πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2012-0785

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

πŸ“– Read

via "National Vulnerability Database".
πŸ” 3D map shows how the coronavirus is spreading worldwide πŸ”

A UN aviation agency uses GIS software to track transmission lines while 20 US airports set up screening centers.

πŸ“– Read

via "Security on TechRepublic".
❌ Apple Takes Heat Over β€˜Vulnerable’ iOS Cut-and-Paste Data ❌

Software developer builds a malicious proof-of-concept iOS app that can read data temporarily saved to the device’s clipboard.

πŸ“– Read

via "Threatpost".
πŸ€ͺπŸ’Έ SPECIAL OFFER! πŸ’ΈπŸ€ͺ

 CYBERSECURITY 2020 by WILEY 😈

β˜‘οΈ Secure yourself a new bundle of cybersecurity ebooks! Get ebooks like Cryptography Engineering: Design Principles and Practical Applications, Reversing: Secrets of Reverse Engineering, Social Engineering: The Science of Human Hacking, and more.

β–ͺ️ $959 Worth of awesome ebooks & videos β–ͺ️
▫️ Pay $1 or more ▫️
β–ͺ️ DRM-Free β–ͺ️
▫️ Multi-format ▫️
πŸ•΄ Security, Networking Collaboration Cuts Breach Cost πŸ•΄

CISOs report increases in alert fatigue and the number of records breached, as well as the struggle to secure mobile devices in a new Cisco study.

πŸ“– Read

via "Dark Reading: ".
πŸ” Smishing, data theft by directors, and a new mental health focus πŸ”

Security researchers and practitioners will be talking about a surge in SMS-based phishing attacks, the threat employees pose to data security, and how to improve health and wellness on security team members.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Verizon: Attacks on Mobile Devices Rise πŸ•΄

Companies of all sizes are being hit by mobile attacks and feeling the effects for extended periods of time, according to the 2020 Verizon Mobile Security Index.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Wanted: Hands-On Cybersecurity Experience πŸ•΄

Organizations lament a lack of qualified job candidates as they continue to struggle to hire and retain security teams, the new ISACA State of Cybersecurity 2020 report shows.

πŸ“– Read

via "Dark Reading: ".
⚠ Google denies illegally slurping data off free student Chromebooks ⚠

Nonsense! says Google in response to a lawsuit filed by New Mexico's AG, which accuses Google of violating COPPA's child privacy laws.

πŸ“– Read

via "Naked Security".
⚠ Smart speakers mistakenly eavesdrop up to 19 times a day ⚠

That smart home speaker isn't listening to everything you say, according to new research - but it is listening a lot more than it should.

πŸ“– Read

via "Naked Security".
⚠ The β€œCloud Snooper” malware that sneaks into your Linux servers ⚠

Fascinating research from SophosLabs into a wolf-in-sheep's-clothing malware sample.

πŸ“– Read

via "Naked Security".
❌ Free Download: The Ultimate Security Pros’ Checklist ❌

The Ultimate Security Pros’ Checklist fully maps the core duties of common security positions, from the core technical security aspect to team management and executive reporting.

πŸ“– Read

via "Threatpost".
❌ Sen. Schumer Pushes for TSA Employee Ban on TikTok App at Work ❌

The Department of Homeland Security and two U.S. military branches already had discontinued use of the app based on concerns over Chinese data-security and censorship practices.

πŸ“– Read

via "Threatpost".
πŸ•΄ McAfee Acquires Light Point for Browser Isolation Tech πŸ•΄

Company plans to integrate Light Point Security's technology into the McAfee Secure Web Gateway and its Mvision UCE platform.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cybersecurity Industry: It's Time to Stop the Victim Blame Game πŸ•΄

There are far more ways to be helpful than adding to the noise of what a company probably did wrong.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Wendy Nather on How to Make Security 'Democratization' a Reality πŸ•΄

Ahead of her keynote at the RSA Conference, Cisco's head of advisory CISOs outlines to Dark Reading a unique paradigm that asks security teams to stop fighting their users, and start sharing control with them.

πŸ“– Read

via "Dark Reading: ".
πŸ” McAfee will acquire Light Point Security to help combat browser-based malware πŸ”

The acquisition will allow McAfee to integrate browser isolation technology into its Secure Web Gateway product and MVISION Unified Cloud Edge platform.

πŸ“– Read

via "Security on TechRepublic".
πŸ›  Falco 0.20.0 πŸ› 

Sysdig falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  WhatWeb Scanner 0.5.1 πŸ› 

WhatWeb is a next-generation web scanner. WhatWeb recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1800 plugins, each to recognize something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more. WhatWeb supports an aggression level to control the trade off between speed and reliability.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".