" data-end="1177">Sonicwall released an update in August 2024 for the security vulnerability and announced that weakness was actively exploited. </p>
<p data-start="1179" data-end="1466">Australian Cyber ​​Security Center (ACSC), the warning issued on September 10, announced that the institutions in the country were targeted by Akira. </p>
<p data-start="1468" data-end="1723">The attacks were found to be connected to VPN via Sonicwall devices via “Default Users Group ve and the assumed general access permits for the“ Virtual Office Portal ”. </p>
<p data-start="1725" data-end="2035">In the Cyber ​​Security Community, allegations that the attacks were due to a new “zero day” deficit had come up. </p>
<p data-start="2037" data-end="2187">The company reported that it examined about 40 incidents in connection with this security vulnerability last month. </p>
<ul data-start="2189" data-end="2366">
<li data-start="2189" data-end="2243">
<p data-start="2191" data-end="2243"><strong data-start="2191" data-end="2201">Gen 5:</strong> SOHO cihazları (5.9.2.14-12o ve öncesi)</p>
</li>
<li data-start="2244" data-end="2308">
<p data-start="2246" data-end="2308"><strong data-start="2246" data-end="2256">Gen 6:</strong> TZ, NSA ve SM modelleri (6.5.4.14-109n ve öncesi)</p>
</li>
<li data-start="2309" data-end="2366">
<p data-start="2311" data-end="2366"><strong data-start="2311" data-end="2321">Gen 7:</strong> TZ ve NSA modelleri (7.0.1-5035 ve öncesi)</p>
</li>
</ul>
<p data-start="2368" data-end="2750">System managers are advised to follow the recommended steps in Sonicwall's security bulletin. </p>
<p data-start="2752" data-end="2993"><strong data-start="2752" data-end="2764"></strong></p>
<p></p>
<p><b>Kaynak: Beykozun Sesi</b></p>]]> </content:encoded>
</item>

<item>
<title>The new Shamos pest spreading with fake Mac repairs targets user information</title>
<link>https://pursaklargundem.com/the-new-shamos-pest-spreading-with-fake-mac-repairs-targets-user-information</link>
<guid>https://pursaklargundem.com/the-new-shamos-pest-spreading-with-fake-mac-repairs-targets-user-information</guid>
<description><![CDATA[ CrowdStrike researchers, Atomic MacOS Stealer (AMOS), a new variant of Shamos pest, deceived Mac users with Clickfix attacks, codes, crypto wallets, Apple Notes and Keychain data announced.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202508/image_870x580_68aea83d40e25.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 Aug 2025 11:12:59 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How to distribute Shamos pest, which data from user devices, click why the clickfix attacks are effective, which steps to take Mac users from this threat</media:keywords>
<content:encoded><![CDATA[<div>
<p>Mac kullanıcılarını hedef alan yeni bir bilgi hırsızı zararlı yazılım ortaya çıktı. <strong>Shamos</strong> adı verilen zararlı, sahte hata düzeltme kılavuzları ve yazılım yüklemeleri üzerinden dağıtılıyor.</p>
<p>Spread with Clickfix attacks</p>
<p>The attackers direct users to run certain commands at the Terminal through fake Github warehouses and harmful ads. </p>
<p>The commands dissolve a connection with Base64 and download BASH betting from a remote server. </p>
<p>Shamos' talents</p>
<ul>
<li>Determining whether it works in a virtual environment with anti-VM controls</li>
<li>Collecting information about the device using applescript</li>
<li>Calling and stealing browser data, keychain items, apple notes content and crypto wallet files</li>
<li>Collect the data in the form of “out.zip” and send it to the attacker via curl</li>
<li>Create a plist file under LaunchDaemons if it is employed by the administrator (Sudo) powers and becoming permanent</li>
<li>Download additional loads such as fake versions of Ledger Live Crypto Wallet Application and botnet modules</li>
</ul>
<p>WARNINGS TO USERS</p>
<p>Experts suggest that commands that are not understood from online sources should not be operated at the Terminal, especially sponsored search results. </p>
<p>Clickfix tactics are becoming widespread</p>
<p>Clickfix attacks threaten not only Mac users, but also many platforms in general. </p>
<p>Kaynak: Beykozun Sesi</p>
</div>]]> </content:encoded>
</item>

<item>
<title>More than 1,200 suspects were caught in the international cyber crime operation in Africa</title>
<link>https://pursaklargundem.com/more-than-1200-suspects-were-caught-in-the-international-cyber-crime-operation-in-africa</link>
<guid>https://pursaklargundem.com/more-than-1200-suspects-were-caught-in-the-international-cyber-crime-operation-in-africa</guid>
<description><![CDATA[ Within the scope of the Operation Serengeti 2.0 under Interpol coordination, 18 African countries and the United Kingdom Security Forces detained 1,209 cyber criminals between June and August 2025.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202508/image_870x580_68aead29378cd.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 Aug 2025 11:11:56 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How many people were caught within the scope of Operation Serengeti 2.0, which type of crime targeted, how much seized amount and collapsed infrastructure, interpol conducted similar operations in the past</media:keywords>
<content:encoded><![CDATA[<div>
<p>Afrika’da siber suç örgütlerine karşı düzenlenen <strong>Operation Serengeti 2.0</strong> isimli geniş çaplı operasyonda 1.200’den fazla kişi tutuklandı. Interpol liderliğinde yürütülen operasyon, Haziran ile Ağustos 2025 arasında gerçekleştirildi.</p>
<p>According to Interpol, during the operation:</p>
<ul>
<li>1,209 suspects were detained</li>
<li>97.4 million dollars illegal income seized</li>
<li>11,432 malicious infrastructure was destroyed</li>
<li>Attacks targeting 87,858 victims worldwide have been blocked</li>
</ul>
<p>Scope of the operation</p>
<p>The fight against cyber crimes was carried out with the participation of 18 African countries and the United Kingdom law enforcement officers. </p>
<p>The action was carried out within the scope of African joint cyber crime operation financed by the United Kingdom Foreign Affairs, Nations Community and Development Office. </p>
<p>Connection with previous operations</p>
<ul>
<li><strong>Operation Red Card (2024–2025):</strong> 306 şüpheli yakalandı, 5.000’den fazla mağdurun etkilendiği saldırılar açığa çıkarıldı.</li>
<li><strong>Operation Serengeti (2024):</strong> 1.006 şüpheli tutuklandı, fidye yazılımı ve çevrimiçi dolandırıcılık çeteleri çökertildi.</li>
<li><strong>Operation Africa Cyber ​​Surge II (2023):</strong> 25 ülkede 14 şüpheli yakalandı, 40 milyon doların üzerinde zarara yol açan saldırılar engellendi.</li>
</ul>
<p>Interpol Genel Sekreteri Valdecy Urquiza, operasyonun ardından yaptığı açıklamada şunları söyledi: <em>“Each operation increases cooperation based on the previous one, strengthens information sharing and improves the capacity of investigation. Our global network produces concrete results in protecting victims more powerful than ever.”</em></p>
<p>Kaynak: Beykozun Sesi</p>
</div>]]> </content:encoded>
</item>

<item>
<title>Davita: 2.7 million people personal and health data were stolen in the ransom software attack</title>
<link>https://pursaklargundem.com/davita-27-million-people-personal-and-health-data-were-stolen-in-the-ransom-software-attack</link>
<guid>https://pursaklargundem.com/davita-27-million-people-personal-and-health-data-were-stolen-in-the-ransom-software-attack</guid>
<description><![CDATA[ Davita, which provides renal dialysis service, announced that almost 2.7 million people have leaked in the ransom software attack in March 2025.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202508/image_870x580_68aeaa4563117.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 Aug 2025 11:09:56 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Davita data violation which information was stolen, when and how the attack took place, how the Interlock ransom Software Group is associated with the event, Davita offers what supports to affected patients</media:keywords>
<content:encoded><![CDATA[<div>
<p>Davita, a US -based kidney dialysis company, confirmed that the sensitive data of approximately 2.7 million people were stolen with the ransom software attack. </p>
<p>Details of the attack</p>
<ul>
<li>The attackers infiltrated Davita's network on 24 March 2025.</li>
<li>The company noticed the incident on 12 April and removed the attackers from their systems.</li>
<li>During this time, the attackers reached the dialysis laboratory database.</li>
</ul>
<p>Among the stolen data:</p>
<ul>
<li>Name, address, date of birth, social security number</li>
<li>Health Insurance Data</li>
<li>Disease, treatment information, laboratory test results</li>
<li>Tax ID numbers and personal check images for some people</li>
</ul>
<p>The US Department of Health's Civil Rights Office (OCR) announced that 2,689,826 people were affected by the incident. </p>
<p>The claim of the Interlock group</p>
<p>Davita does not explain the responsible of the attack, but the Interlock ransom software group undertook the attack at the end of April. </p>
<p>In June, Davita confirmed that some of the leaked files belonged to them. </p>
<p>Davita spokesman, "Unfortunately, we have found that the attacker provides unauthorized access to some patients' personal data. Therefore, we inform existing and old patients and offer free credit monitoring services against identity theft." </p>
<p>About Interlock</p>
<p>The interlocking ransom software group, which emerged in 2024, is especially targeting health institutions. </p>
<p>Kaynak: Beykozun Sesi</p>
</div>]]> </content:encoded>
</item>

<item>
<title>The software developer, who damaged his former employer, was sentenced to 4 years of imprisonment for placing “Kill Switch” on the systems</title>
<link>https://pursaklargundem.com/the-software-developer-who-damaged-his-former-employer-was-sentenced-to-4-years-of-imprisonment-for-placing-kill-switch-on-the-systems</link>
<guid>https://pursaklargundem.com/the-software-developer-who-damaged-his-former-employer-was-sentenced-to-4-years-of-imprisonment-for-placing-kill-switch-on-the-systems</guid>
<description><![CDATA[ Davis Lu, a software developer living in the USA, was found guilty of leaving a “Kill Switch” embedded code and a “Kill Switch”.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202508/image_870x580_68aeaa1dbbd9f.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 Aug 2025 11:07:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How did Davis damage the company&#039;s systems, which effect has created Kill Switch, which evidence was found on the investigation computer, which penalty was sentenced</media:keywords>
<content:encoded><![CDATA[<div>
<p>The US Department of Justice announced that Davis Lu, accused of harming the former employer's systems, was sentenced to four years in prison.</p>
<p>Background of the event</p>
<p>Lu, a 55 -year -old Chinese citizen, served in an Ohio -based company (referred to as Eaton Corporation) from 2007 to 2019. </p>
<p>Harmful codes and "Kill Switch"</p>
<ul>
<li>Java -based infinite cycles and established mechanisms that would cause the servers to collapse.</li>
<li>He designed a Kill Switch, whom he calls “Isdlenabledinad”. </li>
<li>On September 9, 2019, when the account was dismissed and the account was disabled, Kill Switch was activated and became unable to access thousands of employees.</li>
</ul>
<p>Investigation findings</p>
<p>It was found that LU had deleted encrypted files on the laptop that should be returned and made searches on the methods of increasing authorization, process hiding and deleting files.</p>
<p>Matthew R. Galeotti, official of the Ministry of Justice, sabotaged the company's networks, caused great financial losses and violated the trust of the employer. </p>
<p>Details of the punishment</p>
<ul>
<li>Lu was found guilty of deliberately damaging protected computers.</li>
<li>He was sentenced to 4 years in prison.</li>
<li>After the evacuation, he will remain under probation for 3 years.</li>
<li>It was announced that the damage of the company was hundreds of thousands of dollars.</li>
</ul>
<p>Kaynak: Beykozun Sesi</p>
</div>]]> </content:encoded>
</item>

<item>
<title>Colt confirmed that the customer data was stolen in the Warlock ransom Software attack: Documents are on sale in dark network</title>
<link>https://pursaklargundem.com/colt-confirmed-that-the-customer-data-was-stolen-in-the-warlock-ransom-software-attack-documents-are-on-sale-in-dark-network</link>
<guid>https://pursaklargundem.com/colt-confirmed-that-the-customer-data-was-stolen-in-the-warlock-ransom-software-attack-documents-are-on-sale-in-dark-network</guid>
<description><![CDATA[ The UK -based Telekom Company Colt Technology Services announced that customer certificates were stolen in the attack on August 12th and that it was put on sale in the dark network.  ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202508/image_870x580_68aea9ef5a74e.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 Aug 2025 11:05:52 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Which data was stolen in the Colt attack, how Warlock Group was put on sale, what is the history of the ransom software group, how can customers be affected by this data violation</media:keywords>
<content:encoded><![CDATA[<div>
<p>Colt Technology Services, a UK -based telecommunications and network services provider, confirmed that customer certificates were stolen for the first time after the recent cyber attack. </p>
<p>COLT's updated security announcement, "A criminal group has accessed some files from our systems. These files may have information about our customers. Document headings have been published in the dark network." </p>
<p>Warlock's claim</p>
<p>The Warlock ransom Software Group (Storm-2603), which is considered to be China-linked, put up 1 million documents on the Cyber ​​Crime Forum on the RAM for $ 200,000. </p>
<p>According to BleepingComputer's verification, Tox ID, which is included in the forum announcement, matches the identities used in Warlock's previous ransom notes.</p>
<p>About the Warlock Group</p>
<ul>
<li>He appeared in March 2025 and initially demanded ransom using Lockbit leak notes.</li>
<li>In June, he announced his own brand under the name “Warlock Group ve and established special dark network sites.</li>
<li>Previously, Babuk VMware Esxi made attacks using passwords and Lockbit leaks.</li>
<li>In July, Microsoft announced that the group used SharePoint vulnerability to infiltrate corporate networks.</li>
<li>Warlock's ransom demands vary from $ 450,000 to several million dollars.</li>
</ul>
<p>Risk for customers</p>
<p>Although the details of the alleged documents are not explained, the financial and institutional information of Colt customers has a risk of third parties. </p>
<p>Kaynak: Beykozun Sesi</p>
</div>]]> </content:encoded>
</item>

<item>
<title>Cyber Attack on the Turkish Medical Association: 107 thousand people&amp;apos;s data are at risk</title>
<link>https://pursaklargundem.com/cyber-attack-on-the-turkish-medical-association-107-thousand-peoples-data-are-at-risk</link>
<guid>https://pursaklargundem.com/cyber-attack-on-the-turkish-medical-association-107-thousand-peoples-data-are-at-risk</guid>
<description><![CDATA[ The Turkish Medical Association announced that the personal data of employees, users and members registered in medical chambers as a result of a cyber attack on August 8, 2025 announced that the personal data were affected.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a647ca2f472.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 Aug 2025 01:15:47 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How the Turkish Medical Association Data Violation took place, which data were seized in a cyber attack, how many people&#039;s information is at risk, KVKK made a decision about this incident</media:keywords>
<content:encoded><![CDATA[<p><br data-start="521" data-end="524">The Turkish Medical Association (TTB) announced on August 8, 2025 that cyber attacks on its systems. </p>
<p></p>
<p data-start="732" data-end="954">As a result of the data violation, the registered files in the TTB system were accessed and these files were deleted. </p>
<p data-start="956" data-end="1252"><strong data-start="956" data-end="983">Which data were affected</strong><br data-start="983" data-end="986">In a statement, identity, communication, location, legal transaction and transaction safety data were affected by the attack said. </p>
<p data-start="1254" data-end="1491"><strong data-start="1254" data-end="1269">KVKK decision</strong><br data-start="1269" data-end="1272">The Personal Data Protection Board (KVKK) decided to announce the data violation on the website of the institution with the decision of 2025/1514 dated 14 August 2025 and numbered 2025/1514. </p>
<p data-start="1493" data-end="1688"><strong data-start="1493" data-end="1505"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>20 months imprisonment for the claim that he hacked more than 3,000 sites in the UK</title>
<link>https://pursaklargundem.com/20-months-imprisonment-for-the-claim-that-he-hacked-more-than-3000-sites-in-the-uk</link>
<guid>https://pursaklargundem.com/20-months-imprisonment-for-the-claim-that-he-hacked-more-than-3000-sites-in-the-uk</guid>
<description><![CDATA[ 26-year-old Al-Tahery Al-Mathriky, who lives in the city of Rotherham, was sentenced to 20 months of imprisonment by accepting the accusations that he had hacked numerous websites, including government sites and news organizations, stole the data of millions of Facebook users and obtained identity information from various platforms. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a59b9fa4712.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 13:36:53 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords></media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="459" data-end="638">In the UK, 26-year-old Al-Tahery Al-Masshriky received 20 months' imprisonment, accepting the accusations that he attacked thousands of websites and stole information of millions of people.</p>
<p data-start="640" data-end="1024"><strong data-start="640" data-end="665">The history of the investigation</strong><br data-start="665" data-end="668">Mashriky was arrested in 2022 in England in line with the information from the US law enforcement officers. </p>
<p data-start="1026" data-end="1425"><strong data-start="1026" data-end="1051">Targeted institutions</strong><br data-start="1051" data-end="1054">Adli incelemeler, Yemen Dışişleri Bakanlığı ve Yemen Güvenlik Medya Bakanlığı’nın sitelerine sızıldığını ve bu sitelerde kullanıcı adı tarama araçları yerleştirildiğini ortaya koydu. Ayrıca İsrail’deki <em data-start="1256" data-end="1267">Live News</em> sitesinin yönetici sayfalarına erişildi ve tüm içerik indirildi. ABD ve Kanada’daki dini kuruluşlar ile Kaliforniya Su Kurulu da hedefler arasında bulundu.</p>
<p data-start="1427" data-end="1686"><strong data-start="1427" data-end="1446">Stolen Data</strong><br data-start="1446" data-end="1449">Mashriky'nin more than 4 million facebook users data, as well as netflix and Paypal stolen user information for services such as. </p>
<p data-start="1688" data-end="2035"><strong data-start="1688" data-end="1720">National Crime Agency statement</strong><br data-start="1720" data-end="1723">British National Crime Agency (NCA) Cyber Crime Unit President Paul Foster said that Mashriky's attacks have created a great deal of deduction, “These attacks were made only to spread political and ideological messages. In addition, millions of people have seized personal data that would allow them to defraud.”</p>
<p data-start="2037" data-end="2240"><strong data-start="2037" data-end="2049"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>More than 800 N&#45;Eval N&#45;Central server was not patched against critical security deficits, but actively abused</title>
<link>https://pursaklargundem.com/more-than-800-n-eval-n-central-server-was-not-patched-against-critical-security-deficits-but-actively-abused</link>
<guid>https://pursaklargundem.com/more-than-800-n-eval-n-central-server-was-not-patched-against-critical-security-deficits-but-actively-abused</guid>
<description><![CDATA[ It has been confirmed that two critical vulnerabilities in N-Eval N-Central software used by managed service providers and IT teams were actively exploited.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a59bac12e2a.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 13:34:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords></media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="509" data-end="865">The two critical vulnerabilities discovered in the popular network management platform N-Eval N-Central put hundreds of servers around the world at risk. </p>
<p data-start="867" data-end="1165"><strong data-start="867" data-end="888">The seriousness of the situation</strong><br data-start="888" data-end="891">N-Eval announced that the gaps were patched and closed with 2025.3.1 version. </p>
<p data-start="1167" data-end="1345">N-Eval said in a statement that security violations were observed only in a limited number of internal environments and that the abuse was not detected in their own cloud environments.</p>
<p data-start="1347" data-end="1666"><strong data-start="1347" data-end="1375">Mandatory Instruction from CISA</strong><br data-start="1375" data-end="1378">The US Cyber Safety and Infrastructure Safety Agency (CISA) added to the list of ılmış known security deficits ”list. </p>
<p data-start="1668" data-end="1965">Although CISA does not directly obliges the private sector organizations, all network executives called N-Erse to apply the patches published by N-Erse, otherwise the product to disable the product. </p>
<p data-start="1967" data-end="2205"><strong data-start="1967" data-end="1979"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>HR Giant Workday confirmed the data violation of the Salesforce &#45;based social engineering attack.</title>
<link>https://pursaklargundem.com/hr-giant-workday-confirmed-the-data-violation-of-the-salesforce-based-social-engineering-attack</link>
<guid>https://pursaklargundem.com/hr-giant-workday-confirmed-the-data-violation-of-the-salesforce-based-social-engineering-attack</guid>
<description><![CDATA[ Workday, a Human Resources Software Company, which serves more than 11,000 institutions worldwide, announced that it has undergone data violations through the third -party CRM system as a result of a social engineering attack.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a59bb900035.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 13:34:00 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords></media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="498" data-end="813">Workday, headquartered in the US state of California, announced that a social engineering attack on a third -party customer relations management (CRM) platform has been experienced in a social engineering attack. </p>
<p data-start="815" data-end="1207"><strong data-start="815" data-end="841">Details of the attack</strong><br data-start="841" data-end="844">According to Workday's announcement on August 16, the attackers provided access to the CRM platform with social engineering methods targeting company employees. </p>
<p data-start="1209" data-end="1374">It was reported that the incident was identified on August 6 and that the attackers tried to collect information through messages and telephones by introducing themselves as HR or IT employees.</p>
<p data-start="1376" data-end="1784"><strong data-start="1376" data-end="1403">Shinyhunters connection</strong><br data-start="1403" data-end="1406">The incident is part of the wave of global attacks associated with the Shinyhunters group. </p>
<p data-start="1786" data-end="1965">The stolen data are used to ask for ransom from victims via e-mail. </p>
<p data-start="1967" data-end="2156"><strong data-start="1967" data-end="1979"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Fortiweb allows full authority to overcome the full authority, the researcher is preparing to publish the abuse code</title>
<link>https://pursaklargundem.com/fortiweb-allows-full-authority-to-overcome-the-full-authority-the-researcher-is-preparing-to-publish-the-abuse-code</link>
<guid>https://pursaklargundem.com/fortiweb-allows-full-authority-to-overcome-the-full-authority-the-researcher-is-preparing-to-publish-the-abuse-code</guid>
<description><![CDATA[ Fortinet’s web application firewall, Fortiweb, discovered and followed as CV-2025-52970, allows the attackers to completely overcome authentication.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a59bd2760cd.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 13:33:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords></media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="487" data-end="731">A critical vulnerability in Fortinet's Fortweb product allows attackers to imitate any user, even managers. </p>
<p data-start="733" data-end="1128"><strong data-start="733" data-end="762">Technical details of the deficit</strong><br data-start="762" data-end="765">Araştırmacı Aviv Y tarafından “FortMajeure” adı verilen açık, FortiWeb’in çerez ayrıştırmasındaki “out-of-bounds read” hatasından kaynaklanıyor. Saldırgan, <em data-start="921" data-end="926">Era</em> parametresine beklenmedik bir değer atayarak sunucunun tüm sıfırlardan oluşan gizli anahtarı kullanmasına neden oluyor. Bu durum, sahte kimlik doğrulama çerezlerinin kolayca oluşturulmasını sağlıyor.</p>
<p data-start="1130" data-end="1423">In order to exploit the vulnerability, the target user must have actively sign. </p>
<p data-start="1425" data-end="1559"><strong data-start="1425" data-end="1458">Affected versions and patches</strong><br data-start="1458" data-end="1461">Open affects Fortiweb's versions between 7.0 and 7.6. </p>
<ul data-start="1561" data-end="1674">
<li data-start="1561" data-end="1588">
<p data-start="1563" data-end="1588">Fortiweb 7.6.4 and Over</p>
</li>
<li data-start="1589" data-end="1616">
<p data-start="1591" data-end="1616">FORTİWEB 7.4.8 and above</p>
</li>
<li data-start="1617" data-end="1645">
<p data-start="1619" data-end="1645">FORTİWEB 7.2.11 and above</p>
</li>
<li data-start="1646" data-end="1674">
<p data-start="1648" data-end="1674">FORTİWEB 7.0.11 and above</p>
</li>
</ul>
<p data-start="1676" data-end="1812">Fortweb 8.0 versions are not affected by this open. </p>
<p data-start="1814" data-end="2099"><strong data-start="1814" data-end="1839">Researcher's decision</strong><br data-start="1839" data-end="1842">Aviv Y shared a POC showing the foundation of the deficit, but did not publish the entire chain of abuse except for the executive imitation over Rest Endpoint. </p>
<p data-start="2101" data-end="2372">According to the researcher, even missing details do not allow even knowledgeable attackers to develop a complete abuse alone. </p>
<p data-start="2374" data-end="2562"><strong data-start="2374" data-end="2386"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>The Colt Telecom attack was the Warlock ransom Software Group, the stolen data were put on sale</title>
<link>https://pursaklargundem.com/the-colt-telecom-attack-was-the-warlock-ransom-software-group-the-stolen-data-were-put-on-sale</link>
<guid>https://pursaklargundem.com/the-colt-telecom-attack-was-the-warlock-ransom-software-group-the-stolen-data-were-put-on-sale</guid>
<description><![CDATA[ The UK -based Colt Technology Services has been interrupting some services in some services including COLT Online and Voice API due to cyber attack on August 12th.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a59bdf0723e.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 13:32:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords></media:keywords>
<content:encoded><![CDATA[<p data-start="455" data-end="699">The UK -based telecommunication company Colt Technology Services is trying to eliminate the effects of a cyber attack that started on August 12th. </p>
<p data-start="701" data-end="1079"><strong data-start="701" data-end="724">Deduction in services</strong><br data-start="724" data-end="727">According to Colt's statement; </p>
<p data-start="1081" data-end="1498"><strong data-start="1081" data-end="1103">Warlock's claim</strong><br data-start="1103" data-end="1106">A threat actor called ‘CNKJASDFGD’ was attacking on behalf of the Warlock ransom Group. </p>
<p data-start="1500" data-end="1844"><strong data-start="1500" data-end="1524">Possible vulnerability</strong><br data-start="1524" data-end="1527">Cyber Security Researcher Kevin Beaumont said that attackers may have used the critical distance execution deficit in Microsoft Sharepoint and monitored as CV-2025-53770. </p>
<p data-start="1846" data-end="1956">According to Beaumont, the attackers brought hundreds of gigabytes of customer data and internal document out of systems.</p>
<p data-start="1958" data-end="2237"><strong data-start="1958" data-end="1980">Colt's description</strong><br data-start="1980" data-end="1983">Company spokesman, BleepingComputer'a said in a statement, "Cyber incident, we are aware of the allegations, our investigations continue. Our technical team, third -party experts are focused on restoring the affected systems," he said.</p>
<p data-start="2239" data-end="2479"><strong data-start="2239" data-end="2251"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>More than $ 300 million of cyber criminals in global operations, crypto currency frozen</title>
<link>https://pursaklargundem.com/more-than-300-million-of-cyber-criminals-in-global-operations-crypto-currency-frozen</link>
<guid>https://pursaklargundem.com/more-than-300-million-of-cyber-criminals-in-global-operations-crypto-currency-frozen</guid>
<description><![CDATA[ T3+ Global Collaborator program, which was carried out by TRM Labs, Tether, Tron and Binance, was seized in cooperation with Canada and the United States, and more than illegal crypto assets were seized in Chainlysis -supported operations.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a445cd00ca6.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 07:05:50 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Canada-US joint operations which results, which countries between the victims, how to prevent crime income on blockchain</media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="517" data-end="921"><strong data-start="517" data-end="565">250 million dollars frozen with T3+ program</strong><br data-start="565" data-end="568">Founded in September 2024, T3 Financial Crime Unit has froze $ 250 million criminal revenue worldwide. </p>
<p data-start="923" data-end="1062">In one of the prominent cases, the $ 6 million crypto assets were frozen in the “Romance Scam” attacks in cooperation with Binance.</p>
<p data-start="1064" data-end="1308"><strong data-start="1064" data-end="1119">74 million dollars in cooperation with Canada-USA</strong><br data-start="1119" data-end="1122">The “Project Atlas” directed by Canada Ontario State Police and the “Operation Avalanche ği conducted by the British Cooperation Menkul Assets Commission was supported by Chainalysis analytics.</p>
<p data-start="1310" data-end="1472">In the last six months, 74.3 million dollars of fraud income was reached and most of them were frozen. </p>
<p data-start="1474" data-end="1668"><strong data-start="1474" data-end="1490">Global effect</strong><br data-start="1490" data-end="1493">Project Atlas associated more than 2,000 crypto wallets in 14 countries with victims. </p>
<p data-start="1670" data-end="1980"><strong data-start="1670" data-end="1713">Method: intervention at blockchain level</strong><br data-start="1713" data-end="1716">In both initiatives, coordinated operations and direct interventions at the Blockchain level were prevented from transferring criminal revenues or converting them to cash. </p>
<p data-start="1982" data-end="2214"><strong data-start="1982" data-end="1994"></strong></p>
<p></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Hacker returned to the USA is accused of stealing $ 3.3 million in tax fraud</title>
<link>https://pursaklargundem.com/hacker-returned-to-the-usa-is-accused-of-stealing-33-million-in-tax-fraud</link>
<guid>https://pursaklargundem.com/hacker-returned-to-the-usa-is-accused-of-stealing-33-million-in-tax-fraud</guid>
<description><![CDATA[ Nigerian citizen Chukwuememeka Victor Galipwu was returned from France to the United States and accused of unfair profits of $ 3.3 million with fake tax refunds and SBA loan applications.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a445f50b894.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 07:04:55 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Hacker is accused of crimes in the United States, which methods were used in the attacks, how much financial damage occurred in total, what the defendant can receive</media:keywords>
<content:encoded><![CDATA[<p data-start="568" data-end="853"><strong data-start="568" data-end="611">Tax Preparation Companies Targeted</strong><br data-start="611" data-end="614">According to the US Department of Justice, Galipwu provided unauthorized access to systems with Oltalama e-mails targeting tax preparation companies in the US between 2019–2021. </p>
<p data-start="855" data-end="1102"><strong data-start="855" data-end="884">3.3 million dollars of damage</strong><br data-start="884" data-end="887">The defendant, 8.4 million dollars of counterfeit tax refund of approximately 2.5 million dollars by applying, also fake SBA loan applications $ 819 thousand dollars stolen. </p>
<p data-start="1104" data-end="1355"><strong data-start="1104" data-end="1138">Fake Investment Plan also carried out</strong><br data-start="1138" data-end="1141">According to the prosecutor's office, Gokhukwu deceived the victims with fake investment offers in the same period. </p>
<p data-start="1357" data-end="1549"><strong data-start="1357" data-end="1383">Returned from France</strong><br data-start="1383" data-end="1386">The purposeful was returned from France to the United States on August 4, 2025 and was brought before the judge in the Southern York Region the next day. </p>
<p data-start="1551" data-end="1906"><strong data-start="1551" data-end="1584">Facing serious penalties</strong><br data-start="1584" data-end="1587">There are accusations of attempted piability (5 years), twice wired fraud (20 years each), twice attempted wired fraud (20 years) and aggravated identity theft (compulsory 2 years additional penalty). </p>
<p></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Manpower Data Violation: 145 thousand people in the Ransomhub attack leaked</title>
<link>https://pursaklargundem.com/manpower-data-violation-145-thousand-people-in-the-ransomhub-attack-leaked</link>
<guid>https://pursaklargundem.com/manpower-data-violation-145-thousand-people-in-the-ransomhub-attack-leaked</guid>
<description><![CDATA[ Manpower, one of the world&#039;s largest human resources companies, announced that the personal data of nearly 145,000 people were stolen in the cyber attack in December 2024.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a445ab45c71.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 07:03:52 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Manpower data violation was leaked in the data violation, Ransomhub claimed which data he played in the attack, which branch of the company was caused by the company, which support is provided to the victims</media:keywords>
<content:encoded><![CDATA[<p data-start="488" data-end="836"><strong data-start="488" data-end="532">The attack was caused by the franchise branch</strong><br data-start="532" data-end="535">Manpower, a part of Manpowergroup, announced that at the end of December 2024 unauthorized access to systems and that the attackers may have obtained some files. </p>
<p data-start="838" data-end="1145"><strong data-start="838" data-end="870">145 thousand people were informed</strong><br data-start="870" data-end="873">Maine Chief Public Prosecutor's Office in a notification, 144,189 people were affected by the attack said. </p>
<p data-start="1147" data-end="1618"><strong data-start="1147" data-end="1179">Ransomhub undertook the attack</strong><br data-start="1179" data-end="1182">Ransomhub ransom Software Group announced the attack in January 2025. </p>
<p data-start="1620" data-end="1957"><strong data-start="1620" data-end="1642">Description from the company</strong><br data-start="1642" data-end="1645">The ManpowerGroup spokesman stressed that the incident only affected an independent franchise branch and the company's corporate network was not affected by the attack. </p>
<p data-start="1959" data-end="2338"><strong data-start="1959" data-end="1983">Ransomhub's history</strong><br data-start="1983" data-end="1986">Ransomhub has previously targeted institutions such as Halliburton, Rite Aid, Kawasaki, Christie's, Frontier Communications and Planned Parenthood. </p>
<p></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Cisco announced the highest level of security in Firewall Management Center: Risk of Remote Code Operation</title>
<link>https://pursaklargundem.com/cisco-announced-the-highest-level-of-security-in-firewall-management-center-risk-of-remote-code-operation</link>
<guid>https://pursaklargundem.com/cisco-announced-the-highest-level-of-security-in-firewall-management-center-risk-of-remote-code-operation</guid>
<description><![CDATA[ The Cisco announced the critical security deficit (CV-2025-20265) discovered in the Radius component in the SECURE Firewall Management Center software and evaluated with CVSS 10.0 (CV-2025-20265).  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a4438cef475.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 Aug 2025 07:02:54 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>CV-2025-20265 deficit gives the attackers what opportunities, which Fortiweb versions are affected, what Cisco proposes as a temporary solution, the company has published patch for other deficits</media:keywords>
<content:encoded><![CDATA[<p data-start="496" data-end="869"><strong data-start="496" data-end="520">Technical dimension of the deficit</strong><br data-start="520" data-end="523">CV-2025-20265 is due to the fact that the user input is not correctly processed during the Radius authentication process. </p>
<p data-start="871" data-end="1128"><strong data-start="871" data-end="901">Which versions are affected</strong><br data-start="901" data-end="904">According to Cisco, the Open is open, in the 7.0.7 and 7.7.0 versions of FMC software, Radius authentication occurs when the authentication is active. </p>
<p data-start="1130" data-end="1351"><strong data-start="1130" data-end="1158">Updates Published</strong><br data-start="1158" data-end="1161">Cisco has released free software updates to relieve the vulnerability. </p>
<p data-start="1353" data-end="1590"><strong data-start="1353" data-end="1378">Temporary solution option</strong><br data-start="1378" data-end="1381">The only temporary solution proposed in the environments that cannot be loaded with patch, the use of local user accounts, LDAP or SAML -based authentication methods instead of disabled Radius authentication.</p>
<p data-start="1592" data-end="1807"><strong data-start="1592" data-end="1619">Has not been abused yet</strong><br data-start="1619" data-end="1622">Open, Cisco security researcher Brandon Sakai was discovered in internal tests. </p>
<p data-start="1809" data-end="2064"><strong data-start="1809" data-end="1833">Additional security patches</strong><br data-start="1833" data-end="1836">Cisco has also closed 13 high -importance security vulnerabilities, such as Snort 3, ASA, FTD, IOS and IOS XE, such as service rejection (DOS) and HTML injection. </p>
<p><a href="https://beykozunsesi.com.tr/beykoz-haber" target="_blank" rel="noopener">Beykoz News</a></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>257 events in a week in Elazığ: 136 people were arrested, 22 people were arrested</title>
<link>https://pursaklargundem.com/257-events-in-a-week-in-elazig-136-people-were-arrested-22-people-were-arrested</link>
<guid>https://pursaklargundem.com/257-events-in-a-week-in-elazig-136-people-were-arrested-22-people-were-arrested</guid>
<description><![CDATA[ According to the weekly public order bulletin dated 10-17 August 2025, shared by the Provincial Directorate of Press and Public Relations of Elazığ Governorship, 257 events occurred throughout the city.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68a3619017e2a.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 Aug 2025 20:31:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How many people were caught in public order practices in Elazığ, which drugs were seized, how many vehicles were cut in traffic inspections, which products were confiscated in smuggling operations</media:keywords>
<content:encoded><![CDATA[<p data-start="506" data-end="661">The Provincial Directorate of Press and Public Relations of Elazığ Governorship published the weekly public order bulletin covering 10-17 August 2025.</p>
<p data-start="663" data-end="922"><strong data-start="663" data-end="696">136 people caught in 257 incidents</strong><br data-start="696" data-end="699">According to the information contained in the newsletter, 257 events occurred in a week throughout the city. </p>
<p data-start="924" data-end="1101"><strong data-start="924" data-end="963">More than 60 thousand people were checked</strong><br data-start="963" data-end="966">60 thousand 682 people and 25 thousand 162 vehicles were checked in public order applications. </p>
<p data-start="1103" data-end="1494"><strong data-start="1103" data-end="1155">Weapons, drugs and illegal products seized</strong><br data-start="1155" data-end="1158">7 pistols, 5 rifles, 9 cartridges, 2 cutting tools were seized. </p>
<p data-start="1496" data-end="1668">23 thousand 40 macarons, 1 detectors, 5 excavation materials, 7 kilograms of illegal tea and 50 packs of bandrol cigarettes were seized.</p>
<p data-start="1670" data-end="1936"><strong data-start="1670" data-end="1710">78 people were injured in traffic accidents</strong><br data-start="1710" data-end="1713">34 traffic accidents occurred in a week throughout the province. </p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>The zero &#45;day deficit in Winrar was used in targeted attacks to install Romcom malicious software</title>
<link>https://pursaklargundem.com/the-zero-day-deficit-in-winrar-was-used-in-targeted-attacks-to-install-romcom-malicious-software</link>
<guid>https://pursaklargundem.com/the-zero-day-deficit-in-winrar-was-used-in-targeted-attacks-to-install-romcom-malicious-software</guid>
<description><![CDATA[ The gap of the directory transition, which was monitored as CV-2025-8088 and resolved with Winrar 7.13 version, was exploited via specially prepared RAR archives distributed by e-mails.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_68967b3bd942a.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 09 Aug 2025 14:56:55 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How the CV-2025-8088 gap works, the Romcom group has exploited this gap, which version of Winrar was closed, what to do to protect users</media:keywords>
<content:encoded><![CDATA[<p><strong>Winrar</strong>’ın Windows sürümlerinde tespit edilen <strong>CV-2025-8088</strong> güvenlik açığının, yamalanmadan önce hedefli oltalama saldırılarında aktif olarak kullanıldığı ortaya çıktı. <strong>Essence</strong> araştırmacıları <strong>Anton CherePanov</strong>, <strong>Peter Košinár</strong> ve <strong>Peter Strýček</strong> tarafından keşfedilen açık, WinRAR 7.13 sürümünde kapatıldı.</p>
<p>Index crossing (<em>Directory Traveorsal</em>) This open, specially prepared RAR archives caused by their error allow them to issue files to a location defined by the attacker instead of the directory specified by the user. <code>%Appdata%\ Microsoft \ Windows \ Start Menu \ Programs \ Startup</code> veya <code>%Programdata%\ Microsoft \ Windows \ Start Menu \ Programs \ Startup</code>) can be placed. </p>
<p>ESET, saldırılarda hedefli oltalama e-postalarıyla gönderilen RAR dosyalarının bu açığı kullanarak <strong>Romcom</strong> arka kapı zararlı yazılımını yüklediğini belirledi. RomCom (<em>Storm-0978</em>, <em>Tropical scorpius</em> veya <em>UNC2596</em> olarak da bilinir) Rusya bağlantılı bir tehdit grubu olup fidye yazılımı, veri hırsızlığı ve kimlik bilgisi toplama kampanyalarıyla tanınıyor. Grup daha önce Cuba ve Industrial Spy fidye yazılım operasyonlarıyla ilişkilendirilmişti.</p>
<p>WinRAR otomatik güncelleme özelliği sunmadığından, tüm kullanıcıların <a href="https://www.win-rar.com/">win-rar.com</a> adresinden en son sürümü manuel olarak indirmesi öneriliyor. ESET, açığın istismarına dair detaylı bir raporu daha sonra yayımlayacağını açıkladı.</p>
<p>Kaynak: <strong>Cumha - Cumhur News Agency</strong></p>]]> </content:encoded>
</item>

