πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Small Business Is Big Target for Ransomware πŸ•΄

Small businesses are being hit by ransomware, and a majority are paying up to get their data back.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How Enterprises Are Developing and Maintaining Secure Applications πŸ•΄

The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Massive Bot-Enabled Ad Fraud Campaign Targeted Connected TVs πŸ•΄

ICEBUCKET operation is the largest ever to attempt to steal from advertisers by using bots to impersonate human smart-TV viewers, White Ops says.

πŸ“– Read

via "Dark Reading: ".
❌ New PoetRAT Hits Energy Sector With Data-Stealing Tools ❌

A never-before-seen RAT is targeting Azerbaijan energy companies with various tools aimed at stealing credentials and exfiltrating valuable data.

πŸ“– Read

via "Threatpost".
πŸ•΄ Neglected Infrastructure, Invasive Tech to Plague Infosec in 2022 πŸ•΄

Researchers outline cybersecurity threats they predict businesses will face in two years as technology evolves.

πŸ“– Read

via "Dark Reading: ".
❌ Poorly Secured Docker Image Comes Under Rapid Attack ❌

A honeypot experiment shows just how quickly cybercriminals will move to compromise vulnerable cloud infrastructure.

πŸ“– Read

via "Threatpost".
πŸ•΄ Could Return of Ghost Squad Hackers Signal Rise in COVID-19-Related Hactivism? πŸ•΄

New research suggests GSH is active in Southeast Asia following a couple of quiet years.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-11285

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
⚠ GitHub users targetted by Sawfish phishing campaign ⚠

GitHub users beware: online criminals have launched a phishing campaign to try and gain access to your accounts.

πŸ“– Read

via "Naked Security".
⚠ US offers up to $5m reward for information on North Korean hackers ⚠

Know anything about North Korean hackers and their activities in cyberspace, past or ongoing? The US on Wednesday said that it’s got up to $5 million in Rewards for Justice money if you cough up useful details, which you can do here. The FBI and the Departments of State, Treasury, and Homeland Security (DHS) put […]

πŸ“– Read

via "Naked Security".
πŸ•΄ 10 Standout Security M&A Deals from Q1 2020 πŸ•΄

The first quarter of 2020 brought investments in enterprise IoT and endpoint security, as well as billion-dollar investments from private equity firms.

πŸ“– Read

via "Dark Reading: ".
πŸ” How Google Cloud users can combat coronavirus-themed phishing emails πŸ”

Google is striving to block Gmail messages and other content that exploit COVID-19, but there are steps users can take to fight such malware.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 'Look for the Helpers' to Securely Enable the Remote Workforce πŸ•΄

CISOs and CIOs, you are our helpers. As you take action to reassure your company, your confidence is our confidence.

πŸ“– Read

via "Dark Reading: ".
πŸ” Microsoft: Do this to secure your remote desktop users πŸ”

More people working from home has led to an increase in remote desktop access, putting corporate systems at risk.

πŸ“– Read

via "Security on TechRepublic".
❌ Hackers Update Age-Old Excel 4.0 Macro Attack ❌

XLS files sent via emails appear password protected but aren’t, opening automatically to install malware from compromised macros, according to researchers.

πŸ“– Read

via "Threatpost".
❌ Zoom Bombing Attack Hits U.S. Government Meeting ❌

A recent U.S. House Oversight Committee meeting was the latest victim of Zoom bombing, according to an internal letter.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cybersecurity Home-School: The Robot Project πŸ•΄

This fun project can teach your home-bound children and teens about cybersecurity (and keep them occupied for at least a little while).

πŸ“– Read

via "Dark Reading: ".
πŸ›  Falco 0.22.1 πŸ› 

Sysdig falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
ATENTIONβ€Ό New - CVE-2019-12002

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12001

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Microsoft: Our new machine learning model spots critical security bugs 97% of the time πŸ”

Microsoft claims a machine learning models its built for software developers can distinguish between security and non-security bugs 99% of the time.

πŸ“– Read

via "Security on TechRepublic".