πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Warning! Fake Zoom β€œHR meeting” emails phish for your password ⚠

Scammers have turned to employment worries as their latest lure for Zoom phishing scams.

πŸ“– Read

via "Naked Security".
⚠ β€˜Evil GIF’ account takeover flaw patched in Teams ⚠

Microsoft has fixed a flaw in Teams that could have allowed attackers to launch a wormlike attack on multiple accounts by sending one victim a malicious GIF image.

πŸ“– Read

via "Naked Security".
⚠ Coronavirus tracking tool from Apple and Google embraced by Germany ⚠

Germany's ditched a homegrown alternative that featured a centralized database of location data, raising privacy concerns.

πŸ“– Read

via "Naked Security".
❌ Troves of Zoom Credentials Shared on Hacker Forums ❌

Several new databases have been uncovered on underground forums sharing recycled Zoom credentials.

πŸ“– Read

via "Threatpost".
πŸ•΄ New Startup Accurics Tackles Cloud Infrastructure Security πŸ•΄

Accurics offers a free product to prevent "drift" between infrastructure defined through code and infrastructure running in the cloud.

πŸ“– Read

via "Dark Reading: ".
πŸ” Android ransomware attack spoofs the FBI with accusation of pornography πŸ”

The attack accuses victims of possessing pornography, encrypts all files on the device, and then instructs them to pay a fine to unlock the data, according to Check Point Research.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ What's Your Cybersecurity Architecture Integration Business Plan? πŸ•΄

To get the most out of your enterprise cybersecurity products, they need to work together. But getting those products talking to each other isn't easy.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Security Pros Reassigned to IT Tasks in Coronavirus Pandemic πŸ•΄

Most security practitioners surveyed say their job functions have changed during the pandemic, and 90% are now working remotely full time.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Suricata IDPE 5.0.3 πŸ› 

Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
❌ Sophisticated Android Spyware Attack Spreads via Google Play ❌

The PhantomLance espionage campaign is targeting specific victims, mainly in Southeast Asia -- and could be the work of the OceanLotus APT.

πŸ“– Read

via "Threatpost".
❌ WordPress Plugin Bug Opens 100K Websites to Compromise ❌

Legions of website visitors could be infected with drive-by malware, among other issues, thanks to a CSRF bug in Real-Time Search and Replace.

πŸ“– Read

via "Threatpost".
πŸ” Research shows malware is easy to buy, own, and deploy πŸ”

With just a few Bitcoins and a quick search of Dark Web marketplaces, bad actors can become the owners of powerfully malicious tools.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Tech company offers free online cybersecurity training courses πŸ”

Conscious of the state of employment during the pandemic, as well as after, Fortinet offers an opportunity to build skill sets from home.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Cybersecurity professionals are being repurposed during COVID-19 pandemic πŸ”

47% of respondents have been temporarily moved to assist with IT-related tasks during remote work, (ISC)2 survey finds.

πŸ“– Read

via "Security on TechRepublic".
⚠ iPhone β€œword of death” could crash your phone – what you need to know ⚠

Yes, a rogue "word" could freeze up your iPhone - but it's not malware, it doesn't steal data and doesn't do permanent damage.

πŸ“– Read

via "Naked Security".
❌ Hackers Leak Biopharmaceutical Firm’s Data Stolen in Ransomware Attack ❌

The Clop ransomware group has reportedly leaked compromised data of biopharmaceutical company ExecuPharm after a recent cyberattack.

πŸ“– Read

via "Threatpost".
πŸ” Mozilla ranks video call apps by security and privacy features πŸ”

12 of the 15 most popular video call apps meet Mozilla's Minimum Security Standards, according to a new report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Increased Credential Threats in the Age of Uncertainty πŸ•΄

Three things your company should do to protect credentials during the coronavirus pandemic.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-11060

Certain NETGEAR devices are affected by insecure renegotiation. This affects SRX5308 before 2017-02-10, FVS336Gv3 before 2017-02-10, FVS318N before 2017-02-10, and FVS318Gv2 before 2017-02-10.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11059

Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-06, D500 before 2017-01-06, D1500 before 2017-01-06, D3600 before 2017-01-06, D6000 before 2017-01-06, D6100 before 2017-01-06, D6200 before 2017-01-06, D6200B before 2017-01-06, D6300B before 2017-01-06, D6300 before 2017-01-06, DGN1000v3 before 2017-01-06, DGN2200v1 before 2017-01-06, DGN2200v3 before 2017-01-06, DGN2200V4 before 2017-01-06, DGN2200Bv3 before 2017-01-06, DGN2200Bv4 before 2017-01-06, DGND3700v1 before 2017-01-06, DGND3700v2 before 2017-01-06, DGND3700Bv2 before 2017-01-06, JNR1010v1 before 2017-01-06, JNR1010v2 before 2017-01-06, JNR3300 before 2017-01-06, JR6100 before 2017-01-06, JR6150 before 2017-01-06, JWNR2000v5 before 2017-01-06, R2000 before 2017-01-06, R6050 before 2017-01-06, R6100 before 2017-01-06, R6200 before 2017-01-06, R6200v2 before 2017-01-06, R6220 before 2017-01-06, R6250 before 2017-01-06, R6300 before 2017-01-06, R6300v2 before 2017-01-06, R6700 before 2017-01-06, R7000 before 2017-01-06, R7900 before 2017-01-06, R7500 before 2017-01-06, R8000 before 2017-01-06, WGR614v10 before 2017-01-06, WNR1000v2 before 2017-01-06, WNR1000v3 before 2017-01-06, WNR1000v4 before 2017-01-06, WNR2000v3 before 2017-01-06, WNR2000v4 before 2017-01-06, WNR2000v5 before 2017-01-06, WNR2200 before 2017-01-06, WNR2500 before 2017-01-06, WNR3500Lv2 before 2017-01-06, WNDR3400v2 before 2017-01-06, WNDR3400v3 before 2017-01-06, WNDR3700v3 before 2017-01-06, WNDR3700v4 before 2017-01-06, WNDR3700v5 before 2017-01-06, WNDR4300 before 2017-01-06, WNDR4300v2 before 2017-01-06, WNDR4500v1 before 2017-01-06, WNDR4500v2 before 2017-01-06, and WNDR4500v3 before 2017-01-06.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11058

The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.

πŸ“– Read

via "National Vulnerability Database".