<item>
<title>Fraud warning from Kayseri Metropolitan: Aid Applications are made only from the official site</title>
<link>https://pursaklargundem.com/fraud-warning-from-kayseri-metropolitan-aid-applications-are-made-only-from-the-official-site</link>
<guid>https://pursaklargundem.com/fraud-warning-from-kayseri-metropolitan-aid-applications-are-made-only-from-the-official-site</guid>
<description><![CDATA[ Kayseri Metropolitan Municipality warned citizens against fraud attempts regarding stationery and nutrition aid applications.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202508/image_870x_688d47b8c9df3.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 02 Aug 2025 02:06:51 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How to apply for help, how to make a fraud, official applications are made from the site, which information should be paid attention to, where should be applied in cases of suspicion of fraud</media:keywords>
<content:encoded><![CDATA[<p data-start="446" data-end="812">Kayseri Metropolitan Municipality, 2025-2026 Academic Year to be made within the scope of the stationery and nutrition aid applications to the opportunity to turn the opportunity to turn the public warned to the public. </p>
<p data-start="814" data-end="1119">According to the statement, some malevolent people demanded identity and bank information on the pretext of application for help, and tried to open an account through counterfeit forms. </p>
<p data-start="1121" data-end="1406">Only your applications<span> </span><a data-start="1141" data-end="1159" rel="noopener" target="_new" class="" href="http://www.kayseri.bel.tr/">www.kayseri.bel.tr</a><span> </span>It was reminded that it can be done through the address. </p>
<p data-start="1408" data-end="1655">The municipality said that citizens should not respect the directions made through telephone, text message or social media. </p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>With the closure of the XSS.IS forum, a big blow to the international cyber crime network</title>
<link>https://pursaklargundem.com/with-the-closure-of-the-xssis-forum-a-big-blow-to-the-international-cyber-crime-network</link>
<guid>https://pursaklargundem.com/with-the-closure-of-the-xssis-forum-a-big-blow-to-the-international-cyber-crime-network</guid>
<description><![CDATA[ The executive of the XSS.IS forum was detained in the international operation in Kiev, the capital of Ukraine.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202507/image_870x_6881d0b45c3b5.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 24 Jul 2025 17:09:54 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Why was the XSS forum closed, the operation was carried out in cooperation with which countries, how much income of the forum manager earned, how will the closure will affect the world of cyber crime</media:keywords>
<content:encoded><![CDATA[<h1>Xss.is forum closed: Captured by international operation</h1>
<p>Uluslararası iş birliğiyle yürütülen bir operasyon kapsamında, dünyanın en büyük Rusça konuşulan siber suç forumlarından biri olan <strong>Xss.is</strong> kapatıldı. Forumun yöneticisi, <strong>22 July 2025</strong> tarihinde Ukrayna'nın başkenti <strong>Kyiv</strong>He was caught too. </p>
<h2>4 -year investigation process</h2>
<p>Paris Emniyet Müdürlüğü Siber Suç Birimi tarafından <strong>2 July 2021</strong> tarihinde başlatılan kapsamlı soruşturma sonucunda forumun faaliyetlerine dair çok sayıda veri toplandı. Fransız kolluk kuvvetleri, XSS forumuyla bağlantılı olan <em>theSecure.biz</em> adlı Jabber sunucusu üzerinden iletişimleri takip etti. Bu takip sonucunda yakalanan kişinin, çok sayıda yasa dışı siber suç ve fidye yazılımı operasyonuyla bağlantılı olduğu belirlendi.</p>
<h2>The history and role of the forum</h2>
<p><strong>2013</strong> yılında <em>Damagelab</em> adıyla kurulan ve <strong>2018</strong>'de <strong>Xss.is</strong> ismini alan platform, siber suç dünyasında köklü bir geçmişe sahipti. 50 binden fazla kayıtlı kullanıcısıyla XSS.is, kötü amaçlı yazılım satışı, sistemlere izinsiz erişim, çalıntı veri ticareti ve fidye yazılım hizmetleri gibi faaliyetlerin merkezi konumundaydı. Ayrıca forum, şifreli Jabber sunucusu üzerinden siber suçlular arasında anonim iletişim imkânı da sunuyordu.</p>
<h2>Financial dimension and legal process</h2>
<p>Europol tarafından yapılan açıklamaya göre, gözaltına alınan şüphelinin forum üzerinden <strong>7 million euros</strong>It was determined that it generates more income. </p>
<p>Şüpheli hakkında <strong>9 November 2021</strong> tarihinde “veri işleme sistemlerine yönelik saldırılara yardım ve yataklık”, “örgütlü gasp” ve “suç örgütü üyeliği” suçlamalarıyla yasal işlem başlatıldı. Bu operasyon, karanlık ağ üzerindeki benzer platformlara yönelik süren uluslararası baskının bir parçası olarak değerlendiriliyor.</p>
<h2>The effect of closure</h2>
<p>According to experts, the closure of built -in platforms such as XSS.IS with a wide audience may cause serious gaps in the cyber crime ecosystem. </p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Safety gap in the Metaverse universe: Personal data in the virtual world is in danger</title>
<link>https://pursaklargundem.com/safety-gap-in-the-metaverse-universe-personal-data-in-the-virtual-world-is-in-danger</link>
<guid>https://pursaklargundem.com/safety-gap-in-the-metaverse-universe-personal-data-in-the-virtual-world-is-in-danger</guid>
<description><![CDATA[ With the spread of Metaverse platforms, digital identity and safety of financial data have become a major problem in virtual environments.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_681b0a2c7b7c9.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Which cyber risks come to the fore in Metaverse, how to protect virtual identities, users what to do against fraud, Türkiye should close the legal gaps in this field</media:keywords>
<content:encoded><![CDATA[<p data-start="441" data-end="879" class=""><strong data-start="441" data-end="496">The virtual world is growing, the risks come with it</strong><br data-start="496" data-end="499">Metaverse technology stands out as a new digital universe in which users can interact in increased and virtual reality environments. </p>
<p data-start="881" data-end="1287" class=""><strong data-start="881" data-end="934">Identity Theft and Virtual Fraud is increasing</strong><br data-start="934" data-end="937">Identity authentication systems used in metavers are often insufficient. </p>
<p data-start="1289" data-end="1756" class=""><strong data-start="1289" data-end="1339">The new world wants new security protocols</strong><br data-start="1339" data-end="1342">Cyber security experts, Metaverse platforms due to the decentralized structures of classical security protocols are not enough, he says. </p>
<p data-start="1758" data-end="2077" class=""><strong data-start="1758" data-end="1792">Legal gaps attract attention</strong><br data-start="1792" data-end="1795">Metaverse platforms in Turkey have not yet been regulated by open legal frameworks. </p>
<p data-start="2079" data-end="2273" class=""></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Hospitals are on the target: Cyber attacks on the health sector alarm</title>
<link>https://pursaklargundem.com/hospitals-are-on-the-target-cyber-attacks-on-the-health-sector-alarm</link>
<guid>https://pursaklargundem.com/hospitals-are-on-the-target-cyber-attacks-on-the-health-sector-alarm</guid>
<description><![CDATA[ Cyber attacks targeting health institutions in Turkey are increasing rapidly.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_681b099638730.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Cyber attacks on health institutions are increasing why, how to target patient data, how to protect hospitals against cyber threats, what steps should be taken in the health sector of Türkiye</media:keywords>
<content:encoded><![CDATA[<p data-start="486" data-end="906" class=""><strong data-start="486" data-end="538">While the health sector is digitalizing, threats are growing</strong><br data-start="538" data-end="541">Providing health services in digital environments, working with hospital systems with internet connected infrastructures and storing personal data of millions of patients in electronic environment has made the health sector the target of cyber attacks. </p>
<p data-start="908" data-end="1256" class=""><strong data-start="908" data-end="953">Systems are locked with ransom software</strong><br data-start="953" data-end="956">The attackers make it inaccessible by encrypting patient information, medical records and system management panels. </p>
<p data-start="1258" data-end="1569" class=""><strong data-start="1258" data-end="1313">Patient safety and service continuity are at risk</strong><br data-start="1313" data-end="1316">Such attacks threaten not only data security, but also service continuity. </p>
<p data-start="1571" data-end="2051" class=""><strong data-start="1571" data-end="1615">Health Information Infrastructure should be strengthened</strong><br data-start="1615" data-end="1618">According to experts, most of the health institutions in Turkey have inadequate protection for cyber security. </p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Cyber Security Specialist Gargers are Growing: Universities play a critical role</title>
<link>https://pursaklargundem.com/cyber-security-specialist-gargers-are-growing-universities-play-a-critical-role</link>
<guid>https://pursaklargundem.com/cyber-security-specialist-gargers-are-growing-universities-play-a-critical-role</guid>
<description><![CDATA[ The lack of sufficient human resources against rapidly increasing cyber threats in Türkiye mobilized educational institutions.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_681b0ab81d17f.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How big is the deficit of cyber security experts in Türkiye, how the universities offer solutions to this problem, what are the cooperation with the private sector, how to develop training programs</media:keywords>
<content:encoded><![CDATA[<p data-start="2669" data-end="3054" class=""><strong data-start="2669" data-end="2731">Türkiye's biggest deficit in cyber security: human resources</strong><br data-start="2731" data-end="2734">While cyber attacks are rapidly diversified and increasing, the number of experts who can resist these threats does not increase at the same speed. </p>
<p data-start="3056" data-end="3409" class=""><strong data-start="3056" data-end="3096">Universities started to produce solutions</strong><br data-start="3096" data-end="3099">In order to close this gap, many universities open new cyber security departments, while cyber security -oriented lessons are added to the existing computer engineering departments. </p>
<p data-start="3411" data-end="3807" class=""><strong data-start="3411" data-end="3451">Private sector cooperations are expanding</strong><br data-start="3451" data-end="3454">Cyber security companies and technology companies signed protocols with universities and started to organize internship, project and business guaranteed training programs. </p>
<p data-start="3809" data-end="4208" class=""><strong data-start="3809" data-end="3857">The quality and diversity of education should be increased</strong><br data-start="3857" data-end="3860">Experts say that not only at the undergraduate level, but also vocational schools and certificate programs should be expanded. </p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Interior Minister Ali Yerlikaya: &amp;apos;Cyber security is now an integral part of internal and external security&amp;apos;</title>
<link>https://pursaklargundem.com/interior-minister-ali-yerlikaya-cyber-security-is-now-an-integral-part-of-internal-and-external-security</link>
<guid>https://pursaklargundem.com/interior-minister-ali-yerlikaya-cyber-security-is-now-an-integral-part-of-internal-and-external-security</guid>
<description><![CDATA[ Speaking at the Synthetic Media and Information Safety Workshop organized by the Communication Presidency, Interior Minister Ali Yerlikaya stated that the fight against cyber crimes continues with determination and that information security has become a strategic priority in terms of public order and social peace. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_681b1b6cdf9c1.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Cyber security has become a part of internal and external security, how the Ministry of the Interior struggles with cyber crimes, how the information security affects public order, which procedures were done for social media accounts</media:keywords>
<content:encoded><![CDATA[<p><br data-start="460" data-end="463"><strong data-start="463" data-end="514">Critical messages at the workshop held in Ankara</strong><br data-start="514" data-end="517">Interior Minister Ali Yerlikaya also participated in the Synthetic Media and Information Safety Workshop organized by the Communication Presidency in Ankara. </p>
<p></p>
<p data-start="799" data-end="1223" class=""><strong data-start="799" data-end="844">Cyber crimes and digital threats are growing</strong><br data-start="844" data-end="847">Nowadays, many activities carried out in the digital environment, many activities carried out in the digital environment, Yerlikaya, 'Cyber security has become a vital difficulty. </p>
<p data-start="1225" data-end="1658" class=""><strong data-start="1225" data-end="1268">Combating figures against cyber crimes</strong><br data-start="1268" data-end="1271">Yerlikaya, who also shared the data of the Ministry of Interior within the scope of the fight against Cyber Crimes, said that the account bearing a criminal element of 237,753 criminals during the cabinet period was blocked and that the account of the 21.214 account was blocked and the access of the social media account was closed. </p>
<p data-start="1660" data-end="2121" class=""><strong data-start="1660" data-end="1718">INFORMATION SAFETY IS directly related to public order</strong><br data-start="1718" data-end="1721">Referring to the importance of information safety in his speech, Yerlikaya stated that this area is not only a technical issue and that it is a strategic area in terms of public order, social peace and national security. </p>
<p data-start="2123" data-end="2488" class=""><strong data-start="2123" data-end="2176">The work of the Communication Presidency is supported</strong><br data-start="2176" data-end="2179">Yerlikaya, emphasizing the importance of the activities carried out by the Presidency of Communication in the workshop, said that they support the communication activities carried out in order to strengthen the link between the state and the nation. </p>
<p data-start="2490" data-end="2736" class=""><strong data-start="2490" data-end="2502"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>New Period for Cyber Security Training in Saudi Arabia: Ine Security and Abadnet collaboration started</title>
<link>https://pursaklargundem.com/new-period-for-cyber-security-training-in-saudi-arabia-ine-security-and-abadnet-collaboration-started</link>
<guid>https://pursaklargundem.com/new-period-for-cyber-security-training-in-saudi-arabia-ine-security-and-abadnet-collaboration-started</guid>
<description><![CDATA[ Ine Security, one of the global leaders in the field of cyber security, has signed a comprehensive training partnership with Saudi Arabia -based Abadnet Institute.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_682f08553c583.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Ine Security and Abadnet cooperation, how many students in Saudi Arabia will benefit from this program, what is ejpt training, what certificates of Abadnet Institute</media:keywords>
<content:encoded><![CDATA[<p><br data-start="411" data-end="414">Cary, North Karolina -based Cyber Security Training firm Ine Security, announced that it has established a strategic partnership with Abadnet Institute for Training operating in Riyadh. </p>
<p></p>
<p data-start="816" data-end="1287"><strong data-start="816" data-end="860">International Accredited Training Programs</strong><br data-start="860" data-end="863">Founded in 2007, Abadnet Institute is an educational organization that has been interested in international accredited programs that serve more than 10,000 students annually. </p>
<p data-start="1289" data-end="1737"><strong data-start="1289" data-end="1318">The first academy was completely filled</strong><br data-start="1318" data-end="1321">The new cooperation started with the first academy of 200 students and all license quotas were completely filled. </p>
<p data-start="1739" data-end="2240"><strong data-start="1739" data-end="1797">Abadnet improves the quality of education with Ine content</strong><br data-start="1797" data-end="1800">Abadnet Institute Operations Director Ahmed Alkathiri pointed out the content quality of Ine Security: </p>
<p data-start="2242" data-end="2577"><strong data-start="2242" data-end="2268">Future -oriented Investment</strong><br data-start="2268" data-end="2271">This cooperation is considered as part of Ine Security's goal of strengthening the digital employment ecosystem in the region and raising high -quality cyber security experts. </p>
<p data-start="2579" data-end="2774"><strong data-start="2579" data-end="2591"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>More than 100 fake extensions detected in the Chrome store take over sessions</title>
<link>https://pursaklargundem.com/more-than-100-fake-extensions-detected-in-the-chrome-store-take-over-sessions</link>
<guid>https://pursaklargundem.com/more-than-100-fake-extensions-detected-in-the-chrome-store-take-over-sessions</guid>
<description><![CDATA[ More than 100 fake Chrome extensions, which have been identified since February 2024, seize users sessions, steal their identity information and inject advertising to the browsers.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_682f0de6ded00.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Fake Chrome extensions how to work, which services are imitated, how users can be protected, Google which measures took</media:keywords>
<content:encoded><![CDATA[<p data-start="437" data-end="874"><strong data-start="458" data-end="513">Fake Chrome extensions threaten users</strong><br data-start="513" data-end="516">According to the findings of the Domaintools Intelligence (DTI) team, a large number of extensions have been released in the Chrome Web Store since February 2024, which seem to be apparently harmless, but has serious security risks in the background. </p>
<p data-start="876" data-end="1238"><strong data-start="876" data-end="923">Malicious extensions get excessive permits</strong><br data-start="923" data-end="926">Malicious add -ons, manifest.json files give them extensive permissions. </p>
<p data-start="1240" data-end="1661"><strong data-start="1240" data-end="1287">They spread by imitating legitimate services</strong><br data-start="1287" data-end="1290">The distribution of extensions is carried out through fake websites that mimic known services such as Deepseek, Manus, Debank, Fortivpn and Site Stats. </p>
<p data-start="1663" data-end="2004"><strong data-start="1663" data-end="1708">Facebook tools may also be used</strong><br data-start="1708" data-end="1711">The DTI team thinks that attackers also use social media platforms to direct users to fake extensions. </p>
<p data-start="2006" data-end="2372"><strong data-start="2006" data-end="2054">Google took action, users are warned</strong><br data-start="2054" data-end="2057">The malicious extensions identified have been removed from the Chrome Web Store by Google. </p>
<p data-start="2374" data-end="2706"><strong data-start="2374" data-end="2409">The risk of manipulation continues</strong><br data-start="2409" data-end="2412">According to Domaintools' findings, some extensions direct users who give low scores to special feedback forms to manipulate user scoring, while directing high scorers directly to the Chrome Store. </p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>It turned out that the Citrixbled 2 deficit was used in targeted attacks before being announced to the public.</title>
<link>https://pursaklargundem.com/it-turned-out-that-the-citrixbled-2-deficit-was-used-in-targeted-attacks-before-being-announced-to-the-public</link>
<guid>https://pursaklargundem.com/it-turned-out-that-the-citrixbled-2-deficit-was-used-in-targeted-attacks-before-being-announced-to-the-public</guid>
<description><![CDATA[ The critical security vulnerability affecting Citrix Netscaler devices was used in attacks from Chinese IP addresses about two weeks before the publication of POC codes were published.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202507/image_870x_687a320ac9f27.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How the Citrixbled 2 gap works, which dates were abused, why Citrix explained the attacks late, which sectors were targeted</media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="430" data-end="669">The critical security vulnerability called "Citrixbleed 2", which affects Citrix Netscaler products, was found to be targeted by cyber attackers before sharing public abuse codes.</p>
<p data-start="671" data-end="937">Cyber Security Firm Greynoise announced on 23 June 2025 that HoneyPot systems perceived the attacks on which this deficit was targeted. </p>
<p data-start="939" data-end="1417">Greynoise reported that it was a special label to follow the gap on July 7, and thanks to this label, the attack attempts on past data have become visible. </p>
<p data-start="1419" data-end="1874"><strong data-start="1419" data-end="1442">Citrix remained silent</strong><br data-start="1442" data-end="1445">According to verification with the abuse codes provided by Greynoise, the attacks were directly targeted by the Citrixbled 2 deficit. </p>
<p data-start="1876" data-end="2177">On July 15, Citrix released a new blog post on how to detect the symptoms of security in Netscaler systems. </p>
<p data-start="2179" data-end="2717"><strong data-start="2179" data-end="2206">Technical details of the deficit</strong><br data-start="2206" data-end="2209">The Citrixbleed 2 is defined as a memory excess deficit due to insufficient input verification during the login operations in Netscaler systems. </p>
<p data-start="2719" data-end="3041">Kevin Beaumont, "/Douthentication.do" on the way to repeated post requests and "Content-Length: 5" requests that may be symptoms of abuse, he said. </p>
<p data-start="3043" data-end="3534"><strong data-start="3043" data-end="3081">Citrix's suggestions were insufficient</strong><br data-start="3081" data-end="3084">Citrix suggested that ICA and PCOIP sessions be terminated with Kill commands to terminate the abused sessions. </p>
<p data-start="3536" data-end="3833"><strong data-start="3536" data-end="3564">DETERMINATION AND SPRING STATUS</strong><br data-start="3564" data-end="3567">According to Beaumont, the deficit was used as of June 20 and became widespread in the following days. </p>
<p data-start="3835" data-end="4013">On the other hand, according to the statement made by IMPERVA, the products detected over 11.5 million abuse attempts. </p>
<p data-start="4015" data-end="4240">Citrix has released security patches for Netscaler ADC and Gateway and announced that users should urgently pass to supported versions. </p>
<p data-start="4247" data-end="4409"><strong data-start="4247" data-end="4259"></strong></p>
<p></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Critical Warning from Apple: If the AirPlay feature is not closed, the devices are in danger</title>
<link>https://pursaklargundem.com/critical-warning-from-apple-if-the-airplay-feature-is-not-closed-the-devices-are-in-danger</link>
<guid>https://pursaklargundem.com/critical-warning-from-apple-if-the-airplay-feature-is-not-closed-the-devices-are-in-danger</guid>
<description><![CDATA[ Apple warned iPhone users for 23 security vulnerabilities discovered in the AirPlay protocol.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_683023cee90d0.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is the AirPlay deficit, how iPhone users close AirPlay, what proposes against the Apple AirPlay security deficits, which devices affects Airborne security vulnerability</media:keywords>
<content:encoded><![CDATA[<p><br data-start="328" data-end="331"><strong data-start="331" data-end="388">Important warning from Apple to AirPlay vulnerability</strong><br data-start="388" data-end="391">Apple, AirPlay feature due to a large number of security vulnerabilities iPhone users have given a critical warning. </p>
<p></p>
<p data-start="624" data-end="938"><strong data-start="624" data-end="664">23 separate security vulnerabilities were detected</strong><br data-start="664" data-end="667">According to the study of cyber security firm Oligo, Apple has up to 23 in the AirPlay protocol. </p>
<p data-start="940" data-end="1284"><strong data-start="940" data-end="991">Risk of Remote Access and Zero Click Attack</strong><br data-start="991" data-end="994">Oligo CTO Gal Elbaz, these deficits can be used by computer pirates to organize zero -click attacks, he said. </p>
<p data-start="1286" data-end="1586"><strong data-start="1286" data-end="1332">Safety Call from Apple to users</strong><br data-start="1332" data-end="1335">Apple, the most effective measures against these security deficits, AirPlay feature is disabled and the iPhone to the latest version of the iPhone announced. </p>
<p data-start="1588" data-end="1776"><strong data-start="1588" data-end="1600"></strong></p><br><p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Microsoft Teams via fake aid desk searches are spreading matanbuchus pests</title>
<link>https://pursaklargundem.com/microsoft-teams-via-fake-aid-desk-searches-are-spreading-matanbuchus-pests</link>
<guid>https://pursaklargundem.com/microsoft-teams-via-fake-aid-desk-searches-are-spreading-matanbuchus-pests</guid>
<description><![CDATA[ Matanbuchus pests began to be distributed with social engineering attacks on Microsoft Teams.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202507/image_870x_687a329317e55.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How Matanbuchus works, How are the attackers use Microsoft Teamsi, what kind of innovations Matuchus 3.0 contain innovations, which measures should the system managers take</media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="422" data-end="719">The Microsoft Teams Platform has recently been used in social engineering attacks for the recent distribution of malware called Matanbuchus. </p>
<p data-start="721" data-end="1138">Matanbuchus, ilk olarak 2021 yılında karanlık ağda tanıtılan bir <strong data-start="786" data-end="817">Malware-A-A-Service (Maas)</strong> hizmeti olarak dikkat çekmişti. Windows sistemlerinde çalışan bu zararlı yazılım, yüklediği kötü amaçlı bileşenleri doğrudan bellekte çalıştırarak antivirüs yazılımlarının tespitinden kaçabiliyor. Yazılım, daha önce 2022 yılında büyük çaplı bir spam kampanyasında Cobalt Strike bileşenlerini dağıtmak için kullanılmıştı.</p>
<p data-start="1140" data-end="1570"><strong data-start="1140" data-end="1186">It infiltrates systems with fake IT calls</strong><br data-start="1186" data-end="1189">Morphisec adlı güvenlik firmasına göre, Matanbuchus'un yeni sürümü olan 3.0 versiyonunda Microsoft Teams üzerinden saldırılar daha yaygın hale geldi. Saldırganlar, hedef kullanıcıya harici bir Teams çağrısı başlatarak kendilerini BT destek personeli gibi tanıtıyor. Ardından, hedef kullanıcıdan Windows’un yerleşik uzaktan yardım aracı olan <strong data-start="1530" data-end="1546">Quick Assist</strong>He is asked to start.</p>
<p data-start="1572" data-end="1821">Quick Assist üzerinden erişim sağlandıktan sonra kullanıcıdan bir PowerShell komutu çalıştırması isteniyor. Bu komut, üç dosya içeren bir ZIP arşivini indirip çıkararak, <strong data-start="1742" data-end="1762">DLL Side-Loging</strong> yöntemiyle Matanbuchus zararlısının yüklenmesini sağlıyor.</p>
<p data-start="1823" data-end="2158"><strong data-start="1823" data-end="1855">Advanced hidden methods</strong><br data-start="1855" data-end="1858">Matanbuchus 3.0 sürümü, önceki versiyonlara kıyasla daha gelişmiş gizlenme ve tespit önleme özellikleri içeriyor. Komut ve kontrol iletişimi RC4 yerine <strong data-start="2010" data-end="2021">Salsa20</strong> algoritmasıyla sağlanıyor. Zararlı yazılım, yalnızca belirli bölge ve sistemlerde çalışmak üzere <strong data-start="2119" data-end="2135">Anti-Sandbox</strong> kontrolleri uyguluyor.</p>
<p data-start="2160" data-end="2401">Windows API çağrıları yerine doğrudan <strong data-start="2198" data-end="2209">SYSCALL</strong>’lar aracılığıyla işlem yapan zararlı, güvenlik yazılımlarını atlatmayı hedefliyor. Bu işlemler, analizden kaçmak için <strong data-start="2328" data-end="2343">Murmurhash3</strong> adlı non-kriptografik özetleme algoritmasıyla gizleniyor.</p>
<p data-start="2403" data-end="2662">The abilities of the malware after working in the system include the fact that PowerShell, CMD, EXE, DLL, MSI and Shellcode files, collect user information and identify security software and adjust the attack method accordingly.</p>
<p data-start="2664" data-end="2942"><strong data-start="2664" data-end="2694">Threat analysis and warnings</strong><br data-start="2694" data-end="2697">In the technical analysis by Morphisec, Matanbuchus has become a significant advanced threat. </p>
<p data-start="2944" data-end="3259">In the past, it is known that the Darkgate pest has been distributed through Microsoft Teams in similar ways and that organizations with weak external access settings have been targeted. </p>
<p data-start="3266" data-end="3448"><strong data-start="3266" data-end="3278"></strong></p>
<p></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>VMware, PWN2own Berlin in Berlin, the four critical esxi abused with zero &#45;day vulnerabilities patch the vulnerability</title>
<link>https://pursaklargundem.com/vmware-pwn2own-berlin-in-berlin-the-four-critical-esxi-abused-with-zero-day-vulnerabilities-patch-the-vulnerability</link>
<guid>https://pursaklargundem.com/vmware-pwn2own-berlin-in-berlin-the-four-critical-esxi-abused-with-zero-day-vulnerabilities-patch-the-vulnerability</guid>
<description><![CDATA[ At the PWN2own Berlin 2025 event, the company has released updates for four zero -day deficits that have been abused by security researchers and affect VMware ESXI, Workstation, Fusion and Tools products.  ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202507/image_870x_687a32481156e.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 19 Jul 2025 20:23:49 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Which VMware products were affected, explains how it was abused, is there any solution other than the update, which prizes were given in the PWN2own berl</media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="490" data-end="730">VMware has released security updates for four zero -day deficit that affecting virtualization products and abused in the PWN2WN Berlin 2025 competition. </p>
<p data-start="732" data-end="926">Three of these deficits are defined as high -importance weaknesses that allow the attackers to move from the virtual machine to the main system to run a command. </p>
<ul data-start="928" data-end="1483">
<li data-start="928" data-end="1081">
<p data-start="930" data-end="1081"><strong data-start="930" data-end="949">CV-2025-41236:</strong> VMXNET3 sanal ağ adaptöründe bulunan tamsayı taşması açığı. Bu zafiyet, STARLabs SG’den Nguyen Hoang Thach tarafından kullanıldı.</p>
</li>
<li data-start="1082" data-end="1295">
<p data-start="1084" data-end="1295"><strong data-start="1084" data-end="1103">CV-2025-41237:</strong> VMCI (Virtual Machine Communication Interface) bileşeninde tamsayı alt taşması sonucu oluşan out-of-bounds yazma hatası. Açık, REverse Tactics’ten Corentin Bayet tarafından istismar edildi.</p>
</li>
<li data-start="1296" data-end="1483">
<p data-start="1298" data-end="1483"><strong data-start="1298" data-end="1317">CV-2025-41238:</strong> PVSCSI (Paravirtualized SCSI) kontrolcüsünde bulunan heap overflow zafiyeti. Bu açık, Synacktiv’ten Thomas Bouzerar ve Etienne Helluy-Lafont tarafından kullanıldı.</p>
</li>
</ul>
<p data-start="1485" data-end="1533">Each of these three vulnerabilities has 9.3 CVSS points.</p>
<p data-start="1535" data-end="1803"><strong data-start="1535" data-end="1572">Information leakage deficit was also closed</strong><br data-start="1572" data-end="1575">Dördüncü açık olan <strong data-start="1594" data-end="1612">CV-2025-41239</strong>It was defined as a vulnerability that could lead to leakage of information and received 7.1 violence points. </p>
<p data-start="1805" data-end="2186"><strong data-start="1805" data-end="1838">There is no solution other than patch</strong><br data-start="1838" data-end="1841">VMware has announced that it does not offer any temporary solution for these security deficits. </p>
<p data-start="2188" data-end="2383">All of the deficits were shown in the PWN2OW Berlin competition held in May 2025. </p>
<p data-start="2390" data-end="2543"><strong data-start="2390" data-end="2402"></strong></p>
<p></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Artificial Intelligence Supported Intelsonar announced the location detection via image.</title>
<link>https://pursaklargundem.com/artificial-intelligence-supported-intelsonar-announced-the-location-detection-via-image</link>
<guid>https://pursaklargundem.com/artificial-intelligence-supported-intelsonar-announced-the-location-detection-via-image</guid>
<description><![CDATA[ Doğukan Çalışkan, who works in the field of cyber security and intelligence, explained that with the Intelsonar system they developed, geographical location can be detected using only image data. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202506/image_870x_68611a9012327.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 06 Jul 2025 11:54:35 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Intelsonar is exactly how it works, the system can be used in which areas, which geographical data analyzes artificial intelligence, when will the open beta process begin</media:keywords>
<content:encoded><![CDATA[<p></p>
<p data-start="473" data-end="846">Doğukan Çalışkan, who works in the fields of Cyber ​​Security and Open Source Intelligence, announced the newly developed geographical location system called Intelsonar.</p>
<p data-start="848" data-end="1221">According to Çalışkan's statement, Intelsonar provides a high accuracy ratio, especially in images that do not contain EXIF ​​data, blurred or reference points.</p>
<p data-start="1223" data-end="1557">In the final tests, Intelsonar reached a accuracy rate of more than 92 %in challenging areas such as desert and urban border regions.</p>
<p data-start="1559" data-end="1673">Intelsonar, which is still in a closed test phase, is planned to be announced in the coming period.</p>
<p data-start="1675" data-end="1859"><strong data-start="1675" data-end="1687"></strong></p>
<p></p>
<p></p>
<p><b>Kaynak: CUMHA - CUMHUR HABER AJANSI</b></p>]]> </content:encoded>
</item>

