πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Sweeping Federal Cybersecurity Upgrades Needed to Defend US πŸ”

A new report says the federal government and the private sector needs to better defend the United States in cyberspace.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” February sees huge jump in exploits designed to spread Mirai botnet πŸ”

The Mirai botnet is known for targeting Internet of Things devices and conducting massive DDoS attacks, as described by cyberthreat researcher Check Point Research.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Cybersecurity pros are using artificial intelligence but still prefer the human touch πŸ”

More than half of organizations have adopted AI for security efforts, but a majority are more confident in results verified by humans, according to WhiteHat Security.

πŸ“– Read

via "Security on TechRepublic".
❌ Flaws Riddle Zyxel’s Network Management Software ❌

Over 16 security flaws, including multiple backdoors and hardcoded SSH server keys, plague the software.

πŸ“– Read

via "Threatpost".
πŸ•΄ COVID-19 Drives Rush to Remote Work. Is Your Security Team Ready? πŸ•΄

A rapid transition to remote work puts pressure on security teams to understand and address a wave of potential security risks.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Discloses New Remote Execution Flaw in SMBv3 πŸ•΄

A patch for the flaw is not yet available, but there are no known exploits -- so far.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Ransomware Increasingly Targeting Small Governments πŸ•΄

To get back up and running quickly, and because it's cheaper, city and county governments often pay the ransom, especially if insurance companies are footing the bill. The result: More ransomware.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cyberspace Solarium Commission Slams US Cybersecurity Readiness πŸ•΄

The federal commission outlined more than 60 recommendations to remedy major security problems.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-1000111

Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

πŸ“– Read

via "National Vulnerability Database".
⚠ Necurs zombie botnet disrupted by Microsoft ⚠

Necurs, one of the world's biggest botnets, infected over 9 million computers worldwide.

πŸ“– Read

via "Naked Security".
⚠ Analytics firm’s VPN and ad-blocking apps are secretly grabbing user data ⚠

Both Google and Apple have removed at least some of the apps from the company, Sensor Tower.

πŸ“– Read

via "Naked Security".
πŸ” Dell: Cost of data loss per organization surpassed $1M in the past year πŸ”

Businesses now manage an average of 13.53 petabytes of data, but struggle to keep it secure.

πŸ“– Read

via "Security on TechRepublic".
⚠ Intel patches graphics drivers and offers new LVI flaw mitigations ⚠

Intel’s March security updates reached its customers this week and the dominant theme is the bundle of flaws affecting Graphics drivers.

πŸ“– Read

via "Naked Security".
❌ Akamai Talks Massive Uptick in Credential-Stuffing Attacks Against Bank APIs ❌

Researchers with Akamai say that 75 percent of all credential abuse attacks against the financial services industry were targeting APIs.

πŸ“– Read

via "Threatpost".
πŸ•΄ Back to the Future: A Threat Intelligence Journey πŸ•΄

Threat intelligence needs the problem solvers, the curious ones, the mission seekers, the analytical minds, the defenders, and the fierce -- whatever their gender.

πŸ“– Read

via "Dark Reading: ".
❌ $100K Paid Out for Google Cloud Shell Root Compromise ❌

A Dutch researcher claimed Google's very first annual Cloud Platform bug-bounty prize, for a clever container escape exploit.

πŸ“– Read

via "Threatpost".
⚠ Firefox 74 offers privacy and security updates ⚠

A month after shipping version 73 of its Firefox browser, Mozilla has released version 74 with a range of privacy and security enhancements.

πŸ“– Read

via "Naked Security".
⚠ Data of millions of eBay and Amazon shoppers exposed ⚠

Eight million customer records belonging to companies including Amazon, eBay, Shopify, PayPal, and Stripe were collected.

πŸ“– Read

via "Naked Security".
πŸ” Cybercriminals raking in $1.5 trillion every year πŸ”

Research from Atlas VPN found that criminals' net proceeds outpace the revenue made by tech giants each year.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Patches Leaked Remote Code Execution Flaw πŸ•΄

A vulnerability in Microsoft's Server Message Block protocol prompted concerns of wormable exploits when it was disclosed this week.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Working from Home? These Tips Can Help You Adapt πŸ•΄

COVID-19 means many people are doing their jobs from outside the confines of the office. That may not be as easy as it sounds.

πŸ“– Read

via "Dark Reading: ".