๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด What Cybersecurity Pros Really Think About Artificial Intelligence ๐Ÿ•ด

While there's a ton of unbounded optimism from vendor marketing and consultant types, practitioners are still reserving a lot of judgment.

๐Ÿ“– Read

via "Dark Reading: ".
โŒ Coronavirus-Themed APT Attack Spreads Malware โŒ

The APT group was spotted sending spear-phishing emails that purport to detail information about coronavirus - but they actually infect victims with a custom RAT.

๐Ÿ“– Read

via "Threatpost".
๐Ÿ” Friday Five: 3/13 ๐Ÿ”

Ryuk Ransomware targets another U.S. city, University of Kentucky ends a month-long cyberattack, and a secret-sharing app exposes user data - catch up on the week's news with the Friday Five.

๐Ÿ“– Read

via "Subscriber Blog RSS Feed ".
๐Ÿ•ด Beyond Burnout: What Is Cybersecurity Doing to Us? ๐Ÿ•ด

Infosec professionals may feel not only fatigued, but isolated, unwell, and unsafe. And the problem may hurt both them and the businesses they aim to protect.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ•ด Big BEC Bust Brings Down Dozens ๐Ÿ•ด

Two dozen individuals have been named in the latest arrests of alleged participants in a business email compromise scheme that cost victims $30 million.

๐Ÿ“– Read

via "Dark Reading: ".
โŒ WordPress Plugin Bug in Popup Builder Threatens 100K Websites โŒ

The high-severity flaw allows malicious code injection into website pop-up windows.

๐Ÿ“– Read

via "Threatpost".
โŒ Working from Home: COVID-19โ€™s Constellation of Security Challenges โŒ

Organizations are sending employees and students home to work and learn -- but implementing the plan opens the door to more attacks, IT headaches and brand-new security challenges.

๐Ÿ“– Read

via "Threatpost".
๐Ÿ•ด DDoS Attack Trends Reveal Stronger Shift to IoT, Mobile ๐Ÿ•ด

Attackers are capitalizing on the rise of misconfigured Internet-connected devices running the WS-Discovery protocol, and mobile carriers are hosting distributed denial-of-service weapons.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ” How hospital CIOs can prepare for the onslaught of coronavirus patients ๐Ÿ”

There are steps that IT departments can take to strengthen their technical infrastructure in advance of COVID-19's arrival at their facility.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ›  AIEngine 1.9.2 ๐Ÿ› 

AIEngine is a packet inspection engine with capabilities of learning without any human intervention. It helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.

๐Ÿ“– Go!

via "Security Tool Files โ‰ˆ Packet Storm".
โš  Monday review โ€“ the hot 23 stories of the week โš 

Amazon and eBay shopper data was exposed, and the EARN IT act threatens end-to-end encryption. These stories and more in the weekly roundup.

๐Ÿ“– Read

via "Naked Security".
โš  Senate bill would ban TikTok from government phones โš 

Concerns over cybersecurity risk and possible spying by China have already brought about bans from DHS, DoD, TSA, and the State Department.

๐Ÿ“– Read

via "Naked Security".
โš  Open source bugs have soared in the past year โš 

Open source bugs have skyrocketed, according to a report from WhiteSource, with XSS flaws account for a quarter of those bugs.

๐Ÿ“– Read

via "Naked Security".
โš  Report calls for web pre-screening to end UKโ€™s child abuse โ€˜explosionโ€™ โš 

The IICSA report cited "unprecedented levels of depravity" and said that encryption is getting in the way of current screening.

๐Ÿ“– Read

via "Naked Security".
โš  Microsoft patches wormable Windows 10 โ€˜SMBGhostโ€™ flaw โš 

Whatโ€™s the difference between a scheduled security update and one thatโ€™s out-of-band? In this case, it's two days.

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด 4 Ways Thinking 'Childishly' Can Empower Security Professionals ๐Ÿ•ด

Younger minds -- more agile and less worried by failure -- provide a useful model for cyber defenders to think more creatively.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ” Report: US Health and Human Services department hit by cyberattack amidst coronavirus fears ๐Ÿ”

The Sunday cybersecurity attack was designed to slow down the agency's systems as it tries to grapple with the spread of COVID-19.

๐Ÿ“– Read

via "Security on TechRepublic".
ATENTIONโ€ผ New - CVE-2019-10091

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2018-13063

Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2018-13060

Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

๐Ÿ“– Read

via "National Vulnerability Database".