<item>
<title>Ali Yerlikaya: &amp;apos;190 people were caught in operations against cybercrimes in 31 provinces&amp;apos;</title>
<link>https://pursaklargundem.com/ali-yerlikaya-190-people-were-caught-in-operations-against-cybercrimes-in-31-provinces</link>
<guid>https://pursaklargundem.com/ali-yerlikaya-190-people-were-caught-in-operations-against-cybercrimes-in-31-provinces</guid>
<description><![CDATA[ Interior Minister Ali Yerlikaya announced that 190 suspects were caught in cybercrime operations conducted in 31 provinces in the last 3 days. It was stated that the suspects were involved in crimes such as qualified fraud, illegal betting, child obscenity and money laundering. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202506/image_870x_68550c73755bf.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 22 Jun 2025 12:47:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>In which provinces was the cybercrime operation carried out, how many people were detained, what crimes were the suspects caught for, what materials were seized</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="389" data-end="421">Cybercrime operation in 31 provinces <br>Interior Minister Ali Yerlikaya announced that simultaneous operations were carried out in 31 provinces against cybercrimes in the last 3 days and 190 suspects were caught within the scope of these operations. <br> <br> <br>Fraud and illegal betting crimes are at the forefront <br>The operations were carried out for crimes such as qualified fraud, illegal betting, online child obscenity and harassment. It was determined that the suspects defrauded citizens via social media with excuses such as product price, file fee, tax fee, car rental and deposit. It was also determined that some suspects were actively involved in illegal betting sites and mediated money transfers related to these sites. <br> <br>The Chief Public Prosecutor's Office and the Police Department worked in coordination <br>The investigation process was carried out under the coordination of the Chief Public Prosecutor's Office and the Cyber ​​Crimes Department of the General Directorate of Security. Many provincial police departments participated in the operations, which were carried out in a total of 31 provinces, including Erzurum, Konya, Eskişehir, Sakarya, Gaziantep, Ankara, Mersin, Burdur and Kocaeli. <br> <br>Accusations and seizures <br>The suspects were prosecuted for the crimes of 'aggravated fraud', 'illegal betting', 'establishing and being a member of an organization for the purpose of committing a crime', 'laundering assets obtained through crime' and 'fraud through the use of information systems'. Numerous digital materials, unlicensed guns and 10 cars worth approximately 15 million TL were seized during the operations. <br> <br>Emphasis on Cyber ​​Homeland <br>Yerlikaya said, 'As in the Black Homeland, we continue our fight against crime and criminals with our virtual patrols in the Cyber ​​Homeland with determination.' <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Disneyland Paris Massive 64GB Data Leak: Secret Plans and Engineering Documents Revealed</title>
<link>https://pursaklargundem.com/disneyland-paris-massive-64gb-data-leak-secret-plans-and-engineering-documents-revealed</link>
<guid>https://pursaklargundem.com/disneyland-paris-massive-64gb-data-leak-secret-plans-and-engineering-documents-revealed</guid>
<description><![CDATA[ A 64 GB archive of confidential data containing architectural drawings, engineering documents and behind-the-scenes footage of Disneyland Paris was leaked to the internet. The leak was first noticed on the IntelSonar cyber threat intelligence platform developed by Turkish software developers. The platform&#039;s data made a big splash in the cybersecurity world. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202506/image_870x_685599dce8f81.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 22 Jun 2025 12:47:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How did the Disneyland data leak happen, what documents were leaked, what&#039;s in the images, what is the risk of industrial espionage</media:keywords>
<content:encoded><![CDATA[<p></p>
<p>Highly confidential engineering data and projects belonging to Disneyland Paris in France were leaked to the public as a result of a cyber attack. The data archive, which is 64 GB in total, contains numerous documents and media files regarding the construction process of the park. It was learned that the leak occurred as a result of unauthorized access to the digital systems of a subcontractor company working on various theme areas of Disneyland Paris. <br> <br>Detailed plans leaked <br>The archive, which consists of 39,000 files in total, includes detailed architectural plans, engineering calculations, geological reports and safety standards for popular areas such as Frozen, Pirates of the Caribbean, Phantom Manor and Big Thunder Mountain. These documents contain critical information regarding the park's infrastructural security and trade secrets. <br> <br>Secret images are also among the files <br>The leaked documents include more than 4,000 photos and videos. The images are believed to be behind-the-scenes footage taken by Disneyland employees in areas protected by confidentiality agreements. The videos and photos show the construction phases of the theme park. <br> <br>Risk of industrial espionage <br>Experts say that such large-scale leaks pose not only a risk to brand security, but also a serious espionage opportunity for other companies operating in the amusement park sector. Disneyland Paris management has not yet made an official statement. <br> <br>In the focus of cybersecurity experts <br>Details about the incident can be accessed via the Intelsonar platform. Developed by local software developers, this platform stands out as one of the most prominent current solutions in the field of cyber threat intelligence. IntelSonar has become an important tool for the early detection and analysis of such leaks. <br> <br>Disneyland Paris Massive 64GB Data Leak: Secret Plans and Engineering Documents Revealed <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Remote Code Execution Vulnerability Detected in Roundcube: Plesk Quickly Releases Update</title>
<link>https://pursaklargundem.com/remote-code-execution-vulnerability-detected-in-roundcube-plesk-quickly-releases-update</link>
<guid>https://pursaklargundem.com/remote-code-execution-vulnerability-detected-in-roundcube-plesk-quickly-releases-update</guid>
<description><![CDATA[ Following the critical vulnerability (CVE-2025-49113) detected in the Roundcube Webmail system, Plesk released an update on June 5. This vulnerability, which can lead to remote code execution, can affect millions of servers. It is highly recommended to update. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202506/image_870x_6847fa6e826bc.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is the Roundcube vulnerability, which versions did Plesk update, what should servers that do not receive updates do, what is the Plesk lifecycle policy</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="397" data-end="449">Critical vulnerability discovered in Roundcube <br>A critical vulnerability that could allow remote code execution has been discovered in Roundcube Webmail versions prior to 1.5.10 and 1.6.x series prior to 1.6.11. The vulnerability has been identified as CVE-2025-49113. <br> <br> <br>Plesk intervened quickly <br>After this vulnerability was made public, Plesk released an update on June 5th to fix the security vulnerability. The update is expected to reach servers with Plesk panels automatically. However, users are strongly advised to make sure that the update is installed on their systems. <br> <br>Which versions are affected, which updates are required? <br>Plesk officials listed the updates that fixed the security vulnerability as follows: <br> <br>    Plesk Obsidian 18.0.70 Update 1 <br> <br>    Plesk Obsidian 18.0.69 Update 4 <br> <br>Users whose systems are older than these versions should update immediately. <br> <br>Alternative solution: Switching between servers <br>For users who cannot get the update directly, Plesk offers a server-to-server migration option, which allows users to switch to a more up-to-date Plesk version and avoid security vulnerabilities. <br> <br>Plesk lifecycle policy should be taken into consideration <br>It was emphasized that users should examine Plesk's Lifecycle Policy rules and develop long-term solutions for older versions that do not have update support. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Play Ransomware Group Sounds Alarm: Special Virus for Every Attack, Threat via Phone, Special Encryption for VMware!</title>
<link>https://pursaklargundem.com/play-ransomware-group-sounds-alarm-special-virus-for-every-attack-threat-via-phone-special-encryption-for-vmware</link>
<guid>https://pursaklargundem.com/play-ransomware-group-sounds-alarm-special-virus-for-every-attack-threat-via-phone-special-encryption-for-vmware</guid>
<description><![CDATA[ According to CISA’s June 4, 2025 report, the Play ransomware group has become one of the most active cyber threats of 2024. Targeting nearly 900 institutions, the group infiltrates systems using a newly disclosed vulnerability and now directly calls and threatens victims. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202506/image_870x_6845b677af178.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What security vulnerability is the Play group using, what attack method is followed in VMware systems, what is GRIXBA and what does it do, how are threats made to victims by phone</media:keywords>
<content:encoded><![CDATA[<p></p>
<p><strong>Play Group Targets 900 Institutions <br>According to the US Federal Bureau of Investigation (FBI), the Play ransomware group has targeted approximately 900 institutions to date. The group has not only increased the number of attacks, but also diversified its attack techniques. As of May 2025, it continues to carry out active attacks. <br> <br>New Attack Method: SimpleHelp Vulnerability <br>The vulnerability, coded CVE-2024-57727, was announced to the public on January 16, 2025. The Play group and its threat actors quickly began to exploit this vulnerability. The group, which infiltrated systems via a remote desktop access tool called SimpleHelp, is calling on organizations using this software to update. <br> <br>Ransomware Tailored to Each Victim <br>To avoid detection, the Play group recompiles its ransomware files for each attack, creating a unique virus for each victim. This method makes detection difficult for antivirus software, revealing the group's technical capabilities. <br> <br>New Threat Type: Telephone Intimidation <br>The group not only threatens victims by e-mail, but now also by calling them directly. They reach out to numbers belonging to different units of the institutions and put pressure on them by saying, 'We will leak your data'. Specially created e-mail addresses with the extensions "@gmx.de" or "@web.de" are used for each victim. <br> <br>VMware Systems Special Target <br>The Play group has developed a ransomware specifically designed for VMware ESXi hypervisor systems. It shuts down virtual machines and locks virtual machine files with AES-256 encryption. At the same time, they replace the welcome message in the system interface with a ransom note. <br> <br>Their Own Spyware: GRIXBA <br>The information-stealing software, called GRIXBA, is a special spy tool developed by the group. This software scans network structures, detects antivirus software and tries to hide under the identity of Zabbix 2023. <br> <br>What Should Institutions Do? <br>According to CISA's recommendations, the precautions to be taken are listed as follows: <br> <br>    Apply the CVE-2024-57727 patch immediately. <br> <br>    Enable multi-factor authentication, especially on VPN and email systems. <br> <br>    Review your network segmentation. <br> <br>    Check your offline backups. <br> <br>    Update your incident response plan. <br> <br>The Play group is no longer just a ransomware group, but an organized cybercrime network. They pose a serious threat with their rapid technical adaptation, rapid exploitation of new vulnerabilities, and psychological pressure methods. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Password Mistakes Made by Millions Put Cards at Risk: Don&amp;apos;t Use These Numbers</title>
<link>https://pursaklargundem.com/password-mistakes-made-by-millions-put-cards-at-risk-dont-use-these-numbers</link>
<guid>https://pursaklargundem.com/password-mistakes-made-by-millions-put-cards-at-risk-dont-use-these-numbers</guid>
<description><![CDATA[ In today&#039;s world where credit card usage is increasing, simple and predictable passwords leave users vulnerable to fraudsters. Experts emphasize that numbers such as &#039;1234&#039; and birth year should definitely not be included in passwords. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_682f2654cba87.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What mistakes are made when choosing a card password, what are the riskiest password combinations, what experts recommend for password security, how do automatic software work</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="383" data-end="439">As card usage increases, security risks also increase <br>The usage rate of credit cards is increasing day by day. Especially the spread of online shopping and contactless payment systems brings cards to the agenda in terms of both convenience and cyber attacks. <br> <br> <br>Card PINs are the target of cyber attacks <br>In today’s world where the purchasing power of cash has decreased, credit cards have become an indispensable part of daily life. This makes the security of card passwords more important than ever. However, experts say that the majority of users make serious password mistakes. <br> <br>The most preferred passwords are the first thing hackers try <br>According to cybersecurity research, the most preferred 4-digit passwords include "1234", "0000", "1111" and easily guessable numbers such as your birth year. These types of combinations are among the first to be tried by scammers. Thanks to automatic software, such passwords can be cracked in seconds. <br> <br>Secure password advice from experts <br>Experts recommend using random and difficult-to-guess number combinations when setting a card password. It is also critical for security that the password is not the same as the phone PIN and is changed at regular intervals. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>iPhones at risk of remote hacking due to AirPlay vulnerability</title>
<link>https://pursaklargundem.com/iphones-at-risk-of-remote-hacking-due-to-airplay-vulnerability</link>
<guid>https://pursaklargundem.com/iphones-at-risk-of-remote-hacking-due-to-airplay-vulnerability</guid>
<description><![CDATA[ Apple has warned iPhone users about a critical security vulnerability called &#039;AirBorne&#039;. Nearly 23 vulnerabilities discovered in the AirPlay feature can lead to devices being hijacked through zero-click attacks. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_682f252fbf88e.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is the iPhone AirPlay vulnerability, what does zero-click attack mean, what Apple wants its users to do, how to disable AirPlay feature</media:keywords>
<content:encoded><![CDATA[<p><strong>Critical security warning from Apple <br>Technology company Apple has made a statement about a major security vulnerability that directly affects iPhone users. According to the company's warning, critical vulnerabilities detected in the AirPlay feature can make users' devices vulnerable to cyber attacks. <br> <br>Nearly 23 vulnerabilities were detected <br>A study by cybersecurity firm Oligo found 23 different security vulnerabilities in Apple's AirPlay protocol. Most of these vulnerabilities are found in the AirPlay Software Development Kit (SDK), which is used in devices made compatible with AirPlay by third-party manufacturers. <br> <br>Devices can be hijacked without user interaction <br>Gal Elbaz, CTO of Oligo, stated that the discovered vulnerabilities enable 'zero-click' attacks. This can allow hackers to infiltrate devices, install malware or steal data without the user taking any action. It was emphasized that vulnerabilities are often difficult to patch, and some devices may never be patched. <br> <br>Precautions to be taken from Apple <br>To mitigate these security risks, Apple recommends users update their devices to the latest iOS version immediately and disable AirPlay. It is also considered an important security step to only receive files from trusted contacts over AirPlay. <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Cybersecurity expert Abu Bakr Bastama: &amp;apos;RD Gateway vulnerability could grant attackers full access&amp;apos;</title>
<link>https://pursaklargundem.com/cybersecurity-expert-abu-bakr-bastama-rd-gateway-vulnerability-could-grant-attackers-full-access</link>
<guid>https://pursaklargundem.com/cybersecurity-expert-abu-bakr-bastama-rd-gateway-vulnerability-could-grant-attackers-full-access</guid>
<description><![CDATA[ The critical vulnerability, coded CVE-2025-21297, targets the RD Gateway component used in Windows Server systems. Cybersecurity researcher Ebubekir Bastama stated that if the vulnerability is successfully exploited, &quot;attackers could gain full control over the system.&quot; ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_682b235ad4d70.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords></media:keywords>
<content:encoded><![CDATA[<p><strong>Critical vulnerability in Microsoft's RD Gateway component <br>Microsoft’s Remote Desktop Gateway (RD Gateway), a remote desktop access service, is under serious threat due to a newly discovered vulnerability, CVE-2025-21297. The vulnerability, identified by security researchers, allows attackers to execute malicious code by corrupting system memory via a race condition during server startup. <br> <br>Technical details and attack vector <br>The vulnerability in question is caused by a use-after-free (UAF) error in the CTsgMsgServer::GetCTsgMsgServerInstance function in the aaedge.dll component. When multiple threads simultaneously access this function during RD Gateway startup, this leads to incorrect rewriting of the m_pMsgSvrInstance pointer due to lack of synchronization. This can lead to memory corruption and allow attackers to manipulate this process to execute code remotely. <br> <br>Abu Bakr Bastama: 'Server control may fall into the hands of the attacker' <br>Cybersecurity researcher Ebubekir Bastama drew attention to the seriousness of the security vulnerability and made the following statements: <br>"If such vulnerabilities are not addressed quickly, they can have devastating effects, especially on large systems. A vulnerability such as CVE-2025-21297, when exploited, can give an attacker full control over the RD Gateway server. This poses a serious threat to corporate systems. <br> <br>Extent of risk and affected systems <br>The vulnerability is categorized as 'high' risk with a CVSS score of 8.1. Exploitation of the vulnerability involves a complex process involving 9-step heap collisions, but if the attack is successful, it can take complete control of the RD Gateway servers. The vulnerability affects the following Windows Server versions: <br> <br>    Windows Server 2016 <br> <br>    Windows Server 2019 <br> <br>    Windows Server 2022 <br> <br>    Windows Server 2025 <br>    (Including Core and Standard structures) <br> <br>Corporate networks are under threat <br>This vulnerability is critical because RD Gateway is used to provide secure remote access to corporate networks. If exploited, unauthorized access to the corporate network could be gained and serious security breaches such as data leakage or system crashes could occur. <br> <br>Security updates from Microsoft <br>Microsoft has released several security updates to address the vulnerability as of May 2025. The relevant patch codes for the affected systems are as follows: <br> <br>    Windows Server 2016 → KB5050011 <br> <br>    Windows Server 2019 → KB5050008 <br> <br>    Windows Server 2022 → KB5049983 <br> <br>    Windows Server 2025 → KB5050009 <br> <br>Urgent call to action for institutions <br>Experts recommend that users immediately apply the relevant patches and allow access to RD Gateway systems only to trusted IP addresses. It is also stated that RD Gateway logs should be reviewed regularly for unusual activity. <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Zero&#45;Click Vulnerability in Apple Calendar App: System Can Be Hijacked Without Ever Clicking</title>
<link>https://pursaklargundem.com/zero-click-vulnerability-in-apple-calendar-app-system-can-be-hijacked-without-ever-clicking</link>
<guid>https://pursaklargundem.com/zero-click-vulnerability-in-apple-calendar-app-system-can-be-hijacked-without-ever-clicking</guid>
<description><![CDATA[ A critical vulnerability has been discovered in the Calendar app on Apple&#039;s macOS and iOS systems that allows system control without requiring user interaction. The vulnerability, identified as CVE-2022-46723, works through malicious calendar invites and, according to cybersecurity researcher Ebubekir Bastama, can still be actively exploited on devices that have not been updated. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_682b006b75d04.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is the zero-click vulnerability, which devices does CVE-2022-46723 affect, how does the Apple Calendar vulnerability work, what happens if the update is not made</media:keywords>
<content:encoded><![CDATA[<p><strong>Critical vulnerability discovered in Apple's Calendar app <br>The vulnerability, coded CVE-2022-46723, resides in Apple's Calendar application. The vulnerability allows attackers to write, delete files, and gain full system control without requiring any user interaction on the target system simply by sending a malicious calendar invitation. <br> <br>It works with Zero-Click feature <br>The vulnerability in question is one of the types of attacks called 'zero-click', which does not require any interaction from the user. Cybersecurity researcher Ebubekir Bastama, who stated that this vulnerability can be triggered with a malicious .ics calendar file, states that for the vulnerability to work, it is enough for the target to automatically accept incoming calendar invitations. <br> <br>Open old but still dangerous <br>According to Ebubekir Bastama, although this vulnerability was discovered in 2022 and a fix was released by Apple, this vulnerability can still be actively exploited on some devices that have not been updated. Users who use older iOS and macOS versions in particular are at serious risk. <br> <br>Which systems are affected? <br>This vulnerability is valid for Apple's macOS and iOS operating systems. A similar vulnerability has not yet been detected on Windows and Android systems. Devices that accept automatic calendar invites are particularly targeted. <br> <br>What can attackers do? <br>By exploiting the vulnerability, attackers can perform the following actions: <br> <br>    Writing and deleting operations to the file system <br> <br>    Gaining remote code execution (RCE) privilege <br> <br>    Bypassing Gatekeeper via SMB connections <br> <br>    Access personal photos using iCloud sync <br> <br>All these operations can be performed without any confirmation from the user. <br> <br>How to protect? <br>Ebubekir Bastama emphasizes that devices should be kept up to date to protect against such attacks. In addition, the "automatic invitation acceptance" feature should be turned off in the Calendar application, invitations from unknown people should not be opened, and the file system should be checked regularly. <br> <br>Warning: Unupdated devices are at risk <br>Bastama states that detecting and fixing such vulnerabilities before they become widespread prevents major data leaks, and that devices that have not received updates may still be actively affected by this vulnerability. <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Ransomware That Secretly Infiltrates Processor: &amp;apos;Formatting Is Not The Solution&amp;apos;</title>
<link>https://pursaklargundem.com/ransomware-that-secretly-infiltrates-processor-formatting-is-not-the-solution</link>
<guid>https://pursaklargundem.com/ransomware-that-secretly-infiltrates-processor-formatting-is-not-the-solution</guid>
<description><![CDATA[ Rapid7 expert Christiaan Beek has developed a ransomware that can remain active even after the operating system is reinstalled, by exploiting a critical vulnerability in AMD Zen architecture. This new generation software, which manages encryption at the hardware level, can bypass all traditional security measures and is causing great concern in the cybersecurity world. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_68259fc989d2e.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How does ransomware work at the CPU level, what is the vulnerability in AMD processors, why formatting is not a solution, why hardware security has become critical</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="466" data-end="509">Ransomware moves to hardware level <br>The world’s first CPU-level ransomware has emerged. Developed by Rapid7’s director of threat analytics, Christiaan Beek, the conceptual malware exploits a vulnerability discovered in AMD’s Zen architecture that allows attackers to load unauthorized microcode onto processors. <br> <br> <br>Unsigned microcode uploading made possible <br>Google security researchers previously identified a vulnerability that allowed unsigned microcode patches to be loaded into AMD Zen 1 through Zen 4 processors. It was later discovered that this was also the case with the Zen 5 series. Beek used these vulnerabilities to develop a prototype ransomware that operates at the hardware level and manages encryption operations. <br> <br>It remains effective even after the operating system is reinstalled. <br>The software developed by Beek does not lose its effect even if the system is formatted. Because the software works directly on the microcode level of the processor. Although it is stated that the code will not be made public, the fact that such a software has been developed shows that similar attacks can be carried out by others. <br> <br>Ransomware schemes inside UEFI exposed <br>In his analysis, Beek also referred to chat logs belonging to the Conti ransomware gang, which were leaked in 2022. In these logs, gang members discussed the idea of ​​​​inserting the ransomware into UEFI and aimed to keep the system encrypted even if Windows was reinstalled. <br> <br>Hardware security comes to the fore <br>Christiaan Beek states that hardware security should be at the center of cyber defense strategies following the development. According to him, unless the vulnerabilities at the CPU and firmware level are closed, strong passwords and software solutions will be insufficient. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Next&#45;Gen Threat: RTX 5090 Can Crack 8&#45;Digit Passwords in Hours</title>
<link>https://pursaklargundem.com/next-gen-threat-rtx-5090-can-crack-8-digit-passwords-in-hours</link>
<guid>https://pursaklargundem.com/next-gen-threat-rtx-5090-can-crack-8-digit-passwords-in-hours</guid>
<description><![CDATA[ Nvidia&#039;s most powerful graphics card, the RTX 5090, achieves striking results not only in games but also in the field of cybersecurity. According to tests, this graphics card can crack simple 8-character passwords in just 3 hours. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_68246658c5d67.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How many hours does it take for the RTX 5090 to crack a password, how does the password cracking time change, why are complex passwords more secure, how are graphics cards used in password cracking</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="343" data-end="390">Striking results on password security <br>In tests conducted by cybersecurity firm Hive Systems, the password cracking performance of the Nvidia RTX 5090 graphics card yielded remarkable results. In the tests, it was stated that an 8-character password consisting of only numbers could be cracked in approximately 3 hours by a single RTX 5090 card. This indicates a 33% speed increase compared to the previous generation RTX 4090. <br> <br> <br>It can be cracked in 15 minutes with 12 graphics cards <br>In the tests, it was found that when 12 RTX 5090s were used, the same password could be cracked in just 15 minutes. The company aims to measure the effect of GPUs on password cracking with such studies. However, in this case, it is not the passwords that are cracked directly, but encrypted versions called hashes. <br> <br>How to crack password hashes? <br>Hashes allow user passwords to be stored in encrypted form rather than directly. In a data breach, hackers can seize these hashes and try all possible character combinations to find the right match. Graphics cards have a great advantage in this process because they can perform multiple operations in parallel. <br> <br>As complexity increases, time increases <br>An 8-character password consisting of only lowercase letters can take about 3 weeks to crack. If the number is a combination of uppercase and lowercase letters, this period can be extended to 62 years, and if symbols are included, it can be extended to 164 years. However, it is stated that the RTX 5090 is twice as fast as the previous model in cracking complex passwords. <br> <br>There is no danger unless the database is compromised <br>Hive Systems said these tests were only intended to show the weakness of passwords. For a real threat to occur, hackers would first need to obtain a database of password hashes. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​espionage with fake base stations in Istanbul: MİT caught foreign network red&#45;handed</title>
<link>https://pursaklargundem.com/cyber-espionage-with-fake-base-stations-in-istanbul-mit-caught-foreign-network-red-handed</link>
<guid>https://pursaklargundem.com/cyber-espionage-with-fake-base-stations-in-istanbul-mit-caught-foreign-network-red-handed</guid>
<description><![CDATA[ The National Intelligence Organization has caught a foreign spy network that set up fake base stations using rented vehicles in Istanbul, sending fake messages to citizens’ mobile phones and transferring the information to servers based in China. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_681f2dac7f992.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How does a fake base station work? How did MIT detect the network? What kind of information did the captured data reach? How was data transferred to the China-based server</media:keywords>
<content:encoded><![CDATA[<p><strong>Cyber ​​attack with fake base stations <br>The National Intelligence Organization (MIT) caught a foreign network red-handed conducting cyber espionage activities by setting up fake base stations using Chinese-made devices placed in rented vehicles in and around Istanbul. According to the details of the operation, these fake base stations pretended to be GSM operators and sent messages to citizens’ mobile phones that appeared to be sent on behalf of the institutions. <br> <br>They collected data with fake messages <br>It was stated that the messages used by the network were aimed at misleading citizens, especially with content that included payment requests. It was determined that fraud and personal data collection were the purposes behind the fake SMSs sent. <br> <br>Data transferred to China, used in phishing attacks <br>It was determined that the collected user information and communication data were transferred to a server based in China. It was later determined that this data was used in targeted phishing attacks via a foreign-origin mobile application. <br> <br>Coordinated operation from MIT <br>The network in question was caught red-handed in an operation conducted after the intelligence was obtained. A statement is awaited from the official authorities regarding the details of the operation. <br> <br>Source: Beykozun Sesi</strong></p>
<p></p>]]> </content:encoded>
</item>

