πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 5 Ways to Up Your Threat Management Game πŸ•΄

Good security programs start with a mindset that it's not about the tools, it's what you do with them. Here's how to get out of a reactive fire-drill mode with vulnerability management.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Kr00k Wi-Fi Vulnerability Affected a Billion Devices πŸ•΄

Routers and devices with Broadcom and Cypress Wi-Fi chipsets could be forced to sometimes use encryption keys consisting of all zeroes. Now patched, the issue affected a billion devices, including those from Amazon, Apple, Google, and Samsung.

πŸ“– Read

via "Dark Reading: ".
⚠ LTE vulnerability allows impersonation of other mobile devices ⚠

Researchers have found a way to impersonate mobile devices on 4G and 5G mobile networks, and are calling on operators and standards bodies to fix the flaw that caused it.

πŸ“– Read

via "Naked Security".
⚠ Apple’s iOS pasteboard leaks location data to spy apps ⚠

A developer has discovered that malicious apps could exploit the pasteboard to work out a user’s location.

πŸ“– Read

via "Naked Security".
πŸ•΄ Open Cybersecurity Alliance Releases New Language for Security Integration πŸ•΄

OpenDXL Ontology is intended to allow security components to interoperate right out of the box.

πŸ“– Read

via "Dark Reading: ".
❌ Hackers Cashing In On Healthcare Industry Security Weaknesses ❌

Between ransomware attacks on healthcare devices, malware-laced β€œmedical” apps, and fraud services available on the dark net, attackers are pushing the boundaries on targeting healthcare.

πŸ“– Read

via "Threatpost".
πŸ•΄ Next-Gen SOC Is On Its Way and Here's What It Should Contain πŸ•΄

The next-gen-SOC starts with the next-gen SIEM, and Jason Mical of Devo Technology and Kevin Golas from OpenText talk about what capabilities are required, including threat hunting and greater automation, and how security professionals should exploit the tools.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Commonsense Security: Leveraging Dialogue & Collaboration for Better Decisions πŸ•΄

Sometimes, good old-fashioned tools can help an enterprise create a cost-effective risk management strategy.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How to Prevent an AWS Cloud Bucket Data Leak πŸ•΄

Misconfigured AWS buckets have led to huge data breaches. Following a handful of practices will help keep you from becoming the next news story.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-17032

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-17031

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-17030

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-17029

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-17028

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-17027

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Elastic Security Makes Case For Blending 'Human Element,' Election Security πŸ•΄

Nate Fick, general manager of Elastic and former CEO of Endgame, talks about the impact of AI and machine learning on security professionals, and how what technologies can be tapped to improve security in the runup to November's election.

πŸ“– Read

via "Dark Reading: ".
πŸ” RSA: What it's like to attend the first tech conference after the coronavirus epidemic πŸ”

San Francisco is the site of the RSA 2020 conference, which took place despite cancellations from IBM, Verizon and AT&T.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Sophos Boosts Threat Hunting, Managed Detection and Response Capabilities πŸ•΄

JJ Thompson, senior director of managed threat response for Sophos digs deep into how organizations can start to make sense of the seemingly unlimited data that's available from endpoints, cloud, and on-premises networks. And that's a critical capability as attacker behaviors start to change.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US State Dept. Shares Insider Tips to Fight Insider Threats πŸ•΄

The insider threat is a technology, security, and personnel issue, officials said in explaining an approach that addresses all three factors.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How Should I Answer a Nontech Exec Who Asks, 'How Secure Are We?' πŸ•΄

Consider this your opportunity to educate.

πŸ“– Read

via "Dark Reading: ".
❌ RSAC 2020: Lack of Machine Learning Laws Open Doors To Attacks ❌

When it comes to machine learning, research and cybercriminal activity is full speed ahead - but legal policy has not yet caught up.

πŸ“– Read

via "Threatpost".