πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Quantifying Cyber Risk: Why You Must & Where to Start πŸ•΄

Quantifying cybersecurity risks can be a critical step in understanding those risks and getting executive support to address them.

πŸ“– Read

via "Dark Reading: ".
⚠ Cryptojacking is almost conquered – crushed along with coinhive.com ⚠

Cryptojacking may not be entirely gone following the shutdown of notorious cryptomining service Coinhive - but it's drastically diminished.

πŸ“– Read

via "Naked Security".
πŸ” IT security report finds 97% have suspicious network activity πŸ”

The suspicious network activities revealed in the research by Positive Technologies are traffic hiding, VPN tunneling, connections to the Tor anonymous network, and network proxying.

πŸ“– Read

via "Security on TechRepublic".
❌ What is the Best Defense Against Phishing Attacks? ❌

While many view phishing as a small annoyance, this attack method has maintained longevity for a reason and is still the number one cause of data breaches.

πŸ“– Read

via "Threatpost".
πŸ•΄ Achieving DevSecOps Requires Cutting Through the Jargon πŸ•΄

Establishing a culture where security can work easily with developers starts with making sure they can at least speak the same language.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cyber Resilience Benchmarks 2020 πŸ•΄

Here are four things that separate the leaders from the laggards when fighting cyber threats.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ TA505 Targets HR Departments with Poisoned CVs πŸ•΄

Infamous cybercrime organization spotted in attacks that employ legitimate software -- and Google Drive.

πŸ“– Read

via "Dark Reading: ".
πŸ” Healthcare devices at higher cybersecurity risk now due to COVID-19 πŸ”

Much of the US healthcare system is running on outdated software and unsupported operating systems, such as Windows 7, leaving devices vulnerable to hackers who are actively exploiting the coronavirus.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ New Study Calls Common Risk Figure into Question πŸ•΄

Many risk models use a commonly quoted number -- $150 per record -- to estimate the cost of an incident. A new study from the Cyentia Institute says misusing that number means that estimates are almost never accurate.

πŸ“– Read

via "Dark Reading: ".
❌ Cloud Misconfig Mistakes Show Need For DevSecOps ❌

Unit 42 researchers discuss public cloud misconfiguration issues that are leading to breaches of sensitive data.

πŸ“– Read

via "Threatpost".
πŸ•΄ VPN Usage Surges as More Nations Shut Down Offices πŸ•΄

As social distancing becomes the norm, interest in virtual private networks has rocketed, with some providers already seeing a doubling in users and traffic since the beginning of the year.

πŸ“– Read

via "Dark Reading: ".
⚠ NIST shared dataset of tattoos that’s been used to identify prisoners ⚠

The EFF got in touch with the institutions that have the dataset. Some deleted it, while one refused and others didn't bother to respond.

πŸ“– Read

via "Naked Security".
πŸ•΄ DDoS Attack Targets German Food Delivery Service πŸ•΄

Liefrando delivers food from more than 15,000 restaurants in Germany, where people under COVID-19 restrictions depend on the service.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to control what personal information people see in Android πŸ”

Do you know what information you share within the Google ecosystem? You can easily control what is visible or hidden, from with your Android device. Find out how.

πŸ“– Read

via "Security on TechRepublic".
❌ Cisco Warns of High-Severity SD-WAN Flaws ❌

The high-severity flaws exist in the products using SD-WAN software earlier than Release 19.2.2.

πŸ“– Read

via "Threatpost".
πŸ›  TOR Virtual Network Tunneling Tool 0.4.2.7 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs).

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
ATENTIONβ€Ό New - CVE-2019-12128

In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to listen to port traffic on a Linux server πŸ”

Every network administrator needs to know how to listen to port traffic on a server. Here's one way to do it on Linux.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-11361

Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-2723

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-2722

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

πŸ“– Read

via "National Vulnerability Database".