<item>
<title>Young People Targeted with Promise of Easy Money: Social Media Scams Are Exploding</title>
<link>https://pursaklargundem.com/young-people-targeted-with-promise-of-easy-money-social-media-scams-are-exploding</link>
<guid>https://pursaklargundem.com/young-people-targeted-with-promise-of-easy-money-social-media-scams-are-exploding</guid>
<description><![CDATA[ Digital fraud methods that are rapidly increasing on social media platforms target young people in particular with fake investment advice and phishing tactics. Experts emphasize that such attacks have psychological effects beyond economic losses, while law enforcement authorities warn users to be careful. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x_681ca47d8eb42.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the most common methods of digital fraud, why are young people targeted, how can precautions be taken against social media fraud, what warnings do the police give on this issue</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="466" data-end="512">Social media scam raises alarm <br>There has been a significant increase in digital fraud activities carried out on social media platforms in recent months. In complaints made to police departments, fake investment advice, promises of easy money and links requesting identification information are particularly prominent. <br> <br> <br>Young users have become the main target <br>The group most targeted by scammers is young people. According to experts, young users who are motivated by financial gain can easily be lured by promises of getting rich quickly. Convincing scenarios created through fake accounts cause many people to fall into the trap. <br> <br>Experts warn of psychological effects <br>Cybersecurity experts say that digital fraud cases are not limited to financial losses, but also leave serious psychological effects on victims. It is stated that after such cases, victims experience shame, loss of self-confidence and trust issues. <br> <br>Warning from the police to be careful <br>Police authorities are warning users not to trust messages from people they do not know, not to click on unknown links, and not to share their personal information in any way. It is also reported that active investigations into fraudulent activities carried out on social media are ongoing. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>More than half of cyberattacks target the manufacturing and finance sectors</title>
<link>https://pursaklargundem.com/more-than-half-of-cyberattacks-target-the-manufacturing-and-finance-sectors</link>
<guid>https://pursaklargundem.com/more-than-half-of-cyberattacks-target-the-manufacturing-and-finance-sectors</guid>
<description><![CDATA[ According to IBM X-Force’s 2025 Threat Intelligence Index, 56 percent of global cyberattacks affect the manufacturing industry and finance and insurance sectors. This data reveals that threats to digital infrastructures are concentrated in areas that form the backbone of economic functioning. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x580_6814a47a5044c.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Which sectors are most targeted by cyber attacks, why is the manufacturing industry targeted, what is the financial sector&#039;s situation against cyber threats, what are the attack percentages according to the 2025 IBM X-Force report</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="411" data-end="469">Most attacks target critical economic sectors <br>The 2025 Threat Intelligence Index published by IBM X-Force revealed which areas are most affected by cyberattacks. According to the report, 40 percent of the attacks recorded globally throughout 2024 targeted the manufacturing industry, while 16 percent targeted finance and insurance institutions. <br> <br> <br>Production and financial infrastructures are the main targets <br>According to the data in the index, more than half of the attacks are aimed at directly disrupting production lines and systems that ensure cash flow. This poses serious risks to both supply chains and economic security. <br> <br>Cyber ​​threats are concentrated in strategic areas <br>According to experts, the focus of these attacks is not only financial gain but also operational disruption. In particular, the halting of production systems can cause companies to lose millions of dollars. Attacks on finance and insurance infrastructures increase the risk of user data theft and fraud. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Deepfake scam hits $10 billion globally: CEO voices make big haul</title>
<link>https://pursaklargundem.com/deepfake-scam-hits-10-billion-globally-ceo-voices-make-big-haul</link>
<guid>https://pursaklargundem.com/deepfake-scam-hits-10-billion-globally-ceo-voices-make-big-haul</guid>
<description><![CDATA[ According to McAfee and the World Economic Forum&#039;s 2024 data, deepfake technology-based frauds caused more than $10 billion in losses worldwide as of 2025. While serious losses were experienced especially in the finance, insurance and public sectors, companies in Türkiye have also begun to be targeted with similar methods. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202505/image_870x580_6814a6235c71f.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 15:07:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How much has the global cost of deepfake fraud been, which sectors have been most affected, are there any companies in Türkiye that have been scammed using this method, what precautions do experts recommend</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="477" data-end="532">Annual cost of deepfake attacks breaks record <br>According to the latest reports published by the World Economic Forum and McAfee, the global cost of deepfake scams has exceeded $10 billion by 2025. Fake audio and video generated by artificial intelligence technologies are used by fraudsters to target internal company security vulnerabilities. <br> <br> <br>Money transfer instructions are given by imitating CEOs' voices <br>According to the report, one of the most common methods is to imitate the voices of company CEOs using artificial intelligence to give fake money transfer orders to employees. Such cases have caused serious financial losses, especially in finance, insurance and large-scale public institutions. This breaking of the chain of trust within the company multiplies the impact of the attacks. <br> <br>Companies in Türkiye were also targeted <br>Deepfake scams have also had an impact in Türkiye. Some local companies have made transfers worth hundreds of thousands of liras through employees who were guided by fake voice recordings. The incidents were usually carried out through internal correspondence and voice calls. <br> <br>Call for verification from experts <br>Cybersecurity experts warn that instructions received via voice or video should always be verified via a second communication channel, and that it is critical for companies to invest in AI-powered fraudulent content detection systems to prevent such attacks. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Critical warning from experts: They are secretly entering computers with the appearance of &amp;apos;DeepSeek&amp;apos;</title>
<link>https://pursaklargundem.com/critical-warning-from-experts-they-are-secretly-entering-computers-with-the-appearance-of-deepseek</link>
<guid>https://pursaklargundem.com/critical-warning-from-experts-they-are-secretly-entering-computers-with-the-appearance-of-deepseek</guid>
<description><![CDATA[ Kaspersky experts have warned users about fake software spreading under the name &#039;DeepSeek R1&#039;. The malware, which spreads through fake websites and Google ads, aims to steal sensitive data. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202506/image_870x_684c1992e9f4a.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 15 Jun 2025 14:47:38 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>how fake DeepSeek spreads, what is BrowserVenom malware, how to protect yourself from DeepSeek attack, who is the target of the malware</media:keywords>
<content:encoded><![CDATA[<p>Kaspersky Global Research and Analysis Team (GReAT) has uncovered a new malware campaign that infiltrates computers using the fake 'DeepSeek R1 Large Language Model' (LLM) implementation. <br> <br> <br>Redirecting to a Fake Site with Google Ads <br> <br>Attackers use Google ads to lure users to fake sites that mimic the real DeepSeek platform. When users search for “deepseek r1,” the ad link is redirected to a decoy site. <br> <br>Fake Apps and Trojans Are Used <br> <br>The fake site targets Windows operating system users and offers the user to download offline tools such as Ollama or LM Studio. During the download process, the user is tricked using a CAPTCHA test and then the malware is installed on the computer. <br> <br>Bypassing Windows Defender Protection <br> <br>This software bypasses Windows Defender's protection with special algorithms and settles into the system. However, the installation requires the user to have administrative rights. This malware cannot infect the systems of users who do not have administrative rights. <br> <br>User Data At Risk <br> <br>Dubbed 'BrowserVenom', the malware redirects users' web browsers to a proxy server controlled by attackers, stealing users' sensitive browser data and continuously monitoring their activities. <br> <br>Cyber ​​Security Advice from Experts <br> <br>Kaspersky experts recommend users to take the following precautions: <br> <br>    Checking the accuracy of website addresses, <br> <br>    Downloading offline AI tools only from official sources, <br> <br>    Using Windows in profiles without administrative privileges, <br> <br>    Using reliable cybersecurity solutions. <br> <br>While Kaspersky Security Researcher Lisandro Ubiedo pointed out the advantages of using AI applications offline, he noted that such malware can pose a serious threat if the right precautions are not taken. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>SS7 exploit sells for $5,000 on the black market: Cyber ​​threat actor&amp;apos;s communications revealed step by step</title>
<link>https://pursaklargundem.com/ss7-exploit-sells-for-5000-on-the-black-market-cyber-threat-actors-communications-revealed-step-by-step</link>
<guid>https://pursaklargundem.com/ss7-exploit-sells-for-5000-on-the-black-market-cyber-threat-actors-communications-revealed-step-by-step</guid>
<description><![CDATA[ A critical vulnerability in the Signaling System No.7 (SS7) infrastructure was put up for sale on the dark web for $5,000. Exploit developer and threat intelligence analyst Doğukan Çalışkan, posing as a buyer, conducted a technical analysis that revealed the method used in cybercrime networks in full detail. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202506/image_870x_684d6ffa71731.webp" length="49398" type="image/jpeg"/>
<pubDate>Sat, 14 Jun 2025 16:02:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How is the SS7 vulnerability detected, how are vulnerabilities marketed on the dark web, why are SIP ports targeted, how is the RCE vulnerability exploited?</media:keywords>
<content:encoded><![CDATA[<p></p>
<p><strong>What is SS7 and why is it important? <br>SS7 (Signaling System No. 7) is a signaling protocol that handles critical operations such as call origination, SMS routing, and roaming information sharing among telephone operators worldwide. However, structural vulnerabilities in this system that have persisted for years have allowed attacks, particularly location tracking, call routing, and authentication bypassing. <br>  <br>Who is Dogukan Caliskan? <br>Cyber ​​threat intelligence analyst and exploit developer Doğukan Çalışkan discovered the vulnerability on the dark web. Çalışkan contacted the threat actor directly as the recipient and technically recorded the process. <br>  <br>SS7 exploit being sold on the Darkweb <br>In a post on dark web forums in June 2025, a threat actor offered the SS7 vulnerability for sale for $5,000. The post also included screenshots and nmap scans of a device on which the vulnerability was used. It was observed that the SIP (port 5060) service was open on the device in question and that there were services that processed the SS7 protocol. <br>  <br>Contact was established by pretending to be a buyer <br>Çalışkan contacted the threat actor via the TOX messaging app. Initially, no direct exploit was requested; instead, evidence was requested to determine if it was a scam. The actor shared data showing SS7-related traffic on a device and device scan results. <br>  <br>There was a striking phrase in the actor's messages: 'This should still be turned into a working RCE (remote code execution exploit)'. This means that the exploit being sold would need to be developed by a technical processor in its raw form. <br>  <br>What do the technical data shown reveal? <br>The actor stated that there was an Apache server running on devices with an open SIP port and a PHP-based web application was targeted. On these systems, vulnerabilities of services running on CentOS were scanned and it was claimed that there was a potential for RCE. <br>  <br>Among the data presented, the following stood out: <br>  <br>    Wappalyzer analysis screen <br>  <br>    Port scan results with Nmap <br>  <br>    SS7 traffic monitored with sngrep and ngrep <br>  <br>    Details of services running on the target device <br>  <br>The actor also said that credentials for the Asterisk PBX could be accessed, which could allow for control over processes such as call forwarding. <br>  <br>Sales method and use of escrow system <br>The seller stated that they would only work through escrow systems to prevent fraud. In such systems, money is held in an escrow account until the product is verified after payment is made. When Çalışkan requested proof before the transaction, the threat actor provided various technical screenshots. <br>  <br>Potential threats of SS7 vulnerabilities <br>Vulnerabilities in the SS7 infrastructure can be exploited by malicious individuals for the following purposes: <br>  <br>    Redirection of SMS messages <br>  <br>    Eavesdropping on calls or transferring them to another device <br>  <br>    Determining the current location of the target person <br>  <br>    Bypassing two-factor authentication <br>  <br>However, the most important element that draws attention here is that the actor did not directly make this vulnerability operational, but only provided the necessary technical infrastructure. This suggests that the final use of the vulnerability was left to more advanced groups. <br>  <br>Techniques and tools used <br>The tools and methods that stand out in the incident reported by Çalışkan are as follows: <br>  <br>    Targeting with search engines such as Shodan and Fofa <br>  <br>    Port scanning and service detection with nmap <br>  <br>    SIP and SS7 traffic monitoring with sngrep, ngrep <br>  <br>    Software version detection with Wappalyzer <br>  <br>    Web vulnerability analysis and potential RCE detection <br>  <br>On the radar of advanced groups <br>As the threat actor noted, these types of vulnerabilities are often the foundation of infrastructures built not for non-technical users but for ransomware groups, advanced persistent threat (APT) teams, and rogue intelligence networks. <br>  <br>Infrastructure vulnerabilities such as the SS7 vulnerability can target not only individual users but also corporate systems, public communications, and critical communications infrastructures. <br>  <br>  <br>  <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Türkiye&amp;apos;s First Cyber ​​Security Law Entered Into Force</title>
<link>https://pursaklargundem.com/turkiyes-first-cyber-security-law-entered-into-force</link>
<guid>https://pursaklargundem.com/turkiyes-first-cyber-security-law-entered-into-force</guid>
<description><![CDATA[ Türkiye’s cyber defense infrastructure is being strengthened with the Cyber ​​Security Law No. 7545 published in the Official Gazette. The new regulation protects public institutions and critical infrastructures against cyber threats and also covers certification and auditing processes. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67da4ced5936a.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What does Türkiye&#039;s cybersecurity law cover, what are the penalties for cyberattacks, how will critical infrastructures be protected, how will cybersecurity certification be implemented</media:keywords>
<content:encoded><![CDATA[<p>Turkey has taken an important step to increase its security in the digital world. The Cyber ​​Security Law No. 7545 was published in the Official Gazette dated March 19, 2025 and entered into force. The law provides for national measures against cyber threats and introduces new security standards for public institutions and critical infrastructures. <br> <br>New Regulations Strengthening Cyber ​​Security <br> <br>The purpose of the law was determined as ensuring Türkiye's national security in cyberspace, protecting the public and private sectors from cyber threats, and creating a national cybersecurity strategy. Within the scope of the regulation, a Cybersecurity Board will be established and the Cybersecurity Presidency will be authorized. <br> <br>The scope of the law includes public institutions, critical infrastructures, professional organizations, private companies and individuals. However, military and intelligence activities are excluded from this regulation. <br> <br>Broad Powers for the Cyber ​​Security Presidency <br> <br>According to the new regulation, the Cyber ​​Security Presidency; <br> <br>    To ensure the protection of critical infrastructures against cyber attacks, <br>    Conducting cyber security audits for public institutions and critical infrastructures, <br>    Conduct studies to prevent cyber attacks by collecting cyber threat intelligence, <br>    He/she will manage certification and authorization processes in the field of cyber security. <br> <br>Severe Penalties for Cyber ​​Crimes <br> <br>The law also stipulates severe penalties related to cybersecurity. Those who organize cyberattacks on critical infrastructure will be sentenced to 8 to 12 years in prison, and those who spread leaked data will be sentenced to 10 to 15 years in prison. Additionally, those who spread fake news about data leaks will be sentenced to 2 to 5 years in prison. <br> <br>Audit and Certification Process Begins <br> <br>According to the law, companies and software providers operating in the field of cybersecurity will be subject to an authorization and certification process. Local and national software and hardware to be used in public institutions will be encouraged. <br> <br>According to experts, the new law will strengthen Türkiye's cybersecurity infrastructure and provide more effective protection against cyber threats at the national level. <br> <br>Here is the full CYBER SECURITY LAW published <br> <br>Aim <br> <br> <br> <br>ARTICLE 1 - (1) The purpose of this Law is to identify and eliminate existing and potential internal and external threats against all elements constituting the national power of the Republic of Turkey in cyberspace, to determine the principles for reducing the possible effects of cyber incidents, to make the necessary arrangements for the protection of public institutions and organizations, professional organizations with the status of public institutions, real and legal persons and organizations without legal personality against cyber attacks, to determine strategies and policies to strengthen the cyber security of the country and to regulate the principles for the establishment of the Cyber ​​Security Board. <br> <br> <br> <br>Scope <br> <br> <br> <br>ARTICLE 2 - (1) This Law covers public institutions and organizations, professional organizations with the status of public institutions, real and legal persons and organizations without legal personality that exist, operate and provide services in cyberspace. <br> <br> <br> <br>(2) Intelligence activities carried out in accordance with the Law on Police Duties and Authorities No. 2559, dated 4/7/1934, the Coast Guard Command Law No. 2692, dated 9/7/1982, the Law on the Organization, Duties and Authorities of the Gendarmerie No. 2803, dated 10/3/1983, and the activities carried out in accordance with the Law on State Intelligence Services and the National Intelligence Organization No. 2937, dated 1/11/1983, and the Turkish Armed Forces Internal Service Law No. 211, dated 4/1/1961 are outside the scope of this Law. <br> <br> <br> <br>Definitions and abbreviations <br> <br> <br> <br>ARTICLE 3 - (1) In this Law; <br> <br> <br> <br>a) Hosting: Keeping information systems in an external data center, <br> <br> <br> <br>b) President: President of Cyber ​​Security, <br> <br> <br> <br>c) Presidency: Cyber ​​Security Presidency, <br> <br> <br> <br>d) Information systems: Hardware, software, systems and all other active or passive components used in the presentation of all kinds of services, transactions and data provided through information and communication technologies, <br> <br> <br> <br>d) Critical infrastructure: Infrastructures that host information systems that may lead to loss of life, large-scale economic damage, security vulnerabilities or disruption of public order when the confidentiality, integrity or accessibility of the information/data they process is compromised. <br> <br> <br> <br>e) Critical public service: A service that is essential for the maintenance of national, social or economic activities and that is provided with a monopoly or limited substitution throughout the country, and whose interruption or damage may have a significant impact on national security, the social or economic well-being of the country, public order or health, or the provision of other services. <br> <br> <br> <br>f) Cyber ​​security: The totality of activities that include protecting the information systems that constitute the cyberspace from attacks, ensuring the confidentiality, integrity and accessibility of the data processed in this environment, detecting attacks and cyber incidents, activating reaction and alarm mechanisms against these detections and then returning them to the state before the cyber incident, <br> <br> <br> <br>g) Cyber ​​incident: Violation of confidentiality, integrity or accessibility of information systems or data, <br> <br> <br> <br>g) Cyber ​​attack: Intentional actions taken against persons or information systems anywhere in cyberspace in order to eliminate the confidentiality, integrity or accessibility of information systems in cyberspace and the data processed by these systems, <br> <br> <br> <br>h) Cyber ​​threat: Potential dangers that may cause violations of confidentiality, integrity or accessibility of information systems and data contained in or processed by these systems, <br> <br> <br> <br>i) Cyber ​​threat intelligence: Information gathered, transformed, analyzed, interpreted or enriched about current or potential cyber threats and cyber attacks against assets in cyberspace, <br> <br> <br> <br>i) Cyberspace: The environment consisting of all information systems that are directly or indirectly connected to the Internet, electronic communication or computer networks and the networks that connect them to each other, <br> <br> <br> <br>j) SOME: Cyber ​​incident response team, <br> <br> <br> <br>k) Asset: All information and information processing facilities that contain data that can be transferred through communication and that are available in electronic or physical environments, the personnel who use or carry the data, and the physical spaces that host the data, <br> <br> <br> <br>l) Vulnerability: Weaknesses and security gaps of assets in cyberspace that can be exploited by any cyber threat, <br> <br> <br> <br>expresses. <br> <br> <br> <br>Basic principles <br> <br> <br> <br>ARTICLE 4 - (1) The basic principles in ensuring cyber security are as follows: <br> <br> <br> <br>a) Cyber ​​security is an integral part of national security. <br> <br> <br> <br>b) The main goal is to protect critical infrastructure and information systems and create a secure cyberspace. <br> <br> <br> <br>c) Studies on cyber security are carried out on the basis of institutionality, continuity and sustainability. <br> <br> <br> <br>c) It is essential that cyber security measures are implemented throughout the entire life cycle of services and products. <br> <br> <br> <br>d) In studies aimed at ensuring cyber security, local and national products are primarily preferred. <br> <br> <br> <br>e) All public institutions and organizations, real and legal persons are responsible for implementing cyber security policies and strategies and taking necessary measures to prevent cyber attacks or reduce their effects. <br> <br> <br> <br>f) Accountability is essential in the execution of cyber security processes. <br> <br> <br> <br>g) Cyber ​​security policy and strategy development studies are carried out with a continuous improvement approach. <br> <br> <br> <br>g) Studies aimed at increasing the capability and capacity of qualified human resources in the field of cyber security are encouraged. <br> <br> <br> <br>h) It is aimed to spread cyber security culture throughout society. <br> <br> <br> <br>i) The principles of the rule of law, fundamental human rights and freedoms and the protection of privacy are accepted as fundamental principles. <br> <br> <br> <br>CHAPTER TWO <br> <br> <br> <br>Duties, Powers, Responsibilities, Audits and Cyber ​​Security Board <br> <br> <br> <br>Duties of the Presidency <br> <br> <br> <br>ARTICLE 5 - (1) The duties of the Presidency are as follows: <br> <br> <br> <br>a) To perform the duties included in the relevant legislation. <br> <br> <br> <br>b) To carry out activities to increase the cyber resilience of critical infrastructures and information systems, to protect them against cyber attacks, to detect cyber attacks, to prevent possible attacks and to reduce or eliminate their effects, to conduct or have conducted vulnerability and penetration tests and risk analyses for assets, to combat cyber threats, to obtain, create and share cyber threat intelligence, and to conduct malware analysis activities. <br> <br> <br> <br>c) To determine critical infrastructures and the institutions and locations to which they belong. <br> <br> <br> <br>ç) To ensure that the inventory of all assets of public institutions and organizations and critical infrastructures, including their data inventory, is kept and that risk analysis is carried out for the assets, and to take or have taken security measures according to the criticality of the assets of public institutions and organizations and critical infrastructures. <br> <br> <br> <br>d) To establish, have established and supervise SOMEs, to work to determine and increase the maturity levels of SOMEs, to measure the cyber incident response capabilities of SOMEs by conducting cyber security exercises, to coordinate with cyber incident response teams of other countries, to conduct, have conducted and encourage studies to produce and develop all kinds of cyber intervention tools and national solutions. <br> <br> <br> <br>e) To regulate the procedures and principles that those operating in the field of cyber security must comply with. <br> <br> <br> <br>f) To establish, have established, operate or have operated the necessary infrastructures in order to ensure the cyber security of public institutions and organizations and critical public services, and to provide or ensure that hosting services are provided to public institutions and organizations over secure systems and infrastructures, and to determine the application procedures and principles for these activities. <br> <br> <br> <br>g) To prepare standards related to the field of cyber security, to examine the standards prepared by other persons or organizations, to give opinions on them, to accept them as standards if deemed appropriate, to publish them and to monitor their implementation. <br> <br> <br> <br>g) To carry out testing and certification processes for software, hardware, products, systems and services related to the field of cyber security, to establish, have established and operate test infrastructures for this purpose, and to carry out certification, authorization and documentation processes for cyber security experts and companies in coordination with the relevant institutions. <br> <br> <br> <br>h) To carry out cyber security audits and impose sanctions based on the results. <br> <br> <br> <br>i) To determine technical criteria and make legislative arrangements regarding the qualifications that cyber security products and services to be used in public institutions and organizations and critical infrastructures and the businesses that will provide them must have, to conduct or have conducted audits of these, to determine the qualifications that the organizations that will conduct audits must have, to assign these organizations, and to temporarily suspend or cancel the assignment when necessary. <br> <br> <br> <br>Powers <br> <br> <br> <br>ARTICLE 6 - (1) The Presidency exercises the following powers while performing its duties: <br> <br> <br> <br>a) To use the authorities included in the relevant legislation. <br> <br> <br> <br>b) Takes or causes to be taken the necessary measures to protect those within the scope of this Law against cyber attacks and to provide deterrence against the source of these attacks. In this context, it may provide the installation and integration of software and hardware products found suitable for information systems, transfer the data and log records produced or collected by these products to the information systems under the Presidency's management, and use the necessary methods and tools for the detection of cyber incidents. <br> <br> <br> <br>c) It may provide on-site or remote cyber incident response support to those within the scope of this Law who are exposed to cyber incidents, may follow traces of attacks through data, images or log records found or obtained in cyberspace, may examine and prove them, may share findings considered to constitute a crime with judicial authorities and other relevant parties, and may coordinate with domestic and international stakeholders. <br> <br> <br> <br>ç) It may obtain and evaluate information, documents, data and records from those within the scope of this Law, limited to the activities it carries out, and may benefit from their archives, electronic data processing centers and communication infrastructure and establish contact with them. The information, documents, data and records obtained within this scope shall be subject to study for a maximum of two years and shall be destroyed after the study period. Those who are requested within this scope cannot avoid fulfilling the request by citing the provisions of their own legislation. <br> <br> <br> <br>d) It may collect, store and evaluate log records in information systems. It may prepare reports about them and share them with relevant institutions and organizations. <br> <br> <br> <br>e) The Presidency may allocate personnel, when necessary, on cyber security issues in coordination with ministries and other public institutions and organizations. <br> <br> <br> <br>f) It can conduct relations with international organizations and countries on issues within its scope of duty, exchange information, represent our country and ensure coordination, participate in the work of international organizations, follow up on the implementation of decisions taken and ensure the necessary coordination. <br> <br> <br> <br>g) It may classify institutions, organizations and other relevant real and legal persons and organizations without legal personality within the scope of this Law, and may create provisions covering only a certain part of them when necessary while performing their activities. <br> <br> <br> <br>g) It may authorize independent auditors and independent audit organizations that perform cyber security audits, and may cancel their authorization temporarily or indefinitely. <br> <br> <br> <br>h) It determines the criteria for software, hardware, products and services to be used in the information systems of public institutions and organizations and critical infrastructures and that have an impact on cyber security, as well as the procedures and principles regarding notifications to be made to the Presidency. <br> <br> <br> <br>i) It determines the minimum security criteria for cyber security software, hardware, products and services. It manages the certification, authorization and documentation processes for real and legal persons who will provide or supply them. It may request that cyber security software, hardware, products and services be brought into compliance with the standards to be determined, and may take measures to prevent the use of those that do not comply with this request. <br> <br> <br> <br>(2) Within the scope of the work and transactions carried out in accordance with this Law, personal data shall be processed in accordance with the law and the rules of honesty, provided that it is accurate and up-to-date when necessary, for specific, clear and legitimate purposes, in connection with the purpose for which it is processed, limited and proportionate, and kept for the period necessary for the purpose for which it is processed. Personal data and trade secrets to be obtained within the framework of the authorities specified in this Law shall be deleted, destroyed or anonymized ex officio if the reasons requiring access to this data are eliminated. <br> <br> <br> <br>(3) The procedures and principles regarding the implementation of this article are determined by the regulation to be issued by the President. <br> <br> <br> <br>Responsibilities and collaboration <br> <br> <br> <br>ARTICLE 7 - (1) The duties and responsibilities regarding cyber security of those who provide services, collect and process data and carry out similar activities using information systems and are within the scope of this Law are as follows: <br> <br> <br> <br>a) To forward to the Presidency, in a timely manner, all kinds of data, information, documents, hardware, software and other contributions requested by the Presidency within the scope of its duties and activities. <br> <br> <br> <br>b) To take the measures prescribed by the legislation for the purpose of national security, public order or proper execution of public services regarding cyber security, and to report to the Presidency any vulnerabilities or cyber incidents detected in the areas in which they provide services without delay. <br> <br> <br> <br>c) To procure cyber security products, systems and services to be used in public institutions and organizations and critical infrastructures from cyber security experts, manufacturers or companies authorized and certified by the Presidency. <br> <br> <br> <br>c) To obtain the approval of the Presidency within the framework of existing regulations before cyber security companies subject to certification, authorization and documentation start operating. <br> <br> <br> <br>d) To fulfill the issues included in the policy, strategy, action plan and other regulatory procedures published by the Presidency to increase cyber maturity and to take the necessary measures. <br> <br> <br> <br>(2) The Presidency works in cooperation with public institutions and organizations, real and legal persons and unincorporated organizations in carrying out the activities specified in this Law. <br> <br> <br> <br>Control <br> <br> <br> <br>ARTICLE 8 - (1) The Presidency may audit any act or transaction falling within the scope of the Law in cases deemed necessary in relation to its duties specified in this Law; it may conduct on-site inspections or have them conducted for this purpose. Inspection covers the activities and transactions of institutions, organizations and other relevant real and legal persons within the scope of this Law, in relation to the provisions of this Law. Presidency personnel, authorized and certified independent auditors and independent audit organizations are authorized to conduct inspections. This authority is exercised by those assigned by the President. Inspections in public institutions and organizations and critical infrastructures are conducted by Presidency personnel or under their supervision. <br> <br> <br> <br>(2) The Presidency determines the importance and priority principles regarding audit activities and the criteria and application principles to be taken into consideration in risk assessments. Audit activities are carried out in accordance with the program to be established within the scope of importance and priority principles and risk assessments. The Presidency may have audits conducted outside the program for matters deemed necessary to be examined outside the established program. <br> <br> <br> <br>(3) Civil authorities, police forces and other public institution leaders and officers are obliged to provide all kinds of convenience and assistance to those assigned to carry out investigations or audits. <br> <br> <br> <br>(4) Those assigned to audit are authorized to examine electronic data, documents, electronic infrastructure, devices, systems, software and hardware, to obtain copies, digital copies or samples of these, to request written or verbal explanations on the subject, to prepare the necessary minutes, and to examine the facilities and their operations, limited to the audit activities they carry out. Those subject to audit must keep the relevant devices, systems, software and hardware open to audit for the given periods, to provide the necessary infrastructure for audit and to take the necessary measures to keep them in working order. <br> <br> <br> <br>(5) In order to protect national security, public order, prevent crimes or cyber attacks, searches may be conducted in residences, workplaces and closed areas not open to the public upon a judge’s decision or, in cases where delay is deemed undesirable, upon a written order of the public prosecutor, and copying and seizure operations may be carried out in a manner that will not cause long-term service disruptions and without interruption. A copy of the copy made shall be delivered to the relevant person and this matter shall be recorded in the minutes and signed. In order for these operations to be carried out, it must be shown with the justifications that reasonable grounds have arisen. Searches and copying and seizure operations carried out without a judge’s decision shall be submitted to the approval of the competent judge within twenty-four hours. The judge shall announce his/her decision within forty-eight hours; otherwise, the copies made and the texts to which the analysis has been made shall be destroyed immediately and the seizure shall be lifted automatically. Searches, copying and seizure operations may be conducted in the data centers of authorized data center operators only upon a judge’s decision. The Ankara Criminal Court of Peace shall be authorized and tasked with requests falling within the scope of this paragraph. However, a judge’s decision shall not be sought for public institutions and organizations. <br> <br> <br> <br>Cyber ​​Security Board <br> <br> <br> <br>ARTICLE 9 - (1) The Cyber ​​Security Board consists of the President, the Vice President, the Minister of Justice, the Minister of Foreign Affairs, the Minister of Internal Affairs, the Minister of National Defense, the Minister of Industry and Technology, the Minister of Transport and Infrastructure, the Secretary General of the National Security Council, the President of the National Intelligence Organization, the President of Defense Industries and the President of Cyber ​​Security. In cases where the President is not present, the Vice President shall preside over the Board. <br> <br> <br> <br>(2) In addition to the members, relevant ministers and individuals may be invited to the Board meetings, depending on the nature of the agenda, to obtain information and opinions. <br> <br> <br> <br>(3) The Board may form commissions and working groups as it deems necessary within the scope of its duties. Commissions and working groups conduct technical studies on issues within the Board's area of ​​responsibility and produce decision proposals. Experts in the field may be invited to the commission and working group meetings to benefit from their opinions. <br> <br> <br> <br>(4) The duties of the Board are as follows: <br> <br> <br> <br>a) To make decisions regarding cyber security-related policies, strategies, action plans and other regulatory procedures, and to determine the institutions and organizations that will be exempted from all or part of the decisions taken. <br> <br> <br> <br>b) To make decisions regarding the nationwide implementation of the technology roadmap regarding cyber security prepared by the Presidency. <br> <br> <br> <br>c) To determine the priority areas to be encouraged in the field of cyber security and to make decisions regarding the development of human resources in the field of cyber security. <br> <br> <br> <br>c) To determine critical infrastructure sectors. <br> <br> <br> <br>d) To make decisions on disputes that may arise between the Presidency and public institutions and organizations. <br> <br> <br> <br>(5) The secretarial services of the Board are carried out by the Presidency. The working procedures and principles of the Board, commissions and working groups are determined by the regulation to be issued by the President. <br> <br> <br> <br>CHAPTER THREE <br> <br> <br> <br>Provisions Regarding Personnel <br> <br> <br> <br>Employment of contracted expert personnel <br> <br> <br> <br>ARTICLE 10 - (1) Contracted expert personnel, the number of which will be determined by the President, may be employed to carry out tasks related to ensuring cyber security in the Presidency. The qualifications of these personnel, issues related to their employment such as appointment conditions, and net salaries including all kinds of payments to be given to them shall be determined by the Cyber ​​Security Board by taking into account the tasks to be performed by the relevant persons, not to exceed five times the contract salary ceiling applied to those employed in accordance with Article 4, subparagraph (B) of the Civil Servants Law No. 657 dated 14/7/1965. Personnel within the scope of this paragraph shall be deemed insured within the scope of Article 4, first paragraph, subparagraph (a) of the Social Security and General Health Insurance Law No. 5510 dated 31/5/2006. Subject to the special provisions in the laws, employment in this status does not constitute an acquired right in terms of working in any position, cadre or status in public institutions and organizations at the end of the contract. <br> <br> <br> <br>(2) In the Presidency; security investigation and archive research are carried out together for all personnel, including those temporarily assigned, in accordance with the Security Investigation and Archive Research Law No. 7315 dated 7/4/2021. <br> <br> <br> <br>Transfer of compulsory service obligations <br> <br> <br> <br>ARTICLE 11 - (1) The service periods of the personnel employed in the Presidency who have compulsory service obligations to other public institutions and organizations within the scope of the relevant legislation are deducted from the said obligation periods, provided that the consent of the relevant public institution and organization is obtained. <br> <br> <br> <br>Prohibited provisions <br> <br> <br> <br>ARTICLE 12 - (1) Those who are on permanent or contract duty at the Presidency and whose relationship with the Presidency is terminated for any reason cannot take on any other official or private duty in the field of cyber security at home or abroad for two years without the consent of the Presidency, and cannot engage in trade in this field, engage in freelance activities and, in particular, cannot be a shareholder or manager in a company operating in this sector. <br> <br> <br> <br>(2) It is prohibited to publish or disclose any information, documents or similar data obtained within the scope of the duties and activities of the Presidency through radio, television, internet, social media, newspapers, magazines, books and all other media tools and all written, visual, audio and electronic mass communication tools, except in cases authorized by the Presidency. <br> <br> <br> <br>Obligation to keep secret <br> <br> <br> <br>ARTICLE 13 - (1) Confidential information, personal data, trade secrets and documents belonging to the public, relevant parties and third parties obtained within the scope of the duties and activities carried out by the Presidency cannot be disclosed to anyone other than the authorities authorized by law and cannot be used for the benefit of real or legal persons. <br> <br> <br> <br>CHAPTER FOUR <br> <br> <br> <br>Income and Exemptions <br> <br> <br> <br>Revenues of the Presidency <br> <br> <br> <br>ARTICLE 14 - (1) The revenues of the Presidency; <br> <br> <br> <br>a) Treasury aid to be provided from the general budget, <br> <br> <br> <br>b) Income obtained from the activities of the Presidency, <br> <br> <br> <br>c) Revenues obtained from administrative fines imposed by the Presidency, <br> <br> <br> <br>ç) From the amounts to be transferred up to 10% by the decision of the President from the income of the funds established or to be established by law and decree, <br> <br> <br> <br>d) Other income, <br> <br> <br> <br>occurs. <br> <br> <br> <br>Exemptions <br> <br> <br> <br>ARTICLE 15 - (1) Transactions to be carried out for all kinds of materials, tools, equipment, machinery, devices and systems to be provided from abroad through import or grant within the scope of the needs of the Presidency and spare parts, raw materials and aid materials to be used in their research, development, training, production, modernization and software, construction, maintenance and repair, and free of charge aid materials received from external sources are exempt from customs duties, funds and duties, fees and stamp duty on papers prepared for these transactions. This exemption is also applied to the transactions of repair, modernization, maintenance, return to origin, exchange and definite exit, temporary exit, free of charge import and entry abroad on behalf of the Presidency. <br> <br> <br> <br>(2) Permission and certificate of conformity required from public institutions and organizations, real persons and legal entities are not required for the import and export of all kinds of materials, tools, equipment, machinery, devices and systems needed by the Presidency during the execution of its duties. <br> <br> <br> <br>(3) Public institutions and organizations and other institutions and organizations may temporarily allocate or transfer free of charge to the Presidency any materials, equipment, tools and devices that are in their use and confiscated when needed during the performance of the duties set forth in this Law, regardless of the regulations of other laws on this matter. <br> <br> <br> <br>CHAPTER FIVE <br> <br> <br> <br>Application of Penal Provisions and Administrative Fines <br> <br> <br> <br>Penal provisions and administrative fines <br> <br> <br> <br>ARTICLE 16 - (1) Those who do not provide the information, documents, software, data and hardware requested by the authorities and inspection officers authorized by this Law, excluding public institutions and organizations, within the scope of their duties and authorities, or who prevent them from being obtained, shall be punished with imprisonment from one to three years and a judicial fine from five hundred days to one thousand five hundred days. <br> <br> <br> <br>(2) Those who carry out activities without obtaining the required approval, authorization or permissions pursuant to this Law shall be punished with imprisonment from two to four years and a judicial fine from one thousand to two thousand days. <br> <br> <br> <br>(3) Those who fail to fulfill their obligation of confidentiality are sentenced to imprisonment from four to eight years. <br> <br> <br> <br>(4) Those who make personal data, which has previously been included in the scope of a critical public service, accessible, shared or sold, without the permission of individuals or institutions, for a fee or free of charge, due to data leakage in cyberspace, are sentenced to imprisonment from three to five years. <br> <br> <br> <br>(5) Those who create false content claiming that there is a data leak regarding cyber security, in order to create anxiety, fear and panic among the public or to target institutions or individuals, even though they know that there is no data leak in cyberspace, or who spread such content for this purpose, shall be sentenced to imprisonment from two to five years. <br> <br> <br> <br> (6) Those who carry out cyber attacks on the elements that constitute the national power of the Republic of Turkey in cyberspace or who keep any data obtained as a result of such attacks in cyberspace shall be sentenced to imprisonment from eight to twelve years, unless the act constitutes another crime that requires a more severe penalty. Those who disseminate any data obtained as a result of such attacks in cyberspace, send them to another location or put them up for sale shall be sentenced to imprisonment from ten to fifteen years. <br> <br> <br> <br>(7) The penalty to be imposed in accordance with the above paragraphs shall be increased by one third if the crime is committed by a public official, by half if it is committed by more than one person, and by half to two times if it is committed within the scope of the activities of an organization. <br> <br> <br> <br>(8) Those who act contrary to Article 12 shall be sentenced to imprisonment from three to five years. <br> <br> <br> <br>(9) Those who abuse their duties and authorities arising from this Law or who cause a data breach by acting contrary to the requirements of their duties within the scope of protecting critical infrastructures against cyber attacks shall be sentenced to imprisonment from one to three years. <br> <br> <br> <br>(10) Those who do not fulfill their duties and responsibilities in paragraphs (b) and (c) of the first paragraph of Article 7 shall be imposed from one million Turkish Liras to ten million Turkish Liras and those who do not fulfill their duties and responsibilities in Article 18 shall be imposed from ten million Turkish liras to one hundred million Turkish Liras. <br> <br> <br> <br>(11) Those who do not fulfill their obligations in the fourth paragraph of Article 8 shall be imposed from one hundred thousand Turkish Liras to one million Turkish Liras and if these obligations are not fulfilled by the commercial companies, an administrative fine of the gross sales revenue in the annual financial statements that are not less than one hundred thousand Turkish Liras are not fulfilled by the commercial companies. <br> <br> <br> <br>Implementation of administrative fines <br> <br> <br> <br>ARTICLE 17- Before the implementation of the administrative fines, the defense shall be taken to defense within thirty days from the date of notification. <br> <br> <br> <br>(2) If one of the misdemeanors defined in this law is determined that the administrative sanction is made, the relevant real or legal person shall be imposed on a single administrative fine and the amount of the imposition is increased in a way that is not exceeded. <br> <br> <br> <br>(3) Administrative fines issued by the Presidency shall be collected by the tax offices in accordance with the provisions of the Law No. 6183 dated 21/7/1953 upon the notification of the institution. <br> <br> <br> <br>(4) The fifty percent of the administrative fines collected shall be recorded by the general budget share collected from the collection of the general budget; <br> <br> <br> <br>(5) Administrative judicial decisions may be applied against the administrative fine decisions issued in accordance with this law. <br> <br> <br> <br>CHAPTER SIX <br> <br> <br> <br>Miscellaneous and Final Provisions <br> <br> <br> <br>Cyber ​​Security Products and Companies <br> <br> <br> <br>ARTICLE 18- Cyber ​​security products are made in accordance with the procedures and principles to be determined by the Presidency. <br> <br> <br> <br>(2) Cyber ​​Security Procedures, System, Software, Hardware and Services, the merger, division, share transfer or sales transactions shall be notified to the Presidency of the Presidency. <br> <br> <br> <br>(3) The procedures carried out without the approval of the Presidency shall not be valid for the institutions and organizations within the scope of this article. <br> <br> <br> <br>(4) The issues regarding the implementation of this article shall be determined by the procedures and principles to be published by the Presidency. <br> <br> <br> <br>Provisions that have been changed and abolished <br> <br> <br> <br>ARTICLE 19- (1) The following sentence is added to the third paragraph of Article 34 of the Decree Law No. 375 dated 27/6/1989. <br> <br> <br> <br>“The President of the Cyber ​​Security is considered to be equivalent to the undersecretary of the Ministry within the framework of the procedures and principles specified in this paragraph in terms of financial and social rights and aids and retirement rights.” <br> <br> <br> <br>(2) The following line has been added to the “other Administrations with Special Budget” section of the ruler (II) attached to the Public Financial Management and Control Law No. 5018 dated 10/12/2003 and numbered 5018. <br> <br> <br> <br>"46) Cyber ​​Security Presidency" <br> <br> <br> <br>(3) The sixth paragraph of Article 10 of the Law on the regulation of publications made in the internet environment dated 4/5/2007 and numbered 5651 and the fight against crimes committed through these publications has been amended as follows. <br> <br> <br> <br>“(6) The institution provides coordination with content, location, access providers and other relevant institutions and organizations within the scope of their duties, carries out activities to remove the necessary measures and performs needed studies.” <br> <br> <br> <br>(4) Electronic Communication Law No. 5809 dated 5/11/2008; <br> <br> <br> <br>a) paragraph (h) of the first paragraph of Article 5 has been repealed and (I) has been changed as follows. <br> <br> <br> <br>“I) The data and systems within the scope of the duties carried out by the Ministry and the data centers and infrastructures required for the transfer of the data and the necessary infrastructures for the transfer of the data and to determine the policies, strategies and objectives for these centers, to prepare action plans, to determine the procedures and principles of the action and the implementation of all these activities. <br> <br> <br> <br>b) paragraph (V) of the first paragraph of Article 6 has been amended as follows. <br> <br> <br> <br>“V) To fulfill the duties assigned by the President and the Ministry on internet domain names and institution duties.” <br> <br> <br> <br>c) The eleventh paragraph of Article 60 and the annex 1 and 2nd articles were repealed. <br> <br> <br> <br>Compliance, transition arrangements and establishment transactions <br> <br> <br> <br>PROVISIONAL ARTICLE 1- All kinds of transport infrastructure and systems, vehicles, tools, equipment and electronic environment, all kinds of records and documents and all kinds of assets in the case It is transferred to the Security Presidency within six months after the publication of this Law. <br> <br> <br> <br>(2) Employees of the Personnel in the staff and positions of the Information and Communication Technologies Authority and those who are deemed appropriate by the Cyber ​​Security Presidency may be assigned to the presidency. The provisions of the Decree Law no. The service periods that have been entitled to severance pay excluding the severance payments of these personnel shall be taken into consideration in the account of the retirement bonuses or the end of the work before the appointment of this personnel. <br> <br> <br> <br>(3) Contracts on the National Cyber ​​Security Activities of the Presidency of the Information and Communication Technologies Authority and Digital Transformation Office, the lawsuits and enforcement procedures that will be opened and to be opened, and the completion of the assignment procedures in the second paragraph shall be transferred to the presidency and the files related to the existing case files and execution follow -up are transferred to the Presidency. <br> <br> <br> <br>(4) Federations of associations, foundations and trade companies, which are carried out in the field of cyber security, are obliged to complete the certification, authorization and certification procedures within the framework of the principles determined by the Presidency within one year. The legal entities of the Foundations and Federations are terminated by the court decision of the Turkish Civil Code dated 22/11/2001 and numbered 4721, and if necessary measures do not fulfill their liability in the same period. IR. <br> <br> <br> <br>(5) In accordance with the third and fourth paragraphs of Article 19, the institutions operating within the scope of the provisions abolished shall continue to carry out their duties within the framework of the provisions mentioned until the completion of the organization of the Presidency. <br> <br> <br> <br>(6) The regulations regarding the implementation of this Law shall be implemented within one year until the existing regulations are enacted. <br> <br> <br> <br>Force <br> <br> <br> <br>ARTICLE 20- (1) This law shall enter into force on the date of publication. <br> <br> <br> <br>Executive <br> <br> <br> <br>ARTICLE 21- (1) The provisions of this law shall be executed by the President. <br> <br> <br> <br>18/3/2025 <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​Security Law Becomes Law: New Obligations for Companies and Individuals</title>
<link>https://pursaklargundem.com/cyber-security-law-becomes-law-new-obligations-for-companies-and-individuals</link>
<guid>https://pursaklargundem.com/cyber-security-law-becomes-law-new-obligations-for-companies-and-individuals</guid>
<description><![CDATA[ The Cyber ​​Security Law, which aims to protect Türkiye&#039;s data, was accepted in the Turkish Grand National Assembly. The new regulation brings serious obligations and sanctions for companies and individuals. While the security of critical infrastructures is increased, prison sentences related to cyber attacks and data leaks are on the agenda. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67d2c262a9d62.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What does the new Cyber ​​Security Law contain, what obligations are imposed on companies, what penalties will be applied to cyber security violations, what powers will the Cyber ​​Security Presidency have</media:keywords>
<content:encoded><![CDATA[<p></p>
<p><strong>Cyber ​​Security Board and Presidency Authorized <br>With the Cyber ​​Security Law accepted by the Turkish Grand National Assembly, new regulations came into force to ensure Türkiye's digital security. While the powers of the Cyber ​​Security Presidency, established in January, were expanded, the Cyber ​​Security Board affiliated to the Presidency was established. <br> <br>This board will have the authority to determine strategies, conduct audits and create security policies to protect Türkiye against cyber threats. In addition, local and national solutions will be encouraged to protect critical infrastructures. <br> <br>New Obligations for Companies and Individuals <br>The new law covers public and private sector organizations and individuals operating in the digital environment. Accordingly: <br> <br>    Companies will be responsible for identifying and reporting cybersecurity vulnerabilities. <br>    Only authorized cybersecurity products can be used for public and critical infrastructures. <br>    Institutions and companies will be required to submit the requested cybersecurity data to the Cybersecurity Presidency in a timely and complete manner. <br> <br>Heavy Fines and Prison Penalties Are Coming <br>The law provides for severe penalties for companies and individuals that fail to fulfill their cybersecurity obligations: <br> <br>    Companies that create security vulnerabilities will be fined up to 10 million TL. <br>    Those who spread false data leak news will be sentenced to 2 to 5 years in prison. <br>    Those who shared previously leaked data were sentenced to 3 to 5 years in prison. <br>    Those who attack Türkiye's cyber infrastructure will face 8 to 15 years in prison. <br> <br>Cyber ​​Incident Response Team (SOME) to be Established <br>In order to combat cyber attacks more effectively, a Cyber ​​Incident Response Team (SOME) will be established. This team will detect cyber threats, intervene, and conduct international collaborations. In addition, cyber security drills will be organized for public institutions and critical infrastructures. <br> <br>Cyber ​​Security Presidency Will Be Able to Access Company Data <br>According to the law, the Cyber ​​Security Presidency will be able to access the information systems of companies and individuals in order to prevent security risks and integrate the necessary software and hardware products into the systems. In addition, the obtained data will be stored for a maximum of two years and will be destroyed at the end of the specified period. <br> <br>The new regulation aims to raise cyber security standards in Türkiye and create a stronger infrastructure against digital threats. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Critical security update released for Windows 10 and 11!</title>
<link>https://pursaklargundem.com/critical-security-update-released-for-windows-10-and-11</link>
<guid>https://pursaklargundem.com/critical-security-update-released-for-windows-10-and-11</guid>
<description><![CDATA[ Microsoft has released a comprehensive update to close serious security vulnerabilities affecting Windows 10 and 11 users. This update, which fixes 57 vulnerabilities, specifically targets vulnerabilities actively exploited by cyber attackers. It is very important to install the update to reduce the risks of remote access and data breaches. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67d3f3cf2ed84.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What does Windows 10 and 11 security update cover, what is the CVE-2025-24993 vulnerability, what threats do Microsoft&#039;s latest security patches block, what are the update recommendations for system administrators</media:keywords>
<content:encoded><![CDATA[<p></p>
<p><strong>Important security update from Microsoft <br>Microsoft has released a new update to close critical security vulnerabilities in Windows 10 and 11 operating systems. This update, which comes as part of the company's monthly "Patch Tuesday", fixes six vulnerabilities actively used in cyberattacks and a total of 57 security vulnerabilities. <br> <br>Critical patches for system security <br>The update closes vulnerabilities that could allow attackers to remotely access computers and run malicious code. One of the most dangerous vulnerabilities, CVE-2025-24993, allows attackers to take over a system by opening a malicious virtual hard disk file. Microsoft has determined the vulnerability's risk rating as 7.8 and announced that users should update it without delay. <br> <br>In addition, the vulnerability coded CVE-2025-24991 allows attackers to gain unauthorized access to data in the system, while the vulnerability coded CVE-2025-24984 can lead to unwanted data being added to certain log files. <br> <br>Warning from cybersecurity experts <br>Microsoft also announced that it has closed three more vulnerabilities that are actively used in attacks. Cybersecurity experts consider it an extraordinary situation that so many vulnerabilities are being exploited at the same time. The security research group called Zero Day Initiative emphasizes that system administrators should install the update as soon as possible, stating that the vulnerability coded CVE-2025-26633 has affected more than 600 institutions. <br> <br>This update released by Microsoft aims to make users' systems more secure against cyber threats. Users and system administrators are advised to install the updates without wasting time. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​attack on TurkNet: Static IP addresses at risk</title>
<link>https://pursaklargundem.com/cyber-attack-on-turknet-static-ip-addresses-at-risk</link>
<guid>https://pursaklargundem.com/cyber-attack-on-turknet-static-ip-addresses-at-risk</guid>
<description><![CDATA[ TurkNet, one of Türkiye’s leading internet providers, has been subject to a cyber attack. It has been claimed that the static IP addresses of many subscribers were exposed after the attack, raising concerns about security risks. The seizure of static IP addresses poses a major threat in terms of cyber attacks and security breaches. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67d40e96c0ac5.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What risks does the cyber attack on TurkNet pose, what is a static IP address, what happens if a static IP is compromised, how to protect a stolen IP address</media:keywords>
<content:encoded><![CDATA[<p></p>
<p>It has been claimed that TurkNet, one of Türkiye's leading internet service providers, has been subject to a cyber attack. It has been claimed that the static IP addresses of many subscribers have been exposed following the incident, and users are concerned about data security. <br> <br>What is a static IP? <br> <br>A static IP (Internet Protocol) address is an IP address that is manually assigned to a specific device and does not change. It allows devices to be identified on an Internet connection or local network. Unlike dynamic IP addresses, static IP addresses do not change with each reboot. <br> <br>What happens if a static IP is compromised? <br> <br>Static IP addresses hijacked by cyber attackers can pose serious security risks. Attackers can use these addresses to gain unauthorized access to networks or servers. Malware can be spread and firewalls can be bypassed via a hijacked IP address. <br> <br>Additionally, a stolen IP address may be blacklisted if used for illegal activities. This may result in email blocking or access to certain websites being blocked. Users should regularly check their IP addresses and increase security measures to minimize security risks. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​Security Threat: Banking Information Leaked from 24 Million Devices!</title>
<link>https://pursaklargundem.com/cyber-security-threat-banking-information-leaked-from-24-million-devices</link>
<guid>https://pursaklargundem.com/cyber-security-threat-banking-information-leaked-from-24-million-devices</guid>
<description><![CDATA[ According to Kaspersky&#039;s latest report, 26 million devices were infected with malware called &quot;infostealer&quot; between 2023 and 2024. This software victimized millions of users by stealing bank card information. 2.3 million bank card details were leaked on the dark web. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67d42b4a12dfb.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How bank card information is leaked to the dark web, how infostealer software works, how can we protect ourselves from malware, how users&#039; credentials are stolen</media:keywords>
<content:encoded><![CDATA[<p>There are worrying developments in the world of cybersecurity. According to the latest report published by Kaspersky, 26 million devices were infected with malware known as "infostealer" in 2023 and 2024. This software caused millions of people to become victims by stealing users' bank card numbers, passwords and other sensitive data. <br> <br> <br>Bank Card Details Leaked on Dark Web <br>According to Kaspersky’s estimates, 2.3 million bank card numbers have been leaked to the Dark Web in the recent period. The report states that one in 14 infostealer infections results in attackers stealing bank card data. While only 1 percent of bank cards issued globally have been leaked on the dark web, it says 95 percent of the leaked card numbers are “technically valid.” <br> <br>Credentials and Passwords Are Also at Risk <br>Malware can steal not only bank card information but also users' credentials and passwords. This stolen data is spread on the dark web with cookies. Victims face a great danger without realizing that this software has infected their phones, tablets or computers. <br> <br>How Does Malware Spread? <br>Information-stealing software is often disguised as legitimate software. Kaspersky’s report cites common examples such as game cheats. Once downloaded by users, these software can spread to other devices via phishing links, malicious email attachments and infected websites. <br> <br>How Can We Protect Ourselves? <br>If you are a victim of stealer software, Kaspersky recommends monitoring your bank accounts and notifications, re-issue your bank card, change your passwords and enable two-factor authentication. You should also be wary of phishing attacks, fake messages and phone calls, perform security scans on your devices and remove any malware detected. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​Security Law Brings Prison Sentence for False Data Leak Claims</title>
<link>https://pursaklargundem.com/cyber-security-law-brings-prison-sentence-for-false-data-leak-claims</link>
<guid>https://pursaklargundem.com/cyber-security-law-brings-prison-sentence-for-false-data-leak-claims</guid>
<description><![CDATA[ The new Cyber ​​Security Law, which was passed by the Turkish Grand National Assembly, has introduced severe penalties for data leaks and false claims. Data leakers will be sentenced to up to 15 years in prison, while those who spread false data leak claims will face between 2 and 5 years in prison. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67d2c2ac7779d.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What penalties does the new Cyber ​​Security Law foresee, what punishment will be given to false data leakage claims, how many years of prison will be imposed on data leakers, what should be considered in social media posts</media:keywords>
<content:encoded><![CDATA[<p>Within the scope of the Cyber ​​Security Law, which was approved by the Turkish Grand National Assembly and became law, new sanctions were introduced against data leaks and spreading false information. According to the law, those who leak data could be sentenced to up to 15 years in prison. Those who share previously leaked data could be sentenced to up to 5 years in prison. <br> <br> <br>There are also penalties for false data leak claims <br>One of the important regulations in the law is related to false data leakage claims. Accordingly, those who spread false claims that an institution or company has suffered a data leak will face a prison sentence of 2 to 5 years. <br> <br>The article of the law states that, "Those who create false content with the aim of creating anxiety, fear and panic among the public or targeting institutions or individuals, even though they know that there is no data leak in cyberspace, or who spread such content for this purpose, will be sentenced to imprisonment from 2 to 5 years." <br> <br>Be careful about social media sharing <br>In recent years, many claims have been made on social media that public institutions, ministries and private companies have suffered data leaks. Some of these claims, which have been denied by official statements, have caused great public outcry. Under the new law, those who make or share such claims could also face prison sentences. Therefore, citizens need to be careful when sharing posts about data leaks. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Fake Parking Ticket Texts Spread in US: Cities Warn</title>
<link>https://pursaklargundem.com/fake-parking-ticket-texts-spread-in-us-cities-warn</link>
<guid>https://pursaklargundem.com/fake-parking-ticket-texts-spread-in-us-cities-warn</guid>
<description><![CDATA[ Fraudulent text messages have been detected in several cities in the US, sending fake parking ticket messages to drivers. The messages, which appear to be from official authorities, aim to steal personal and financial information from users by redirecting them to fake websites. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67ceb6d592fbb.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How fake parking ticket messages spread in the US, what methods scammers use, how to spot fake messages, how to protect your personal information</media:keywords>
<content:encoded><![CDATA[<p data-start="376" data-end="790"></p>
<p data-start="376" data-end="790">Cities across the U.S. have warned of a new mobile phishing attack targeting drivers. The fake messages pretend to be municipal parking enforcement agencies, notifying drivers that they have unpaid parking tickets. The message warns that if the tickets are not paid by the due date, a $35 daily fee will be added.</p>
<p data-start="792" data-end="1040">This scam method is seen intensively in big cities such as New York, Boston, Detroit, Houston, San Diego, San Francisco. The attacks, which have been ongoing since December, aim to trick users through fake links.</p>
<p><img src="https://beykozunsesi.com.tr/uploads/images/202503/image_870x_67ce4aa8bdc02.webp" alt=""></p>
<p><strong>Information is being seized through fake sites <br> <br>Scammers are using Google’s open redirect feature to trick users. Because the redirects are made via Google.com, a trusted domain, these links are not blocked by iMessage on iPhones and direct users to fake payment sites. <br> <br>For example, a fake website for New York City appears to operate under the address "nycparkclient[.]com." When users enter their name and zip code, they are presented with the amount they allegedly owe and asked to click the "Make Payment" button. <br> <br>But one of the most obvious signs of a scam is typos on the payment screen. While the dollar sign ($) is usually written before the number in the US, these fake sites use it attached to the end of the number. <br> <br>Credit Card and Personal Information Are Stolen <br> <br>When victims proceed to pay, scammers request their name, address, phone number, email, and credit card information. This data can be used for identity theft, financial fraud, and other cybercrimes. <br> <br>Authorities stress that people should be careful about messages coming from an unexpected number, not click on suspicious links and report such messages to the authorities. <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY <br> <br> <br><br></strong></p>]]> </content:encoded>
</item>

