πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” How cybercriminals target organizations with new and old security threats πŸ”

Spam, ransomware, and malware continue to haunt organizations, but bad actors are also cooking up new spins on these tried-and-true methods, according to security company Fortinet.

πŸ“– Read

via "Security on TechRepublic".
πŸ” UK company takes retro approach to security πŸ”

Garrison wants to move security away from software and into hardware

πŸ“– Read

via "Security on TechRepublic".
⚠ How one man could have flooded your phone with Microsoft spam ⚠

What a difference one tiny little character can make to a phone number.

πŸ“– Read

via "Naked Security".
πŸ” Cloud misconfigurations are a new risk for the enterprise πŸ”

Cybersecurity is an imperfect science, similar to infectious disease control, according to McAfee CTO.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Intel Analyzes Vulns Reported in its Products Last Year πŸ•΄

A new Intel report looks at the more than 250 CVEs affecting Intel products in 2019.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to make high security standards a competitive advantage πŸ”

Security firm specializes in secure cloud architecture and penetration testing.

πŸ“– Read

via "Security on TechRepublic".
πŸ” RSA Red Team exercise highlights election threats from deepfakes and fake news πŸ”

In a RSA 2020 simulation, the Red Team compromised email accounts, created deepfake videos and spread disinformation on Election Day in Adversaria.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Egress mail security platform aims to stop insider breaches πŸ”

Machine learning creates a profile of expected email contacts and turns on a stop sign when new people pop up.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ How We Enabled Ransomware to Become a Multibillion-Dollar Industry πŸ•΄

As an industry, we must move beyond one-dimensional approaches to assessing ransomware exposures. Asking these four questions will help.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-16900

Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-2992

Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Intangibles of CCPA 2.0 Loom Over RSA Privacy Talks πŸ”

Th California Consumer Privacy Act is nebulous as it is. Potential changes to the state's privacy laws, slated for later this year, could cloud things further.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” After DISA breach, experts say US agencies must stop lateral movement of hackers πŸ”

Attackers shouldn't have been able to remove sensitive data like Social Security numbers from military networks, according to cybersecurity experts.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Open Cybersecurity Alliance looks for new members and new projects at RSA 2020 πŸ”

New standards project aims to make it easy to integrate multiple security tools.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Tense Talk About Supply Chain Risk Yields Few Answers πŸ•΄

RSA panelists locked horns over whether the ban preventing US government agencies from doing business with Huawei is unfairly singling out the Chinese telecom giant.

πŸ“– Read

via "Dark Reading: ".
❌ RSAC 2020: GM’s Transportation Future Hinges on Cybersecurity ❌

CEO Mary T. Barra addressed the high stakes in rolling out self-driving cars and biometric-enhanced vehicles, where one cyber-event could derail plans for emerging automotive technologies.

πŸ“– Read

via "Threatpost".
πŸ•΄ Government Employees Unprepared for Ransomware πŸ•΄

Data shows 73% are concerned about municipal ransomware threats but only 38% are trained on preventing these attacks.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-8878

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-8877

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.

πŸ“– Read

via "National Vulnerability Database".
❌ Google’s War on Android App Permissions, 60 Percent Successful ❌

An automated Google warning to Android app developers regarding mobile app permissions has cut the number of requests in half.

πŸ“– Read

via "Threatpost".