Security
  • Menu
  • All Tips
  • FAQs
  • Categories
  • Guidelines
  • Data Security Support
  • Tools
  • Have I Been Pwned?
  • Pwned Passwords
  • Email Checker
  • Password Generator
  • My IP
  • Privacy
DATA PRIVACY NOTICE AND CONSENT FORM

Cloudstaff is committed to protecting the privacy of its data subjects, and ensuring the safety and security of personal data under its control and custody. This policy provides information on what personal data is gathered by Cloudstaff Security Tips about its current, past, and prospective employees; how it will use and process this; how it will keep this secure; and how it will dispose of it when it is no longer needed. This information is provided in compliance with the Philippine Republic Act No. 10173, also known as, the Data Privacy Act of 2012 (DPA) and its Implementing Rules and Regulations (DPA-IRR). It sets out Cloudstaffs’ data protection practices designed to safeguard the personal data of individuals it deals with, and also to inform such individuals of their rights under the Act.

The personal data obtained from this application is entered and stored within the Cloudstaff system and will only be accessed by the Cloudstaff’s authorized personnel. Cloudstaff have instituted appropriate organizational, technical and cloud security measures (Amazon Web Services Shared Responsibility) to ensure the protection of the users personal data.

Information collected will be automatically deleted after three (3) years inactivity.

Furthermore, the information collected and stored in the application are as follows:
  • Given Name
  • Family Name
  • Avatar [Profile Picture]

USER CONSENT

I have read the Data Privacy Statement and expressed my consent for Cloudstaff to collect, record, organize, update or modify, retrieve, consult, use, consolidate, block, erase or destruct my personal data as part of my information.

I hereby affirm my right to be informed, object to processing, access and rectify, suspend or withdraw my personal data, and be indemnified in case of damages pursuant to the provisions of the Republic Act No. 10173 of the Philippines, Data Privacy Act of 2012 and its corresponding Implementing Rules and Regulations.

If you want to exercise any of your rights, or if you have any questions about how we process your personal data, please contact Cloudstaff’s Data Protection Officer, through the following channel:

Email to privacy@cloudstaff.com

  • Log in Now
Researchers Warn of Sophisticated Malware Hidden in Open-Source Projects

Cybersecurity experts have discovered a new hacker group called Water Curse that uses fake GitHub repositories to spread multi-stage malicious software. Disguised as security or developer tools, the malicious software steals sensitive data like passwords, browser info, and session tokens, and gives hackers remote access to infected systems. It uses Visual Basic Script and PowerShell to run hidden scripts, install malicious apps, and gather system data while avoiding detection and staying on the system long-term.

At least 76 GitHub accounts are linked to the group, and the campaign may have started in March 2023. Water Curse targets developers and the software supply chain by abusing trusted platforms like GitHub. Their repositories contain malicious software, game cheats, crypto wallet tools, bots, and data stealers. The stolen information is sent through platforms like Telegram and file-sharing websites.

Other recent attacks use similar tricks, including phishing emails with fake invoices and OneDrive links that download Sorillus RAT, a virus that can steal data, track activity, and uninstall itself. These campaigns also use temporary internet links created through services like Cloudflare to hide from security systems and appear like safe, normal traffic.

To stay safe from threats like these:

  • Download tools only from trusted, verified sources
  • Avoid clicking on suspicious email links or attachments
  • Use strong antivirus and anti-malware protection
  • Keep software and systems updated
  • Enable two-factor authentication (2FA)
  • Avoid using cracked software or game cheats
  • Review the code and dependencies of developer tools

Being cautious and informed is key to protecting your devices and data.

Source: https://thehackernews.com/2025/06/water-curse-hijacks-76-github-accounts.html


Vyete (VyeteR) Raymundo | News
Created: June 18 2025 | Updated: 1 week, 5 days ago
Comments


  2021 © Mazer

Security Tips v2.0.1 | Crafted with by Saugi