<item>
<title>Company&amp;apos;s Systems Crashed After Being Sabotaged by Former Employee</title>
<link>https://pursaklargundem.com/companys-systems-crashed-after-being-sabotaged-by-former-employee</link>
<guid>https://pursaklargundem.com/companys-systems-crashed-after-being-sabotaged-by-former-employee</guid>
<description><![CDATA[ A software developer in the US has been found guilty of sabotaging the systems of his former employer. Davis Lu, who installed malware on the company&#039;s networks and blocked thousands of employees with a &#039;kill switch&#039; code, faces up to 10 years in prison. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67cebf3ebde0e.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:45 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Why did Davis Lu sabotage the company&#039;s systems, how did the kill switch work, how much did the sabotage cost the company, how much prison time could Lu get</media:keywords>
<content:encoded><![CDATA[<p>Davis Lu, a 55-year-old software developer living in Houston, USA, was found guilty of sabotaging the computer systems of his former employer, Eaton Corporation. It was revealed that Lu crashed the systems with specially written malware after he lost his duties at the company. <br> <br>'Kill Switch' Locks Out Thousands of Employees <br> <br>Eaton Corporation is known as a global power management company that operates electrical, hydraulic and mechanical systems. Davis Lu worked at the company's headquarters in Ohio from 2007 to 2019. However, his authority was reduced after a corporate restructuring in 2018. <br> <br>Lu injected malicious code into the company's computers, which overloaded and crashed the systems by injecting 'infinite loops', constantly recreating Java threads, consuming server resources and preventing employees from logging in. <br> <br>In addition, Lu was found to have deleted his colleagues’ user profiles and deployed a system called a ‘kill switch.’ This code, called ‘IsDLEnabledinAD,’ automatically ran when Lu’s Active Directory account was disabled, cutting off thousands of employees’ access to the system. This mechanism was triggered when Lu was fired on September 9, 2019, causing a massive outage across the company. <br> <br>Facing Prison Sentence <br> <br>The investigation by the US Department of Justice also found that Lu had conducted searches on internet search history for methods to elevate privileges, hide processes and quickly delete files. Authorities said this sabotage caused hundreds of thousands of dollars in losses to the company. <br> <br>The jury convicted Lu of "intentionally damaging protected computers." The maximum penalty for this crime is 10 years in prison, but a final verdict is not yet available. <br> <br>Company's Systems Crashed After Being Sabotaged by Former Employee <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>TurkNet Massive Data Breach: 244,000 Users&amp;apos; Information Stolen</title>
<link>https://pursaklargundem.com/turknet-massive-data-breach-244000-users-information-stolen</link>
<guid>https://pursaklargundem.com/turknet-massive-data-breach-244000-users-information-stolen</guid>
<description><![CDATA[ As a result of the SQL Injection attack on TurkNet İletişim Hizmetleri A.Ş. systems, the identity and contact information of 244,396 subscribers were leaked. While the KVKK published a public announcement regarding the violation, information channels for users were announced. ]]></description>
<enclosure url="https://beykozunsesi.com.tr/uploads/images/202504/image_430x256_67eb82a27d2cc.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What information was leaked in the TurkNet data breach, how was the attack carried out, how many users were affected, what decision did KVKK make on this issue</media:keywords>
<content:encoded><![CDATA[<p>TurkNet, one of Türkiye’s leading internet service providers, has come to the fore with a major data breach. According to the notification made to the Personal Data Protection Board (KVKK), 244,396 users’ information was leaked as a result of a SQL Injection attack on one of the company’s systems. <br> <br>How did the data breach occur? <br> <br>TurkNet's statement to the Board stated that the attack started on February 26, 2025, but was noticed as a result of a complaint filed with the Information Technologies and Communication Authority (BTK) on March 11, 2025. <br> <br>Authorities reported that the attack was carried out through SQL Injection into one of the company's services and that the attackers accessed customer information in the database. <br> <br>What data was leaked? <br> <br>According to initial investigations, personal data affected by the attack was listed as follows: <br> <br>    Name, surname <br> <br>    Phone number <br> <br>    Subscription number <br> <br>    Turkish ID number <br> <br>    TurkNet subscription circuit information <br> <br>    Address <br> <br>    Static IP information <br> <br>TurkNet announced that detailed investigations are ongoing to clarify the extent of the incident. <br> <br>Official statement from KVKK <br> <br>The Personal Data Protection Board (KVKK), with its decision numbered 2025/578 dated 20 March 2025, decided to publish the announcement regarding the data breach on the institution's website. <br> <br>TurkNet announced that users who want to get information about the violation can call the fast action lines at 0850 288 80 80 and 0850 344 28 18 or submit a written application to its head office in Istanbul. <br>What is SQL Injection? <br> <br>SQL Injection is a vulnerability that allows cyber attackers to gain unauthorized access to a website’s database. These attacks are typically carried out by injecting malicious SQL commands into data entry points such as user login forms or search bars. With SQL Injection, attackers can steal, modify, or delete data on the system. It is critical for web developers to take security measures to close such vulnerabilities. <br> <br> <br>Source: Beykozun Sesi <br> <br> <br>Source: Pursaklar News</p>]]> </content:encoded>
</item>

