πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Hellman & Friedman Acquires Checkmarx for $1.15B πŸ•΄

The private equity firm will buy Checkmarx from Insight Partners, which will continue to own a minority interest.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Needed: A Cybersecurity Good Samaritan Law πŸ•΄

Legislation should protect the good hackers who are helping to keep us safe, not just go after the bad.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ InfoSec Pros Uncertain About Relationships With Partner Security Teams πŸ•΄

Only half of respondents to a recent Dark Reading study felt confident that their third-party business partners would, at least, tell them if a compromise occurred.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybersecurity risks grow as thousands of federal employees shift to telecommuting πŸ”

The Trump administration has ordered hundreds of thousands of federal employees to be prepared to work from home full time and use VPNs to connect to government systems.

πŸ“– Read

via "Security on TechRepublic".
❌ APT36 Taps Coronavirus as β€˜Golden Opportunity’ to Spread Crimson RAT ❌

The Pakistani-linked APT has been spotted infecting victims with data exfiltration malware.

πŸ“– Read

via "Threatpost".
πŸ” How to protect your organization from security threats amidst the rise in telecommuters πŸ”

Security becomes a greater challenge as more people work from home due to the coronavirus. Learn how to better protect your organization and employees.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Remote Workforce Jumps 15% In Two Weeks πŸ•΄

Netskope reports the total number of remote employees is the highest it has ever observed.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-11074

A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations with SYSTEM privileges (although not controlling the contents of such files) due to insufficient sanitisation when passing arguments to the phantomjs.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Full Web Page Sensor and set specific settings when executing the sensor.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21037

Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18576

The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ This Tax Season, Save the Scorn and Protect Customers from Phishing Scams πŸ•΄

As security professionals, it's easy to get cynical about the continued proliferation of tax ID theft and blame the consumers themselves. But that doesn't help anyone.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Security Lessons We've Learned (So Far) from COVID-19 πŸ•΄

Takeaways about fighting new fires, securely enabling remote workforces, and human nature during difficult times.

πŸ“– Read

via "Dark Reading: ".
πŸ” Canadian Govt Prioritizing Rules Around Insider Threats πŸ”

Following a high profile espionage case, Canada is set to roll out a new set of protocols designed to stop insider threats within government departments.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Startup Offering Secure Access to Corporate Apps Emerges from Stealth πŸ•΄

Axis Security has raised $17 million in VC funding.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Attorney General Directs DoJ to Prioritize Coronavirus Crime πŸ•΄

Criminal activity related to the pandemic cannot be tolerated, William Barr states in memo.

πŸ“– Read

via "Dark Reading: ".
❌ This Stalkerware Delivers Extra-Creepy Features ❌

Stalkerware called Monitor Minor gives users the ability to creep on a target’s missives swapped via Instagram, Skype and Snapchat.

πŸ“– Read

via "Threatpost".
❌ A COVID-19 Cybersecurity Poll: Securing a Remote Workforce ❌

COVID-19 is changing how we work. Weigh in on how your organization is securing its remote footprint with our short Threatpost poll.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-11939

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

πŸ“– Read

via "National Vulnerability Database".
❌ Magecart Cyberattack Targets NutriBullet Website ❌

Researchers warn that a Magecart group has set up skimmers on the blender manufacturer's website, in hopes of stealing customer payment-card data.

πŸ“– Read

via "Threatpost".
⚠ Human traffickers use social media oversharing to gain victims’ trust ⚠

Posts about money or family trouble are being used to gain trust by those who force victims into sex work or slavery, the FBI warns.

πŸ“– Read

via "Naked Security".