<item>
<title>6 Million Pieces of Company Data Up for Sale, Oracle Strongly Denies Breach Claims</title>
<link>https://pursaklargundem.com/6-million-pieces-of-company-data-up-for-sale-oracle-strongly-denies-breach-claims</link>
<guid>https://pursaklargundem.com/6-million-pieces-of-company-data-up-for-sale-oracle-strongly-denies-breach-claims</guid>
<description><![CDATA[ The claim that a hacker stole 6 million company records from Oracle systems has caused a great stir in the technology world. Oracle has categorically denied these claims made by CloudSEK. However, cybersecurity experts warn that the risk could be serious. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67e3ec0a032ef.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Are Oracle data breach claims true, what data did the hacker access, what does CloudSEK&#039;s report reveal, what security measures should companies take</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="409" data-end="459">CloudSEK: Millions of company data leaked <br>According to a report published by Bengaluru-based cybersecurity firm CloudSEK, a hacker with the pseudonym 'rose87168' has put up for sale online 6 million company records that he claims to have stolen from Oracle systems. The report stated that the data in question includes critical files, encrypted login credentials and keys used for secure connections. <br> <br> <br>Oracle's outright denial of the allegations <br>Oracle, in its public statement, defended the allegations as untrue. The statement included the following statements: 'There was no data breach in Oracle Cloud. The identity information that was revealed does not belong to Oracle Cloud. There is no data loss among our customers.' <br> <br>Ransom demand and decryption attempts <br>According to CloudSEK’s assessments, the hacker reached out to more than 140,000 companies whose data security was compromised and demanded ransom in exchange for the deletion of stolen data. It was reported that the hacker also asked online platforms for help in decrypting encrypted information and offered a reward to those who could provide a solution. <br> <br>Is the vulnerability Oracle WebLogic Server? <br>The report suggested that the hacker may have exploited a vulnerability in the login module in Oracle Cloud systems. Experts believe that this vulnerability may be related to Oracle WebLogic Server software. <br> <br>Potential threat to companies <br>The alleged leaked data includes JKS files, encrypted single sign-on (SSO) passwords, various key files, and Oracle Enterprise Manager JPS keys. Such information could pose a risk of infiltration into wider systems through unauthorized access. <br> <br>Experts call on companies to take urgent action <br>In order to prevent possible threats, companies are advised to update their passwords immediately and choose strong, complex passwords. Additionally, it is recommended to activate multi-factor authentication (MFA) systems. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​Security Law Comes into Force Aims to Increase Türkiye&amp;apos;s Security</title>
<link>https://pursaklargundem.com/cyber-security-law-comes-into-force-aims-to-increase-turkiyes-security</link>
<guid>https://pursaklargundem.com/cyber-security-law-comes-into-force-aims-to-increase-turkiyes-security</guid>
<description><![CDATA[ The new law, which will strengthen cybersecurity in Türkiye, will prioritize domestic solutions against cyber threats. In addition, the law introduces severe penalties and inspection obligations. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67dc0eee343ff.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>When did the new Cyber ​​Security Law come into force, what is the purpose of the Cyber ​​Security Law, who will make up the Cyber ​​Security Board, what are the penalties introduced by the Law</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="336" data-end="388">Cyber ​​Security Law published in the Official Gazette <br>The Cyber ​​Security Law, prepared to make cyber security more effective in Türkiye, was published in the Official Gazette and entered into force. The law, which was approved by the TBMM General Assembly on March 12, aims to provide Türkiye with a stronger defense mechanism against cyber threats. The law emphasizes the use of domestic and national products in particular and aims to protect personal data and ensure the security of trade secrets. <br> <br> <br>Local Products and Protection of Personal Data <br>According to the law, personal data and trade secrets obtained within the scope of cybersecurity measures will be deleted, anonymized or destroyed ex officio when the need for access is no longer required. Detailed regulations for these processes will be determined by a regulation to be issued by the Presidency. <br> <br>Cyber ​​Security Board is Being Established <br>The law also foresees the establishment of a Cyber ​​Security Board. The board will be chaired by the President; the Vice President, the Minister of Justice, the Minister of Foreign Affairs, the Minister of the Interior, the Minister of National Defense, the Minister of Industry and Technology, the Minister of Transport and Infrastructure, the Secretary General of the National Security Council, the President of the National Intelligence Organization, the President of Defense Industries and the President of Cyber ​​Security. The board will be able to invite experts and relevant institutions to meetings and form commissions when necessary. <br> <br>Severe Penalties and Sanctions <br>The new law also stipulates severe penalties for cyberattacks. Individuals who conduct cyberattacks will be sentenced to 8 to 12 years in prison. Those who disseminate, sell or send data will be sentenced to 10 to 15 years in prison. Additionally, those who do not share data requested by inspectors will be sentenced to 1 to 3 years in prison and a judicial fine of 500 to 1,500 days. Those who violate the obligation of confidentiality will be sentenced to 4 to 8 years in prison. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Trojan Horse Targeting Cryptocurrency Wallets Detected in Google Chrome!</title>
<link>https://pursaklargundem.com/trojan-horse-targeting-cryptocurrency-wallets-detected-in-google-chrome</link>
<guid>https://pursaklargundem.com/trojan-horse-targeting-cryptocurrency-wallets-detected-in-google-chrome</guid>
<description><![CDATA[ According to the statement made by Microsoft, a malware called StilachiRAT targeting cryptocurrency wallets was detected in the Google Chrome browser. Investors are at great risk. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67dd3d9b36988.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How does the StilachiRAT malware work, are cryptocurrency wallets safer in the browser, what is the significance of the warnings from Microsoft</media:keywords>
<content:encoded><![CDATA[<p></p>
<p><strong>New Threat: StilachiRAT Trojan <br> <br>Microsoft has announced the discovery of a new malware targeting Google Chrome users. The trojan horse, StilachiRAT, specifically targets cryptocurrency wallets. Popular wallets such as MetaMask, TrustWallet, OKX, and OKX Wallet are among the main targets of this malware. Aiming to steal users’ passwords, keywords, and wallet information, this malware leaks wallet information in the Chrome browser, allowing attackers to obtain it. <br> <br>Attack Method and Results <br> <br>Once infiltrated, StilachiRAT searches for wallet information stored in the browser and sends it to an unknown central system. In this way, users' cryptocurrency accounts can be compromised and investors can experience serious financial losses. <br> <br>Microsoft Warns: Store Crypto Wallets in Hardware <br> <br>Microsoft warned users to protect themselves from this threat and recommended using a strong antivirus software. In addition, it was emphasized that it would be safer to store cryptocurrency wallets in hardware wallets rather than in the browser. This warning shows that users should be more careful about security, especially due to the recent increase in cryptocurrency theft and fraud. <br> <br>Ways to Be Safe <br> <br>One of the most effective ways to increase security for cryptocurrency users is to avoid suspicious links, use reliable security software, and store wallet information offline. These measures provide stronger protection against attacks. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Those Who Spread False Data Leak Claims Will Be Sentenced to 5 Years in Prison</title>
<link>https://pursaklargundem.com/those-who-spread-false-data-leak-claims-will-be-sentenced-to-5-years-in-prison</link>
<guid>https://pursaklargundem.com/those-who-spread-false-data-leak-claims-will-be-sentenced-to-5-years-in-prison</guid>
<description><![CDATA[ The new Cyber ​​Security Law, approved by the Turkish Grand National Assembly, will bring prison sentences of 2 to 5 years for those who spread false data leak claims. Those who share false content on social media will face serious penalties. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67dd55bdddc06.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Who will be punished for false data leakage claims, what penalties will be given to those who have data leakage according to the Cyber ​​Security Law, how do false data leakage claims affect the public</media:keywords>
<content:encoded><![CDATA[<p>The Cyber ​​Security Law, which was passed by the Turkish Grand National Assembly (TBMM) and became law, tightens penalties for cybersecurity and data leaks. Under the new law, those who leak data will be sentenced to 15 years in prison, while those who share previously leaked data will be sentenced to 5 years in prison. <br> <br>Penalties for False Data Leak Claims <br>Another noteworthy article of the law is directed at those who spread false data leak claims despite knowing that there has been no data leak. These claims have become a common topic, especially on social media, and have caused public panic. According to the rules set forth by the law, those who make false data leak claims in order to target an institution or create fear and anxiety among the public, even though there has been no data leak, will be sentenced to between 2 and 5 years in prison. <br> <br>The new regulation is of particular concern to social media users and those operating on the internet. Previously, allegations of data leaks regarding many institutions, public institutions and private sector companies have caused great repercussions and some allegations have been denied by official statements. If such allegations are proven to be false, those who spread lies and cause panic among the public could face serious penal sanctions. <br> <br>Beware of Data Leak Claims <br>The new laws aim to effectively monitor the internet and social media in order to prevent the spread of false data leak claims and to maintain public order. It also emphasizes that citizens should be careful and take official statements into consideration before trusting such claims. <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​Security Law Passed by the Turkish Grand National Assembly: A New Era Begins for Türkiye&amp;apos;s Data Security</title>
<link>https://pursaklargundem.com/cyber-security-law-passed-by-the-turkish-grand-national-assembly-a-new-era-begins-for-turkiyes-data-security</link>
<guid>https://pursaklargundem.com/cyber-security-law-passed-by-the-turkish-grand-national-assembly-a-new-era-begins-for-turkiyes-data-security</guid>
<description><![CDATA[ The Cyber ​​Security Law introduces important regulations to protect Türkiye&#039;s digital infrastructure. With the new law, a Cyber ​​Security Presidency and Board will be established, domestic products will be preferred, and various penal sanctions will be implemented. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67dd53af93282.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the innovations brought by the Cyber ​​Security Law in Türkiye? What are the duties of the Cyber ​​Security Presidency? What responsibilities will the Cyber ​​Security Law impose on digital companies? What are the penalties to be applied to those who violate cyber security</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="384" data-end="424">Cyber ​​Security Law passed by the Turkish Grand National Assembly <br>The Cyber ​​Security Law, prepared to strengthen Türkiye's data security, was accepted by the Turkish Grand National Assembly and became law. The law covers all public and private sector organizations operating in the digital environment. The law implements regulations that will create Türkiye's national power in the cyber world and combat external threats. <br> <br> <br>The Role of the Cyber ​​Security Board and its Presidency <br>The Cyber ​​Security Presidency was established with the law, and the presidency's powers were clarified. The Cyber ​​Security Board will also be responsible for determining strategies and policies to strengthen Türkiye's cyber security. The presidency will also conduct risk analyses for critical infrastructures and take protective measures against cyber attacks. <br> <br>Local and National Products Will Be Preferred <br>The use of domestic and national products will be prioritized for cybersecurity measures. Public institutions and private sector companies will monitor all digital processes in line with their cybersecurity strategies. <br> <br>New Obligations and Penalties <br>Cybersecurity obligations cover all companies operating in the digital environment. With the law, companies that do not comply with cybersecurity measures will be fined up to 10 million TL. In addition, those who carry out cyberattacks will be sentenced to up to 15 years in prison. Those who share false data leaks will be sentenced to up to 5 years in prison. <br> <br>Cyber ​​Incident Response Team (CIR) <br>SOME will be established to rapidly respond to cybersecurity crises. This team will work to detect cyberattacks and mitigate their effects. In addition, international cybersecurity collaborations will be established. <br> <br>Supervisory Powers of the Cyber ​​Security Presidency <br>The Cyber ​​Security Presidency will determine the standards in this area by inspecting all software and services in the field of cyber security. It will also detect possible cyber crimes by examining log records in information systems. <br> <br>The New Responsibilities of Digital Companies <br>The cybersecurity law increases the responsibilities of companies operating in the digital field. Companies will be required to immediately report any security vulnerabilities they detect and will be obliged to take all cybersecurity measures. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​fraud increased in Ramadan: Watch out for fake messages!</title>
<link>https://pursaklargundem.com/cyber-fraud-increased-in-ramadan-watch-out-for-fake-messages</link>
<guid>https://pursaklargundem.com/cyber-fraud-increased-in-ramadan-watch-out-for-fake-messages</guid>
<description><![CDATA[ Cyber ​​scammers, who are taking advantage of the month of Ramadan, are targeting citizens with fake aid campaigns and reward messages. Experts say that people should be careful, especially against messages such as &quot;You have won a Ramadan package&quot; or &quot;Your iftar reservation has been confirmed&quot; that come via SMS and WhatsApp. It is emphasized that the people and institutions that will be helped should definitely be investigated. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67dc0037c378c.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the most common methods of cyber fraud during Ramadan, how to protect yourself from fake charity campaigns, how does iftar reservation fraud work, why should you be careful about gift card messages</media:keywords>
<content:encoded><![CDATA[<p></p>
<p>The month of Ramadan has come with new traps for scammers. Cyber ​​scammers reach out to citizens via social media, SMS and WhatsApp, aiming to access personal data and bank accounts through various methods. <br> <br>Beware of fake aid campaigns <br> <br>Scammers are exploiting the spiritual atmosphere of Ramadan and demanding money under the names of "zakat," "fitra" and "Ramadan package aid." People who present themselves as needy are using the goodwill of citizens by making calls for help through fake accounts. Experts state that aid campaigns shared on social media must be organized with the permission of the governor's office and that it is important to do good research before making a donation. <br> <br>Aydın Ağaoğlu, the President of the Consumer Confederation (TÜKONFED), made a statement on the subject and said, “People who want to do good can become the target of scammers. These people not only demand money, but can also obtain personal data. The people and organizations that will be helped should definitely be investigated well. The most reliable method is to help through official institutions and foundations.” <br> <br>Fake rewards and iftar reservation trap <br> <br>Scammers are trying to deceive citizens not only with requests for help, but also with fake prizes. They are directed to malicious links through messages such as 'You have won a Ramadan package', 'You have won a gift card'. Citizens who click on these links can have malicious software loaded onto their phones, which can then access their bank accounts. <br> <br>Consumers Union Chairman Mahmut Şahin warned against such fraudulent methods, saying, “Free cheese is in a mousetrap. No institution distributes gift certificates or aid packages to random people. Therefore, do not click on the links that come to your phone. In addition, aid should be delivered not only to those who request it, but also to those who really need it and do not request it.” <br> <br>Another method used by scammers is the 'iftar reservation' trap. With messages that say 'your iftar reservation has been activated', citizens are directed to fake links and their account information is seized. Experts emphasize that citizens should be careful against these types of scams, which increase during Ramadan. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Google Chrome users warned about a new trojan targeting crypto wallets</title>
<link>https://pursaklargundem.com/google-chrome-users-warned-about-a-new-trojan-targeting-crypto-wallets</link>
<guid>https://pursaklargundem.com/google-chrome-users-warned-about-a-new-trojan-targeting-crypto-wallets</guid>
<description><![CDATA[ According to a Microsoft security report, a trojan horse called StilachiRAT can steal critical user information by targeting crypto wallet extensions in Google Chrome browsers. Authorities have warned against the use of antivirus. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67dc0bec17dd0.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is the StilachiRAT trojan, How can Google Chrome users protect themselves from this threat, Which crypto wallets are targeted by StilachiRAT, What is the significance of Microsoft&#039;s security warning</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="375" data-end="416">Google Chrome users are in danger <br>Recently, cyber attackers have increasingly targeted vulnerabilities in the cryptocurrency world. Google Chrome users have also been hit by these threats. According to a report published by the Microsoft security team, a trojan horse called StilachiRAT is trying to steal users’ sensitive information by targeting crypto wallet extensions in the Google Chrome browser. <br> <br> <br>Wallets are being targeted <br>StilachiRAT is designed to target 20 different wallets, including TrustWallet, OKX, MetaMask, and OKX Wallet. Thanks to this trojan, users of crypto wallets can lose critical information such as passwords and keywords in their browsers. The trojan sends this information to a central point and provides access to users' wallets. <br> <br>Security warning for users <br>Microsoft strongly recommends users to use anti-virus software to protect their computers. It is emphasized that more attention should be paid to such threats. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Google bought cybersecurity giant Wiz for $32 billion!</title>
<link>https://pursaklargundem.com/google-bought-cybersecurity-giant-wiz-for-32-billion</link>
<guid>https://pursaklargundem.com/google-bought-cybersecurity-giant-wiz-for-32-billion</guid>
<description><![CDATA[ Google parent Alphabet has agreed to buy New York-based cybersecurity firm Wiz for $32 billion, making it the largest deal in Google’s history, surpassing the $12.5 billion it paid for Motorola Mobility in 2012. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67da75bf24233.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Why did Google buy Wiz, what is Google&#039;s biggest acquisition, what companies does Wiz serve, will the acquisition be caught in antitrust scrutiny</media:keywords>
<content:encoded><![CDATA[<p>Google is buying cybersecurity firm Wiz for $32 billion in a bid to strengthen cloud computing security. The acquisition is pending regulatory approval, Alphabet announced. <br> <br>Wiz serves major technology companies <br>Wiz, an Israeli startup, provides cloud-based security solutions to tech giants like Microsoft, Amazon and Oracle. Google announced that Wiz will continue to operate within Google Cloud after the acquisition. However, it was emphasized that Wiz's products will also be available on other cloud platforms in order to avoid antitrust concerns. <br> <br>Antitrust review process continues <br>Google had planned to acquire Wiz last year for a valuation of $23 billion, but the company’s executives and investors rejected the deal because it could run afoul of antitrust laws. Now, it is thought that the new US administration and the Federal Trade Commission (FTC) will take a more flexible approach. The approval process of the acquisition is being closely monitored due to FTC Chairman Andrew Ferguson’s tough stance on big tech companies. <br> <br>Google continues to invest in cybersecurity <br>Google has made major investments in cybersecurity in recent years. The company, which acquired Siemplify for $500 million and Mandiant for $5.4 billion in 2022, will make its biggest move in this area with Wiz. On the other hand, Google is currently struggling with two separate antitrust cases due to its search engine and digital advertising activities. <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Beware of Scammers in Ramadan: New Traps Have Emerged</title>
<link>https://pursaklargundem.com/beware-of-scammers-in-ramadan-new-traps-have-emerged</link>
<guid>https://pursaklargundem.com/beware-of-scammers-in-ramadan-new-traps-have-emerged</guid>
<description><![CDATA[ During Ramadan, cyber fraudsters are trying to access personal information and bank accounts through various methods by abusing citizens&#039; spiritual feelings. Experts have warned against fraudsters who deceive people with messages such as &#039;Ramadan package&#039;, &#039;iftar reservation&#039; and &#039;gift certificate&#039;. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67da8cc8cea2d.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:52:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What methods do scammers use during Ramadan, how does the iftar reservation trap work, what precautions should be taken against scammers, what should be considered when providing aid</media:keywords>
<content:encoded><![CDATA[<p></p>
<p>Ramadan continues to be a period when scammers develop new tactics. Cyber ​​scammers collect money from citizens through fake messages spread through social media, SMS and WhatsApp, aiming to access personal data and bank accounts. <br> <br>Fraud Methods Have Diversified <br> <br>Cyber ​​scammers are trying to lure citizens into a trap by sending messages like, "You have won a Ramadan package" or "Your iftar reservation has been activated." People who ask for money under the names of "zakat", "fitra" and "Ramadan package aid" through fake accounts that present themselves as needy people are committing fraud by exploiting spiritual feelings. <br> <br>Experts warn that clicking on malicious links in such messages, especially those sent to phones, could result in bank accounts being emptied and personal data being compromised. It is emphasized that aid campaigns should only be conducted through officially authorized organizations. <br> <br>'The Person to be Helped Should Be Researched Well' <br> <br>Aydın Ağaoğlu, President of the Consumer Confederation (TÜKONFED), stated that citizens who want to do good during Ramadan should be careful and said: <br> <br>“Scammers who pose as needy people exploit the feelings of charitable people. They both extort money and seize personal data. Those who want to help should make their donations through official institutions, foundations and associations.” <br> <br>'Free Cheese in a Mousetrap' <br> <br>Consumers Union Chairman Mahmut Şahin drew attention to the fact that fraudulent methods are increasing and issued the following warning: <br> <br>“Scammers are not only asking for help, they are also trying to trick people with messages like ‘you have won a gift certificate’. It should not be forgotten that free cheese is in a mousetrap. Citizens should not click on such messages and links. They should investigate whether the person is really in need when helping.” <br> <br>Iftar Reservation Trap <br> <br>One of the most common methods used by scammers during Ramadan is iftar reservation messages. Messages that say 'Your iftar reservation has been activated' aim to infiltrate phones and gain access to bank accounts through malicious links they contain. <br> <br>Consumer associations state that fraudulent activities increase as the Ramadan holiday approaches, and emphasize that citizens should be cautious about all kinds of messages and calls. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</p>]]> </content:encoded>
</item>

<item>
<title>Cybersecurity Alarm Bells: Ransomware Attacks Increase, OpenSSL Vulnerability At Critical Level</title>
<link>https://pursaklargundem.com/cybersecurity-alarm-bells-ransomware-attacks-increase-openssl-vulnerability-at-critical-level</link>
<guid>https://pursaklargundem.com/cybersecurity-alarm-bells-ransomware-attacks-increase-openssl-vulnerability-at-critical-level</guid>
<description><![CDATA[ There were important developments in the world of cybersecurity in the 14th week of 2025. Ransomware attacks increased by 37% in Türkiye, and a critical vulnerability that could affect millions of systems was detected in OpenSSL. While Microsoft&#039;s AI-supported analysis platform attracted attention, the European Union&#039;s data security bill and zero trust architecture were among the other prominent topics. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202504/image_870x580_6801f023d3be5.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:42:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Why did ransomware attacks increase in Türkiye? Which systems are affected by the OpenSSL vulnerability? What does Sentinel AI+ offer? Why is Zero Trust architecture important</media:keywords>
<content:encoded><![CDATA[<p></p>
<p><strong>Artificial Intelligence-Powered Security Platform from Microsoft <br>Microsoft has announced its new AI-powered threat analysis platform, 'Sentinel AI+', for corporate networks. This system detects anomalies on the network in real time and analyzes threat intelligence to provide recommendations to security teams. Aiming to reduce the burden on SOC (Security Operations Center) teams, this solution strengthens the use of AI as a decision support tool. <br> <br>New Move from the EU for Artificial Intelligence and Data Security <br>The European Union is working on a new bill to ensure the safe processing of personal data. Going beyond the GDPR, the draft aims to bring more transparency and accountability to how AI systems work. It is envisioned that companies will develop explainable AI systems and be open to auditing. <br> <br>Alarming Increase in Ransomware Attacks in Türkiye <br>According to local cybersecurity reports, ransomware attacks increased by 37% in Türkiye in the first quarter of 2025. These attacks, which target SMEs in particular, are easily successful due to weak encryption systems and unupdated infrastructures. Experts state that emphasis should be placed on backup systems, EDR solutions and regular penetration tests. <br> <br>Critical Vulnerability in OpenSSL <br>The buffer overflow vulnerability, coded CVE-2025-13456, detected in the OpenSSL library puts millions of servers worldwide at risk. It is stated that attackers can run arbitrary code through this vulnerability. Experts emphasize that system administrators should urgently switch to OpenSSL version 3.2.4. <br> <br>Zero Trust Architecture is on the Agenda of Institutions <br>According to a new report by Gartner, 78% of organizations plan to invest in zero trust architecture by 2025. This architecture provides an effective security layer against both external and internal threats by continuously authenticating users and devices. <br> <br>WhatsApp Security Vulnerability Quickly Fixed <br>Attackers were able to access private media via WhatsApp thanks to a vulnerability affecting Android users. Meta announced that this vulnerability, coded CVE-2025-09876, has been fixed and users should update the application. <br> <br>Demand for Cybersecurity Training Explodes <br>Rising threats have also increased interest in cybersecurity training at individual and corporate levels. In particular, certification programs in areas such as SOC analysis, vulnerability analysis, and ethical hacking are in high demand. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Google infrastructure vulnerability targeted Gmail users with fake &amp;apos;court&amp;apos; emails</title>
<link>https://pursaklargundem.com/google-infrastructure-vulnerability-targeted-gmail-users-with-fake-court-emails</link>
<guid>https://pursaklargundem.com/google-infrastructure-vulnerability-targeted-gmail-users-with-fake-court-emails</guid>
<description><![CDATA[ Gmail users were tricked by a security vulnerability in Google&#039;s infrastructure, using an official-looking court notification. The company announced that they were aware of the attack and that the vulnerability had been patched. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202504/image_870x580_680b55980586c.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 29 Apr 2025 00:42:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What kind of vulnerability was used in the Google phishing attack, how were Gmail users targeted, what should be done to distinguish fake emails, how did Google warn users</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="379" data-end="449">Gmail users face new phishing threat <br>Technology company Google has issued a serious security warning for its Gmail platform, which is used by billions of people. The warning came to the fore after software developer Nick Johnson shared his experience with a scam on social media. Johnson explained that an email he thought came from Google was actually fake, and that the message was designed to be convincing enough to bypass Gmail's security checks. <br> <br> <br>Scammers exploit vulnerability in Google infrastructure <br>The fake email Johnson received appeared to be from one of Google’s official addresses. It claimed that his account was the subject of legal proceedings and that he was being sued. The link in the email led to a fake site that was not actually Google’s, but used similar domain names. This fake “support portal” aimed to steal the user’s login information. <br> <br>Official statement: The vulnerability has been closed, users should be careful <br>A Google spokesperson announced that they were aware of such targeted attacks and had closed the vulnerability in their systems. The statement emphasized that users should be careful against fraud attempts. The spokesperson warned users by saying, "Google will not ask you for your password, single-use codes or confirmation of notifications via email or phone." <br> <br>New guidelines from Google <br>The company has issued new security guidelines to protect users from similar scams, particularly not clicking on unknown links and carefully examining domain names in emails. <br> <br> <br> <br>Source: CUMHA - CUMHURS NEWS AGENCY</strong></p>]]> </content:encoded>
</item>

<item>
<title>Cyber ​​threats are growing gradually: corporate and personal data are at risk</title>
<link>https://pursaklargundem.com/cyber-threats-are-growing-gradually-corporate-and-personal-data-are-at-risk</link>
<guid>https://pursaklargundem.com/cyber-threats-are-growing-gradually-corporate-and-personal-data-are-at-risk</guid>
<description><![CDATA[ Cyber ​​attack methods continue to threaten both individuals and institutions by constantly evolving. While ransom software, identity hunting attacks and artificial intelligence -supported frauds are rapidly increasing, cyber security experts strive to develop new protection strategies. So, what are the most up -to -date cyber threats and what precautions should be taken against these threats? ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67c17cd101568.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 10 Mar 2025 11:09:53 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the most up -to -date cyber threats, how ransom software works, how to take precautions against artificial intelligence -supported frauds, what are the corporate cyber security strategies</media:keywords>
<content:encoded><![CDATA[<p> <br>In recent years, cyber attacks have become more sophisticated and complex and confront both individual users and large companies with serious risks. Especially the financial sector, health institutions and government institutions are among the most targeted areas of hackers. Experts say that if measures are not taken against developing threats, data violations may lead to major financial losses and loss of reputation. <br>New generation cyber threats <br> <br>Cyber ​​criminals are constantly updating attack techniques with developing technology. Some of the prominent cyber threats that have come to the forefront: <br> <br>    Artificial Intelligence Supported Frauds: Identity hunting attacks with fake sounds and images created using artificial intelligence become more convincing. In particular, the managers of large companies are targeted and financial fraud cases are increasing. <br>    Ransomware: Attackers who encrypt the data by locking systems demand ransom. Large institutions may have to pay millions of dollars to avoid data loss. <br>    Supply Chain Attacks: Third -party software and service providers where companies work can be leaked to the systems by targeting. Such attacks can even threaten even reliable companies indirectly. <br>    IoT (Internet of Objects) Security Defits: With the spread of smart devices, attackers who benefit from security deficits are trying to play data by accessing networks. <br> <br>What are the protection strategies? <br> <br>Some measures that can be taken at both individual and institutional levels against cyber attacks are as follows: <br> <br>    Using Multi -Factor Authentication: In order to increase the safety of accounts, only additional verification methods should be used instead of password. <br>    Regular Backup: Regular backup of data against ransom software attacks is of great importance. <br>    Cyber ​​Safety Training: Awareness of employees against identity hunting attacks may reduce the success rate of the attacks. <br>    Updated Security Software: Antivirus programs and firewalls should be constantly updated to protect against new threats. <br>    Zero Trust approach: Companies need to limit limited access to authorization policies instead of informal access to each user and device connected to their networks. <br> <br>Today, when cyber threats are constantly evolving, it is of great importance that individuals and institutions take proactive security measures. Experts emphasize that more powerful defense mechanisms should be developed against attacks targeting critical infrastructures. <br> <br> <br> <br>Source: Cumha - Cumhur News Agency</p>]]> </content:encoded>
</item>

<item>
<title>Two new malware that threatened Mac users emerged</title>
<link>https://pursaklargundem.com/two-new-malware-that-threatened-mac-users-emerged</link>
<guid>https://pursaklargundem.com/two-new-malware-that-threatened-mac-users-emerged</guid>
<description><![CDATA[ Two new malware targeting Mac systems were detected. One of them, using a vulnerability in the Parallels virtual machine provides root access to the attackers, while the other is deceiving users and stealing their passwords. Apple and Parallels are working on updates to relieve security vulnerabilities. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67c176f417c6e.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 10 Mar 2025 11:09:53 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the new security threats for Mac systems, how parallels are running, how to infect the Frigidstealer, which safety measures take Apple and PARALLELS</media:keywords>
<content:encoded><![CDATA[<p> <br>Although Mac systems are known for their safety, they may face new threats from time to time. Finally, two new malware were detected by security researchers. One of these software is corrected by Apple with an update to be released within this week, while there is no definite solution for the other. <br> <br>Malse software using the parallels deficit <br> <br>According to Macworld, security researcher Mickey Jin discovered a vulnerability in the Parallels virtual machine. This is due to the security weakness of Parallels, running Windows, Linux and Old MacOS versions. This vulnerability, especially affecting Intel -based Macs, has the potential to provide root access to attackers. However, the risk level is considered relatively low as physical access is required to take the attack. <br> <br>The Parrallels team continues to work to close the vulnerability. Parallels Desktop 20.2.2 and 19.4.2 versions will be released this week to resolve the problem. <br> <br>Password Thief: Frigidstealer <br> <br>Other malicious software, Frigidstealer, can be run remotely and focuses on password theft, especially. The attack process, which started with users' deceiving by e-mail, continues with a message claiming that the user should update the browser through a fake web page. <br> <br>When the user clicks the "Update" button, a harmful loader is downloaded to Mac device. To overcome Gatekeeper security, the user is asked to open the file with the "Control" key. If the user applies these steps, the Frigidstealer becomes activated and starts to steal the passwords on the device. <br> <br>Apple and security experts warn users to be careful against suspicious e-mails and make updates from official sources. <br> <br> <br> <br>Source: Cumha - Cumhur News Agency<b><a href="https://cumha.com.tr/" target="_blank" rel="noopener"></a></b></p>]]> </content:encoded>
</item>

<item>
<title>Operation for those who sell children abuse images on social media: 103 suspects were caught!</title>
<link>https://pursaklargundem.com/operation-for-those-who-sell-children-abuse-images-on-social-media-103-suspects-were-caught</link>
<guid>https://pursaklargundem.com/operation-for-those-who-sell-children-abuse-images-on-social-media-103-suspects-were-caught</guid>
<description><![CDATA[ The Ministry of Interior, 8 province -based operations and covering 28 provinces in the operation of illegal betting, qualified fraud and online child abuse of 103 people involved in crimes announced. Within the scope of the operation, millions of pounds worth of assets were confiscated. ]]></description>
<enclosure url="https://cumha.com.tr/uploads/images/202503/image_870x580_67c93d3e74a5a.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 07 Mar 2025 12:32:44 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How many people were caught in cyber crime operations, the suspects were linked to, which assets were confiscated in operations, which warnings against cyber crimes</media:keywords>
<content:encoded><![CDATA[<p>Interior Minister Ali Yerlikaya, social media account said in a statement, illegal betting, qualified fraud and online child abuse crimes announced a large -scale operation.</p>
<p></p>
<p>Simultaneous operation in 28 provinces</p>
<p>Kocaeli, Ankara, Kayseri, Adana, Zonguldak, Aksaray, Istanbul and Izmir -based operations in a total of 28 provinces, 103 suspects were detained.</p>
<p></p>
<p>Captured persons, social media platforms and phishing sites through bungalow and bodyal fraud, investment promise of high -earning offers by offering people defrauded people. In addition, it was determined that members of the criminal organization that provides financial management of illegal betting sites laundered their money through screens and crypto assets.</p>
<p></p>
<p>Millions of pounds of assets were confiscated</p>
<p>Within the scope of the operation, 13 vehicles worth 250 million TL, 3 villas, 3 companies, 2 hotels in Istanbul and Aydın, 7.5 million dollars worth of crypto assets and bank accounts were confiscated.</p>
<p></p>
<p>During the raids, unlicensed pistols, a large amount of foreign exchange and Turkish Lira with a large number of digital materials were seized.</p>
<p></p>
<p>Warning from Minister Yerlikaya</p>
<p>Interior Minister Ali Yerlikaya, calling for citizens to be careful against cyber crimes, 'Do not send money to people you do not know, do not believe in the promising offers. The most powerful shield against cyber crimes is awareness. Report suspicious situations to 112 Emergency Call Center 'he said.</p>
<p></p>
<p>Source: Cumha - Cumhur News Agency</p>]]> </content:encoded>
</item>

<item>
<title>Osman Doğan: &amp;quot;Critical Infrastructures Face Rising Threats from APT Attacks&amp;quot;</title>
<link>https://pursaklargundem.com/osman-dogan-critical-infrastructures-face-rising-threats-from-apt-attacks</link>
<guid>https://pursaklargundem.com/osman-dogan-critical-infrastructures-face-rising-threats-from-apt-attacks</guid>
<description><![CDATA[ Gais Security, Malwation, and MonSpark CEO Osman Doğan warns about the growing danger of Advanced Persistent Threats (APT) targeting critical sectors like energy, healthcare, and finance. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67b63bb4d62ea.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What sectors are primarily targeted by APT attacks, how can malware analysis help combat APT threats, what role does threat intelligence play in cybersecurity, why is a proactive approach necessary against APTs</media:keywords>
<content:encoded><![CDATA[<p data-start="302" data-end="818">Osman Doğan, CEO and co-founder of Gais Security, Malwation, and MonSpark, has raised alarms about the increasing threat of Advanced Persistent Threats (APTs) targeting critical infrastructures. Highlighting sectors such as energy, healthcare, finance, and transportation, Doğan stated that these industries are among the top priorities for cyber attackers. He stressed that these attacks, often sophisticated and long-term, can cause significant harm to both organizations and national security.</p>
<p data-start="820" data-end="958"><strong data-start="820" data-end="850">Risks Posed by APT Attacks</strong><br data-start="850" data-end="853">According to Doğan, undetected APT attacks could have severe consequences, including the following risks:</p>
<ul data-start="960" data-end="1086">
<li data-start="960" data-end="997">Disruption of operational processes</li>
<li data-start="998" data-end="1022">Major financial losses</li>
<li data-start="1023" data-end="1055">Damage to corporate reputation</li>
<li data-start="1056" data-end="1086">Threats to national security</li>
</ul>
<p data-start="1088" data-end="1450"><strong data-start="1088" data-end="1123">Why Malware Analysis is Crucial</strong><br data-start="1123" data-end="1126">In combating APT attacks, Doğan emphasized the importance of malware analysis. He noted that by utilizing sandbox and dynamic analysis methods, the techniques used by attackers can be decrypted, which in turn strengthens security measures. This allows organizations to detect and mitigate potential threats more effectively.</p>
<p data-start="1452" data-end="1660"><strong data-start="1452" data-end="1502">Threat Intelligence Provides Proactive Defense</strong><br data-start="1502" data-end="1505">Doğan also pointed out that malware intelligence plays a critical role in cybersecurity. He explained that such intelligence provides several key benefits:</p>
<ul data-start="1662" data-end="1815">
<li data-start="1662" data-end="1703">Potential threats can be detected early</li>
<li data-start="1704" data-end="1759">Security teams can take faster action against attacks</li>
<li data-start="1760" data-end="1815">Critical infrastructures can be proactively protected</li>
</ul>
<p data-start="1817" data-end="2131"><strong data-start="1817" data-end="1869">Proactive Approach is Essential in Cybersecurity</strong><br data-start="1869" data-end="1872">Doğan concluded by stating that reactive solutions alone are insufficient to defend against APT attacks. He stressed that continuous malware analysis and up-to-date threat intelligence are indispensable for protecting critical infrastructures in the long run.</p>]]> </content:encoded>
</item>

<item>
<title>Critical Vulnerability Found in AnyDesk: Attackers Can Gain Admin Privileges</title>
<link>https://pursaklargundem.com/critical-vulnerability-found-in-anydesk-attackers-can-gain-admin-privileges</link>
<guid>https://pursaklargundem.com/critical-vulnerability-found-in-anydesk-attackers-can-gain-admin-privileges</guid>
<description><![CDATA[ A critical security flaw (CVE-2024-12754) in AnyDesk allows attackers to access system files and elevate privileges, posing a significant risk to Windows users. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67b0f9e24254e.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is CVE-2024-12754, how does the vulnerability allow privilege escalation, which steps can attackers take to exploit this flaw, what security measures should AnyDesk users take</media:keywords>
<content:encoded><![CDATA[<p data-start="275" data-end="575">A critical security vulnerability has been discovered in the popular remote access software AnyDesk. Identified as CVE-2024-12754, this flaw allows attackers to access system files and escalate privileges, potentially leading to full administrative control of the affected system.</p>
<p data-start="577" data-end="1006"><strong data-start="577" data-end="616">Exploitation of File Copy Mechanism</strong><br data-start="616" data-end="619">The vulnerability was discovered by security researcher Naor Hodorov and revolves around the file copying mechanism used by the AnyDesk service running on Windows systems. When a new session is initiated, AnyDesk copies the current desktop wallpaper to the C:\Windows\Temp folder. This process allows low-privileged users to read and potentially control certain files within this folder.</p>
<p data-start="1008" data-end="1476"><strong data-start="1008" data-end="1061">Unauthorized File Access and Privilege Escalation</strong><br data-start="1061" data-end="1064">A low-privileged user can manipulate the process by changing the desktop wallpaper and controlling which file gets copied to C:\Windows\Temp. However, the copied file is only accessible by system administrators and NT AUTHORITY\SYSTEM. To bypass this restriction, an attacker can place a file with the same name in the C:\Windows\Temp directory before the copy operation, allowing them to access the copied file.</p>
<p data-start="1478" data-end="1677">Additionally, attackers can exploit the Windows-created HarddiskVolumeShadowCopy (Shadow Copies) mechanism to access system files. Following these steps, attackers can elevate their local privileges:</p>
<ol data-start="1679" data-end="2018">
<li data-start="1679" data-end="1746">Place a file with the target name in C:\Windows\Temp beforehand.</li>
<li data-start="1747" data-end="1805">Trigger the copy operation using an oplock (file lock).</li>
<li data-start="1806" data-end="1889">Redirect the folder containing the wallpaper to the NT Object Manager Namespace.</li>
<li data-start="1890" data-end="1953">Use shadow copies to access SAM, SYSTEM, and SECURITY files.</li>
<li data-start="1954" data-end="2018">Gain administrator privileges by utilizing the obtained data.</li>
</ol>
<p data-start="2020" data-end="2309"><strong data-start="2020" data-end="2043">Disclosure Timeline</strong><br data-start="2043" data-end="2046">The vulnerability was reported to AnyDesk developers on July 24, 2024. After being tracked through Trend Micro’s Zero Day Initiative (ZDI), the flaw was publicly disclosed on December 19, 2024. Details about the CVE and ZDI can be found through the provided link.</p>
<p data-start="2311" data-end="2453">To prevent exploitation of this vulnerability, AnyDesk users are advised to follow updates and review their system security settings promptly.</p>]]> </content:encoded>
</item>

<item>
<title>SonicWall Firewalls Targeted by Exploited Vulnerability: Over 4,500 Devices at Risk</title>
<link>https://pursaklargundem.com/sonicwall-firewalls-targeted-by-exploited-vulnerability-over-4500-devices-at-risk</link>
<guid>https://pursaklargundem.com/sonicwall-firewalls-targeted-by-exploited-vulnerability-over-4500-devices-at-risk</guid>
<description><![CDATA[ Cybersecurity experts confirm that a critical vulnerability in SonicWall firewalls (CVE-2024-53704) is actively being exploited, granting attackers unauthorized access to networks. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67afdbf45e1d9.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What is CVE-2024-53704, how many SonicWall devices are vulnerable, what are the recommended actions for affected devices, which ransomware groups previously targeted SonicWall devices</media:keywords>
<content:encoded><![CDATA[<p data-start="302" data-end="655">Cybersecurity experts have confirmed that a critical security vulnerability (CVE-2024-53704) in SonicWall firewalls is being actively exploited by threat actors. This vulnerability affects the SSLVPN authentication mechanism, allowing attackers to bypass authentication requirements and gain unauthorized access to targeted networks.</p>
<p data-start="657" data-end="1030">The attacks accelerated after the release of a Proof-of-Concept (PoC) exploit code.<br data-start="740" data-end="743">The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified this vulnerability as critical. It impacts SonicOS versions 7.1.x (up to version 7.1.1-7058), 7.1.2-7019, and 8.0.0-8035, which are commonly used in Gen 6 and Gen 7 firewalls, as well as SOHO series devices.</p>
<p data-start="1032" data-end="1299">SonicWall issued security updates on January 7 to address the flaw and urged customers to update their systems immediately. For those unable to update, the company recommended restricting device access to trusted sources only and cutting off internet access entirely.</p>
<p data-start="1301" data-end="1554">However, the publication of PoC exploit code by Bishop Fox security researchers on February 10 has shown attackers how to exploit the vulnerability. Following this release, Arctic Wolf, a cybersecurity firm, reported a sharp increase in attack attempts.</p>
<p data-start="1556" data-end="1899"><strong data-start="1556" data-end="1589">Over 4,500 Devices Vulnerable</strong><br data-start="1589" data-end="1592">Internet scans conducted by Bishop Fox researchers on February 7 revealed that more than 4,500 SonicWall SSL VPN servers remain unprotected against the vulnerability. The company warned that these devices are easy targets for attackers and urged administrators to apply security patches as soon as possible.</p>
<p data-start="1901" data-end="2133">Previously, ransomware groups Akira and Fog were known to have targeted SonicWall firewalls. According to a report published by Arctic Wolf in October, at least 30 cyberattacks were traced back to compromised SonicWall VPN accounts.</p>
<p data-start="2135" data-end="2313">Experts emphasize that SonicWall users must immediately update their devices to close the security hole. If updates are not possible, disabling the SSLVPN service is recommended.</p>]]> </content:encoded>
</item>

<item>
<title>PAN&#45;OS Management Interface Under Threat: Cyberattackers Exploit Critical Vulnerability</title>
<link>https://pursaklargundem.com/pan-os-management-interface-under-threat-cyberattackers-exploit-critical-vulnerability</link>
<guid>https://pursaklargundem.com/pan-os-management-interface-under-threat-cyberattackers-exploit-critical-vulnerability</guid>
<description><![CDATA[ A high-risk vulnerability in Palo Alto Networks’ PAN-OS firewalls has been exploited by cybercriminals to bypass authentication and potentially compromise system integrity and privacy. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67afd03cd928b.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What versions of PAN-OS are vulnerable, what is CVE-2025-0108, how can attackers exploit this vulnerability, how many PAN-OS devices are still exposed to the internet</media:keywords>
<content:encoded><![CDATA[<p data-start="310" data-end="723">Cyber attackers are exploiting a critical security flaw, CVE-2025-0108, found in Palo Alto Networks’ PAN-OS firewall system. This vulnerability, recently patched, affects the management web interface of PAN-OS, allowing unauthorized users within a network to bypass authentication processes. By executing specific PHP scripts, attackers can compromise the system's integrity and data privacy.</p>
<p data-start="725" data-end="865">On February 12, Palo Alto Networks issued a security bulletin urging system administrators to upgrade to the following versions immediately:</p>
<ul data-start="866" data-end="951">
<li data-start="866" data-end="886">11.2.4-h4 or later</li>
<li data-start="887" data-end="907">11.1.6-h1 or later</li>
<li data-start="908" data-end="929">10.2.13-h3 or later</li>
<li data-start="930" data-end="951">10.1.14-h9 or later</li>
</ul>
<p data-start="953" data-end="1184">The PAN-OS 11.0 version is also impacted by the vulnerability, but since it has reached its end of life, no security updates will be provided. Therefore, users of this version are strongly advised to upgrade to a supported release.</p>
<p data-start="1186" data-end="1555"><strong data-start="1186" data-end="1219">Security Researchers’ Warning</strong><br data-start="1219" data-end="1222">The vulnerability, CVE-2025-0108, was discovered by cybersecurity firm Assetnote and reported to Palo Alto Networks. In a technical report published after the patch release, the researchers demonstrated that attackers could exploit this flaw to extract sensitive system data, view firewall configurations, or alter specific settings.</p>
<p data-start="1557" data-end="1687">The attackers leverage a confusion between Nginx and Apache servers within PAN-OS to bypass authentication and gain system access.</p>
<p data-start="1689" data-end="2007"><strong data-start="1689" data-end="1717">Surge in Attack Attempts</strong><br data-start="1717" data-end="1720">Cyber threat monitoring platform GreyNoise has recorded an increasing number of attack attempts targeting unpatched PAN-OS systems. As of February 13, 17:00 UTC, attacks originating from multiple IP addresses and threat actors attempting to exploit this vulnerability have been observed.</p>
<p data-start="2009" data-end="2187">Additionally, Yutaka Sejiyama, a security researcher at Macnica, revealed that over 4,400 PAN-OS devices worldwide still have their management interfaces exposed to the internet.</p>
<p data-start="2189" data-end="2374"><strong data-start="2189" data-end="2216">Defense Recommendations</strong><br data-start="2216" data-end="2219">Experts predict a rise in attack attempts due to the public disclosure of this vulnerability. To mitigate the risk, the following measures are recommended:</p>
<ul data-start="2375" data-end="2559">
<li data-start="2375" data-end="2418">Immediate application of security patches</li>
<li data-start="2419" data-end="2476">Restricting access to the firewall management interface</li>
<li data-start="2477" data-end="2559">Implementing additional security controls to prevent unauthorized network access</li>
</ul>
<p data-start="2561" data-end="2722">If exploited, this vulnerability could place systems in significant jeopardy, underscoring the need for prompt action from authorities and system administrators.</p>]]> </content:encoded>
</item>

<item>
<title>Italian Government: &amp;apos;Paragon Spyware Targeted Citizens Across Europe&amp;apos;</title>
<link>https://pursaklargundem.com/italyan-hukumeti-paragon-casus-yazilimi-avrupa-genelinde-vatandaslari-hedef-aldi</link>
<guid>https://pursaklargundem.com/italyan-hukumeti-paragon-casus-yazilimi-avrupa-genelinde-vatandaslari-hedef-aldi</guid>
<description><![CDATA[ The Italian government has announced that spyware developed by Paragon Solutions was used in a surveillance campaign uncovered by WhatsApp, targeting users in several European countries. While allegations suggest that Italian journalist Francesco Cancellato and activist Luca Casarini were among the targets, the government has denied these claims. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67afb8c8d8741.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>Which countries was the Paragon spyware used in?, How many people were targeted in Italy?, How did WhatsApp detect the spyware?, How did Paragon Solutions respond to these allegations?</media:keywords>
<content:encoded><![CDATA[<p data-start="0" data-end="234">The Italian government has announced that spyware developed by Paragon Solutions was used in a surveillance campaign uncovered by WhatsApp, targeting citizens across Europe. The announcement was made in a press release on Wednesday.</p>
<p data-start="236" data-end="543">The government denied allegations that the spyware targeted Italian journalist Francesco Cancellato and activist Luca Casarini. Cancellato serves as the editor-in-chief of the news site Fanpage.it, while Casarini works for the civil society organization Mediterranea Saving Humans, which assists migrants.</p>
<h3 data-start="545" data-end="591">Several European countries were targeted</h3>
<p data-start="593" data-end="876">The Italian National Cybersecurity Agency (ACN) stated that it had contacted WhatsApp and its legal firm, Advant, determining that at least seven individuals in Italy had been targeted by the spyware. However, WhatsApp declined to disclose their identities due to privacy concerns.</p>
<p data-start="878" data-end="1096">According to WhatsApp, similar targeting occurred in several European countries, including Austria, Belgium, Cyprus, Czechia, Denmark, Germany, Greece, Latvia, Lithuania, the Netherlands, Portugal, Spain, and Sweden.</p>
<p data-start="1098" data-end="1300">While WhatsApp did not directly respond to the Italian government's claims, it previously stated that 90 individuals had been affected by the spyware, spanning more than two dozen countries worldwide.</p>
<h3 data-start="1302" data-end="1348">Paragon Solutions denies the accusations</h3>
<p data-start="1350" data-end="1704">In a statement on Tuesday, Paragon Solutions claimed that it sells its spyware technology exclusively to the U.S. government and other "allied" nations. The company emphasized that its strict terms of use prohibit targeting journalists and civil society representatives and that it would terminate relationships with clients who violate these policies.</p>
<p data-start="1706" data-end="1838">However, the company did not directly confirm whether the countries mentioned by the Italian government were indeed its customers.</p>
<p data-start="1840" data-end="1948" data-is-last-node="" data-is-only-node="">The Italian National Cybersecurity Agency and the Prime Minister's Office declined to comment on the matter.</p>]]> </content:encoded>
</item>

<item>
<title>Crypto Crimes Hit Record High in 2024 Amid Market Growth</title>
<link>https://pursaklargundem.com/crypto-crimes-hit-record-high-in-2024-amid-market-growth</link>
<guid>https://pursaklargundem.com/crypto-crimes-hit-record-high-in-2024-amid-market-growth</guid>
<description><![CDATA[ Despite the rapid expansion of the crypto market, digital crimes surged to alarming levels in 2024. According to TRM Labs&#039; 2025 Crypto Crime Report, illicit transactions reached a staggering $45 billion, while fraud and ransomware attacks broke records. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67af9599aa18f.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How much did illicit crypto transactions total in 2024, What role did AI and deepfake technology play in crypto fraud, How much was stolen from crypto exchanges in 2024, Why are stablecoins like USDT being used in illicit transactions</media:keywords>
<content:encoded><![CDATA[<p data-start="377" data-end="840"><strong data-start="377" data-end="427">Fraud-Related Transactions Reach All-Time High</strong><br data-start="427" data-end="430">Blockchain analytics firm <strong data-start="456" data-end="471">Chainalysis</strong> reports that revenue from crypto-related fraud hit record levels in 2024. Cybercriminals leveraged <strong data-start="571" data-end="602">AI-powered investment scams</strong> and <strong data-start="607" data-end="632">deepfake technologies</strong> to make fraud more convincing. Throughout the year, a total of <strong data-start="696" data-end="712">$9.9 billion</strong> was funneled into scam-associated wallets, with projections suggesting this figure could reach <strong data-start="808" data-end="825">$12.4 billion</strong> by year-end.</p>
<p data-start="842" data-end="1225"><strong data-start="842" data-end="872">Rise in Ransomware Attacks</strong><br data-start="872" data-end="875">Ransomware attacks also soared to their highest levels in history, with over <strong data-start="952" data-end="971">5,600 incidents</strong> reported globally in 2024. Ransom payments broke records, with the notorious <strong data-start="1049" data-end="1064">Dark Angels</strong> hacker group demanding <strong data-start="1088" data-end="1103">$75 million</strong> in a single attack. Major security breaches hit financial institutions across <strong data-start="1182" data-end="1222">China, Japan, South Korea, and India</strong>.</p>
<p data-start="1227" data-end="1561"><strong data-start="1227" data-end="1272">Crypto Exchanges Under Heavy Cyberattacks</strong><br data-start="1272" data-end="1275">Cryptocurrency exchanges became prime targets for hackers, with <strong data-start="1339" data-end="1355">$2.2 billion</strong> worth of digital assets stolen throughout the year. <strong data-start="1408" data-end="1445">North Korea-linked hacking groups</strong> alone were responsible for illicit transactions worth <strong data-start="1500" data-end="1516">$800 million</strong>, primarily targeting Asia-based exchanges.</p>
<p data-start="1563" data-end="1959"><strong data-start="1563" data-end="1616">Crypto’s Role in Drug Trade and Sanctions Evasion</strong><br data-start="1616" data-end="1619">Cryptocurrencies continued to play a crucial role in <strong data-start="1672" data-end="1692">drug trafficking</strong> and <strong data-start="1697" data-end="1723">illicit fund transfers</strong>. Reports indicate that insurgent groups in <strong data-start="1767" data-end="1775">Asia</strong> used blockchain networks for untraceable transactions. <strong data-start="1831" data-end="1856">Stablecoins like USDT</strong> were increasingly utilized for illegal activities due to their ease of transfer and price stability.</p>
<p data-start="1961" data-end="2161">As digital crimes escalate, cybersecurity experts warn that <strong data-start="2021" data-end="2045">regulatory oversight</strong> and <strong data-start="2050" data-end="2091">advanced fraud detection technologies</strong> are urgently needed to combat evolving threats in the crypto space.</p>]]> </content:encoded>
</item>

<item>
<title>NVISO Labs: &amp;apos;Hackers Use Microsoft Teams and Spam Emails to Launch Social Engineering Attacks&amp;apos;</title>
<link>https://pursaklargundem.com/nviso-labs-hackers-use-microsoft-teams-and-spam-emails-to-launch-social-engineering-attacks</link>
<guid>https://pursaklargundem.com/nviso-labs-hackers-use-microsoft-teams-and-spam-emails-to-launch-social-engineering-attacks</guid>
<description><![CDATA[ A newly discovered cyber campaign starts with an email flood to distract victims, followed by Microsoft Teams messages from fake IT support agents. Attackers trick users into granting remote access via Quick Assist or AnyConnect. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67a68c3e0cdc1.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How do attackers use email flooding in this campaign, What remote access tools are used in the attack, How can Microsoft Teams users identify suspicious activity, What measures can organizations take to prevent social engineering attacks</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="387" data-end="430">Cyber Attack Begins with Email Flooding</strong><br data-start="430" data-end="433">A campaign uncovered by <strong data-start="457" data-end="471">NVISO Labs</strong> leverages email bombing as an initial distraction tactic. Victims’ inboxes are flooded with harmless-looking spam emails, such as newsletters, to divert their attention from the real threat.</p>
<p><img src="https://www.ajansexpres.com.tr/uploads/images/202501/image_870x_67922467d6c79.webp" alt=""></p>
<p data-start="666" data-end="1015">Once the distraction is in place, attackers impersonate <strong data-start="722" data-end="737">"Help Desk"</strong> or <strong data-start="741" data-end="757">"IT Support"</strong> on <strong data-start="761" data-end="780">Microsoft Teams</strong>, reaching out to targeted individuals. According to NVISO Labs, they attempt to manipulate victims into granting remote access using tools like <strong data-start="925" data-end="941">Quick Assist</strong> or <strong data-start="945" data-end="959">AnyConnect</strong>, allowing them to take full control of their systems.</p>
<p data-start="1017" data-end="1186"><strong data-start="1017" data-end="1061">Attack Execution Through Microsoft Teams</strong><br data-start="1061" data-end="1064">These social engineering attacks on Microsoft Teams can lead to severe security breaches. Attackers use their access to:</p>
<ul data-start="1187" data-end="1272">
<li data-start="1187" data-end="1215">Bypass security controls</li>
<li data-start="1216" data-end="1242">Extract sensitive data</li>
<li data-start="1243" data-end="1272">Deploy malicious software</li>
</ul>
<p data-start="1274" data-end="1421"><strong data-start="1274" data-end="1317">How to Detect and Prevent These Attacks</strong><br data-start="1317" data-end="1320">NVISO Labs has shared several key indicators that can help organizations detect such cyber threats:</p>
<ul data-start="1423" data-end="1956">
<li data-start="1423" data-end="1538"><strong data-start="1425" data-end="1462">Sudden Increase in Email Traffic:</strong> A spike in spam or phishing emails could indicate the start of an attack.</li>
<li data-start="1539" data-end="1661"><strong data-start="1541" data-end="1585">Suspicious Usernames on Microsoft Teams:</strong> Be cautious of accounts with names like <strong data-start="1626" data-end="1641">"Help Desk"</strong> or <strong data-start="1645" data-end="1659">"Support."</strong></li>
<li data-start="1662" data-end="1789"><strong data-start="1664" data-end="1703">Unusual Use of Remote Access Tools:</strong> Unauthorized use of <strong data-start="1724" data-end="1740">Quick Assist</strong> or <strong data-start="1744" data-end="1758">AnyConnect</strong> may signal a breach attempt.</li>
<li data-start="1790" data-end="1956"><strong data-start="1792" data-end="1844">Timing Between Email Flooding and Chat Messages:</strong> If a <strong data-start="1850" data-end="1869">Microsoft Teams</strong> chat starts within three hours of an email bombing event, it should be investigated.</li>
</ul>
<p data-start="1958" data-end="2152">As social engineering attacks become more sophisticated, experts recommend organizations improve <strong data-start="2055" data-end="2082">user awareness training</strong> and implement <strong data-start="2097" data-end="2131">strict authentication policies</strong> to minimize risks.</p>
<p></p>]]> </content:encoded>
</item>

<item>
<title>Tenable Report: &amp;apos;ProxyLogon Vulnerability Still Exposes 91% of Affected Exchange Servers to Attacks&amp;apos;</title>
<link>https://pursaklargundem.com/tenable-report-proxylogon-vulnerability-still-exposes-91-of-affected-exchange-servers-to-attacks</link>
<guid>https://pursaklargundem.com/tenable-report-proxylogon-vulnerability-still-exposes-91-of-affected-exchange-servers-to-attacks</guid>
<description><![CDATA[ Despite being disclosed in March 2021, the ProxyLogon vulnerability remains unpatched in 91% of Exchange Servers. The flaw continues to be exploited by China-linked hacking group Salt Typhoon in cyber-espionage campaigns. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67a68c3d87c60.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How many Exchange Servers are still vulnerable to ProxyLogon, What malware does Salt Typhoon use in its operations, What is Volt Typhoon’s main objective, How can organizations defend against these persistent cyber threats</media:keywords>
<content:encoded><![CDATA[<p data-start="381" data-end="952"><strong data-start="381" data-end="439">ProxyLogon Vulnerability Remains Open for Exploitation</strong><br data-start="439" data-end="442">A critical security flaw, ProxyLogon (CVE-2021-26855), which was initially disclosed by Microsoft in March 2021, continues to put numerous systems at risk. Despite nearly four years passing, 91% of Exchange Server systems with this vulnerability remain unpatched, according to a report by cybersecurity risk management firm Tenable. The flaw is actively being exploited by the China-backed cyber-espionage group Salt Typhoon, among others, to conduct attacks on U.S. telecommunications and government networks.</p>
<p data-start="954" data-end="1368"><strong data-start="954" data-end="990">Salt Typhoon's Espionage Tactics</strong><br data-start="990" data-end="993">Scott Caveza, a research engineer at Tenable, noted that Salt Typhoon uses specialized malware to remain undetected within victim networks for extended periods. Malware like GhostSpider, SnappyBee, and Masol are the primary tools used by this group for espionage operations. These persistent attackers utilize remote code execution to infiltrate and control targeted systems.</p>
<p data-start="1370" data-end="1782">In addition to Salt Typhoon, other Chinese government-backed groups such as Volt Typhoon and Flax Typhoon have been using similar tactics but targeting different sectors. Volt Typhoon, for example, is focused on disrupting U.S. critical infrastructure with an eye on disabling key systems during potential conflicts. Meanwhile, Flax Typhoon targets IoT devices to create botnet networks for future cyber-attacks.</p>
<p data-start="1784" data-end="2092"><strong data-start="1784" data-end="1829">Congress Focuses on China's Cyber Threats</strong><br data-start="1829" data-end="1832">In a recent session of the U.S. House of Representatives Homeland Security Committee, China’s growing cyber threats were highlighted as one of the primary topics. Experts emphasized that China poses the most "capable and opportunistic" cyber threat to the U.S.</p>
<p data-start="2094" data-end="2380">Former U.S. Navy Rear Admiral Mark Montgomery explained that Volt Typhoon’s operations are designed to disrupt the speed and efficiency of military operations by targeting logistics networks. He described these actions as "preparing the battlefield" in the context of potential warfare.</p>
<p data-start="2382" data-end="2725"><strong data-start="2382" data-end="2406">Urgent Action Needed</strong><br data-start="2406" data-end="2409">Caveza stressed the importance of organizations regularly patching their publicly accessible devices and swiftly addressing known vulnerabilities despite persistent attacks from these threat groups. "It’s vital for organizations to close these security gaps quickly to protect against further exploitation," he said.</p>]]> </content:encoded>
</item>

<item>
<title>Wiz Cybersecurity Firm: &amp;apos;Authentication Flaw Found in DeepSeek Databases&amp;apos;</title>
<link>https://pursaklargundem.com/wiz-cybersecurity-firm-authentication-flaw-found-in-deepseek-databases</link>
<guid>https://pursaklargundem.com/wiz-cybersecurity-firm-authentication-flaw-found-in-deepseek-databases</guid>
<description><![CDATA[ A security vulnerability detected by Wiz reveals that DeepSeek&#039;s databases are accessible without authentication. Attackers could exploit this flaw to gain full control over the system and escalate privileges. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67a68c3cd18be.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>How was the security flaw in DeepSeek discovered, What data was leaked due to the vulnerability, How did DeepSeek address the issue and what measures were taken, What precautions should companies in the AI sector take to secure databases</media:keywords>
<content:encoded><![CDATA[<p data-start="342" data-end="814"><strong data-start="342" data-end="387">Authentication Flaw in DeepSeek Databases</strong><br data-start="387" data-end="390">Cybersecurity firm Wiz has uncovered a serious security flaw in databases used by DeepSeek. The vulnerability allows unauthorized access to databases hosted on <strong data-start="550" data-end="588">oauth2callback.deepseek[.]com:9000</strong> and <strong data-start="593" data-end="620">dev.deepseek[.]com:9000</strong>, making them available without proper authentication. Experts warn that attackers could exploit this flaw to gain full control over the database and escalate their privileges within the system.</p>
<p data-start="816" data-end="1184"><strong data-start="816" data-end="855">How the Vulnerability Was Exploited</strong><br data-start="855" data-end="858">Security researchers revealed that the leaked data was accessed using a vulnerability in the <strong data-start="951" data-end="965">ClickHouse</strong> HTTP interface. By exploiting this flaw, attackers could run arbitrary SQL queries directly through a web browser. This kind of vulnerability presents a significant opportunity for cybercriminals, according to experts.</p>
<p data-start="1186" data-end="1565"><strong data-start="1186" data-end="1228">DeepSeek’s Response and Measures Taken</strong><br data-start="1228" data-end="1231">DeepSeek confirmed the security flaw and stated that patches have been applied to address the issue. However, this incident brings the risks of data security in AI-related ventures back into focus. Experts highlight the growing importance of securing databases and access control in organizations, particularly those in the AI sector.</p>
<p data-start="1567" data-end="1638"><strong data-start="1567" data-end="1582">Leaked Data</strong><br data-start="1582" data-end="1585">The data leaked due to this security flaw includes:</p>
<ul data-start="1639" data-end="1791">
<li data-start="1639" data-end="1669">Over 1 million log records</li>
<li data-start="1670" data-end="1693">User chat histories</li>
<li data-start="1694" data-end="1739">Sensitive API keys and access credentials</li>
<li data-start="1740" data-end="1791">Backend system details and operational metadata</li>
</ul>
<p data-start="1793" data-end="2094"><strong data-start="1793" data-end="1822">Expert Warnings and Risks</strong><br data-start="1822" data-end="1825">This breach underscores the need for companies to strengthen their data security measures. Experts specifically warn AI companies to tighten their database access controls and to be more vigilant about securing sensitive data to prevent similar incidents in the future.</p>]]> </content:encoded>
</item>

<item>
<title>Ebubekir Bastama: &amp;apos;Fraud Methods Using Fake Instagram Ads Are On The Rise&amp;apos;</title>
<link>https://pursaklargundem.com/ebubekir-bastama-fraud-methods-using-fake-instagram-ads-are-on-the-rise</link>
<guid>https://pursaklargundem.com/ebubekir-bastama-fraud-methods-using-fake-instagram-ads-are-on-the-rise</guid>
<description><![CDATA[ A new fraud technique is spreading quickly across social media platforms. Ebubekir Bastama detailed how scammers deceive users with fake video ads on Instagram and shared security warnings ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67a68c3c3389f.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What information do scammers try to collect through Instagram, What warnings did Ebubekir Bastama give about fraud, What security measures should be taken to protect against fraud, How do scammers bypass Instagram’s fraud filters</media:keywords>
<content:encoded><![CDATA[<p data-start="323" data-end="571"><strong data-start="323" data-end="353">Fraud Using Fake Video Ads</strong><br data-start="353" data-end="356">A new fraud method is quickly gaining traction on social media platforms. Ebubekir Bastama explained this scam in detail on his YouTube channel, showing how scammers use fake video ads on Instagram to deceive users.</p>
<p data-start="573" data-end="864"><strong data-start="573" data-end="609">Gaining Trust with the USOM Name</strong><br data-start="609" data-end="612">Scammers are using the name of Turkey’s National Cyber Incident Response Center (USOM) to claim they will help individuals who have fallen victim to cyberattacks. However, their real goal is to steal personal and financial information from the victims.</p>
<p data-start="866" data-end="1024"><strong data-start="866" data-end="907">Instagram Information Collection Trap</strong><br data-start="907" data-end="910">The fraudsters ask victims to fill out a fake "Contact Form" on Instagram, requesting the following information:</p>
<ul data-start="1025" data-end="1347">
<li data-start="1025" data-end="1085">How much money have you lost? (A rough amount is asked.)</li>
<li data-start="1086" data-end="1155">When did this loss occur? (Month and year details are requested.)</li>
<li data-start="1156" data-end="1284">Share the details of the incident. (They ask for information about the fraud method, transaction details, and company name.)</li>
<li data-start="1285" data-end="1347">Contact information: Name, surname, email, and phone number.</li>
</ul>
<p data-start="1349" data-end="1587"><strong data-start="1349" data-end="1396">How Scammers Bypass Filters on Social Media</strong><br data-start="1396" data-end="1399">Fraudsters use various techniques to bypass Instagram's fraud filters. Unlike standard scams, they collect data using an official-looking form and use video ads to gain the victim's trust.</p>
<p data-start="1589" data-end="1853"><strong data-start="1589" data-end="1622">Warning from Ebubekir Bastama</strong><br data-start="1622" data-end="1625">Ebubekir Bastama warns that no information should be entered into such fake ads or forms. He also advises that any suspicious content encountered on social media platforms should be reported to the relevant platform authorities.</p>
<p data-start="1855" data-end="1972"><strong data-start="1855" data-end="1906">Precautionary Measures to Protect Against Fraud</strong><br data-start="1906" data-end="1909">Bastama outlines how users can protect themselves from fraud:</p>
<ul data-start="1973" data-end="2341">
<li data-start="1973" data-end="2064">Verify the authenticity of announcements that claim to come from official institutions.</li>
<li data-start="2065" data-end="2108">Do not fill out unknown links or forms.</li>
<li data-start="2109" data-end="2193">Use the official support channels of Instagram and other social media platforms.</li>
<li data-start="2194" data-end="2270">Report suspicious ads to the relevant platforms to prevent their spread.</li>
<li data-start="2271" data-end="2341">Never provide personal or financial information in social media ads.</li>
</ul>]]> </content:encoded>
</item>

<item>
<title>2024: A Year of Rising Cybersecurity Threats, Gais Security CEO Highlights Organizational Gaps</title>
<link>https://pursaklargundem.com/2024-a-year-of-rising-cybersecurity-threats-gais-security-ceo-highlights-organizational-gaps</link>
<guid>https://pursaklargundem.com/2024-a-year-of-rising-cybersecurity-threats-gais-security-ceo-highlights-organizational-gaps</guid>
<description><![CDATA[ Gais Security CEO Osman Doğan discusses critical structural flaws, insufficient budgets, and human resource shortages leading to increased cybersecurity risks in organizations ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67a68c3b9806f.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:42 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What are the major organizational shortcomings in cybersecurity identified by Osman Doğan, how does the lack of penetration testing impact organizations, why is cybersecurity a cultural responsibility for all employees</media:keywords>
<content:encoded><![CDATA[<p data-start="331" data-end="657">2024 has proven to be a year filled with significant cybersecurity challenges for many organizations. In this context, Osman Doğan, CEO of Gais Security, provided an in-depth evaluation of the security vulnerabilities and cyberattacks identified on the field, highlighting serious structural deficiencies within organizations.</p>
<p data-start="659" data-end="705"><strong data-start="659" data-end="705">Limited Authorities of Cybersecurity Units</strong></p>
<p data-start="707" data-end="1021">Osman Doğan pointed out that the cybersecurity units in many organizations have limited authority within their structure, making it difficult to implement risk-mitigating measures. He stated, "Cybersecurity teams are unable to take necessary actions to minimize risks because they are denied sufficient authority."</p>
<p data-start="1023" data-end="1087"><strong data-start="1023" data-end="1087">Insufficient Budgets and Human Resources Pose Major Problems</strong></p>
<p data-start="1089" data-end="1408">Doğan also mentioned that the budgets allocated to cybersecurity departments are inadequate, and this shortage, combined with a lack of qualified personnel, further exacerbates security vulnerabilities. "Companies are not allocating enough budget and expert staff despite the increasing cybersecurity threats," he said.</p>
<p data-start="1410" data-end="1447"><strong data-start="1410" data-end="1447">Penetration Testing is Inadequate</strong></p>
<p data-start="1449" data-end="1725">The cybersecurity expert emphasized that many organizations conduct penetration tests only once a year, which he argued is insufficient. "Digital assets are constantly evolving, but companies create significant risks by failing to perform regular security tests," Doğan added.</p>
<p data-start="1727" data-end="1774"><strong data-start="1727" data-end="1774">Serious Deficiencies in DevSecOps Processes</strong></p>
<p data-start="1776" data-end="2073">Doğan criticized the security processes in software development, saying, "There are serious deficiencies in automated and manual testing, preventing the early detection of security vulnerabilities." He highlighted that the lack of robust DevSecOps processes exposes organizations to greater risks.</p>
<p data-start="2075" data-end="2123"><strong data-start="2075" data-end="2123">Data Leaks and Insider Threats Go Undetected</strong></p>
<p data-start="2125" data-end="2381">According to Doğan, existing security vulnerabilities are not limited to external threats. Insider threats and data leaks also pose significant challenges. "Many institutions learn about data breaches through social media or third-party sources," he noted.</p>
<p data-start="2383" data-end="2429"><strong data-start="2383" data-end="2429">Malware and Security Solution Deficiencies</strong></p>
<p data-start="2431" data-end="2682">Doğan also discussed how malware hidden in documents sent to company employees often goes undetected due to flaws or misconfigurations in existing security solutions. "These errors make it easier for attackers to gain access to systems," he explained.</p>
<p data-start="2684" data-end="2742"><strong data-start="2684" data-end="2742">Configuration Mistakes in Cloud Systems Are Widespread</strong></p>
<p data-start="2744" data-end="2976">He stressed that misconfigurations in cloud-based systems, incorrect network segmentation, and insufficient access control mechanisms create major security risks. "Companies need to be more cautious about this issue," Doğan advised.</p>
<p data-start="2978" data-end="3017"><strong data-start="2978" data-end="3017">Cybersecurity Must Become a Culture</strong></p>
<p data-start="3019" data-end="3363">Finally, Doğan emphasized that cybersecurity should not solely be the responsibility of the relevant departments but must be ingrained across the entire organization. "Companies need to spread security awareness to all employees. Cybersecurity is not a luxury; it is the only way to survive in the digital world’s ongoing battle," he concluded.</p>
<p><strong>Haberi Yapan: Ebubekir Bastama</strong></p>]]> </content:encoded>
</item>

<item>
<title>Health Net Federal Services and Centene to Pay $11.2 Million Over Cybersecurity Violations</title>
<link>https://pursaklargundem.com/health-net-federal-services-and-centene-to-pay-112-million-over-cybersecurity-violations</link>
<guid>https://pursaklargundem.com/health-net-federal-services-and-centene-to-pay-112-million-over-cybersecurity-violations</guid>
<description><![CDATA[ Health Net Federal Services and its parent company Centene Corporation agree to pay $11.25 million after failing to meet cybersecurity standards under TRICARE contract with the Defense Health Agency. ]]></description>
<enclosure url="https://pursaklargundem.com.tr/uploads/images/202502/image_870x580_67b796e11174c.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 27 Feb 2025 13:52:41 +0300</pubDate>
<dc:creator>bastama</dc:creator>
<media:keywords>What cybersecurity violations were identified in Health Net Federal Services&#039; contract with DHA, how did HNFS fail to meet the required security standards, why did HNFS submit false compliance certifications, what are the terms of the settlement between the companies and the Justice Department</media:keywords>
<content:encoded><![CDATA[<p data-start="328" data-end="967">Health Net Federal Services (HNFS), a U.S.-based healthcare provider, along with its parent company Centene Corporation, has agreed to pay $11,253,400 to resolve allegations that they failed to implement adequate cybersecurity measures under their TRICARE contract with the Defense Health Agency (DHA). The U.S. Department of Justice announced that HNFS, during its provision of healthcare services to U.S. military personnel and their families between 2015 and 2018, did not comply with required cybersecurity protocols. The company is also accused of making false claims regarding its adherence to security standards.</p>
<p data-start="969" data-end="1308"><strong data-start="969" data-end="1008">Security Vulnerabilities Identified</strong><br data-start="1008" data-end="1011">Under the terms of the contract, HNFS was required to comply with cybersecurity controls outlined in 48 C.F.R. § 252.204-7012 and the National Institute of Standards and Technology (NIST) Special Publication 800-53. However, HNFS reportedly neglected several critical security measures, including:</p>
<ul data-start="1310" data-end="1650">
<li data-start="1310" data-end="1392">Failure to scan systems for security vulnerabilities and promptly address issues</li>
<li data-start="1393" data-end="1474">Ignoring risks outlined in audit reports and failing to take corrective actions</li>
<li data-start="1475" data-end="1570">Not implementing asset management, access control, firewall protections, and patch management</li>
<li data-start="1571" data-end="1609">Using outdated hardware and software</li>
<li data-start="1610" data-end="1650">Not enforcing strong password policies</li>
</ul>
<p data-start="1652" data-end="1838">The U.S. Department of Justice also revealed that HNFS submitted false compliance certifications on at least three occasions: November 17, 2015, February 26, 2016, and February 24, 2017.</p>
<p data-start="1840" data-end="2149"><strong data-start="1840" data-end="1870">Company Denies Allegations</strong><br data-start="1870" data-end="1873">While HNFS and Centene deny any data breaches or information leaks, they have agreed to pay the $11.25 million fine as part of a settlement. However, the agreement does not exempt the companies from potential future criminal or administrative penalties if new evidence arises.</p>]]> </content:encoded>
</item>

</channel>
</rss>