🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Web Shells Continue to Threaten a Decade Later 🕴

A decade after their first use, Web shells remain a common tool for all stripes of attackers, from common cybercriminals to sophisticated state actors.

📖 Read

via "Dark Reading: ".
Critical GitLab Flaw Earns Bounty Hunter $20K

A GitLab path traversal flaw could allow attackers to read arbitrary files and remotely execute code.

📖 Read

via "Threatpost".
ThreatList: Human-Mimicking Bots Spike, Targeting e-Commerce and Travel

Overall bot activity on the web has soared, with a 26 percent growth rate -- attacks on applications, APIs and mobile sites are all on the rise.

📖 Read

via "Threatpost".
🕴 Web Shells Continue to Threaten 🕴

A decade after their first use, Web shells remain a common tool for all stripes of attackers, from common cybercriminals to sophisticated state actors.

📖 Read

via "Dark Reading: ".
🔐 Messaging apps are getting more use, and it's putting companies at risk 🔐

Businesses need to be aware of the dangers associated with employees using WhatsApp, WeChat, and other communication channels.

📖 Read

via "Security on TechRepublic".
🕴 7 Fraud Predictions in the Wake of the Coronavirus 🕴

It's theme and variations in the fraud world, and fraudsters love -- and thrive -- during chaos and confusion

📖 Read

via "Dark Reading: ".
🔐 Messaging apps are getting more use, and it's putting companies at risk 🔐

Businesses need to be aware of the dangers associated with employees using WhatsApp, WeChat, and other communication channels.

📖 Read

via "Security on TechRepublic".
🕴 Microsoft Warns of Malware Hidden in Pirated Film Files 🕴

An active campaign inserts malicious VBScript into ZIP files posing as downloads for "John Wick 3," "Contagion," and other popular movies.

📖 Read

via "Dark Reading: ".
🕴 7 Secure Remote Access Services for Today's Enterprise Needs 🕴

Secure remote access is a "must" for enterprise computing today, and there are options for you to explore in the dynamic current environment.

📖 Read

via "Dark Reading: ".
Millions of Brute-Force Attacks Hit Remote Desktop Accounts

Automated attacks on Remote Desktop Protocol accounts are aimed at taking over corporate desktops and infiltrating networks.

📖 Read

via "Threatpost".
High-Severity Cisco IOS XE Flaw Threatens SD-WAN Routers

Cisco's IOS XE software for SD-WAN routers has a high-severity insufficient input validation flaw.

📖 Read

via "Threatpost".
🔐 How to enable the new Eyes Open feature for Google Pixel 4 🔐

Google has finally added the Eyes Open requirement for Google Pixel 4 Face Unlock. Learn how to enable it.

📖 Read

via "Security on TechRepublic".
🔏 Outlining IP Protection Best Practices 🔏

A non-profit tech consortium has released a series of best practices that companies should follow in order to protect digital IP

📖 Read

via "Subscriber Blog RSS Feed ".
🕴 86% of Companies Report Network Disruption Amid Remote Work Shift 🕴

Nearly two-thirds say disruptions were at least moderate in severity, and more have seen VPN connectivity issues as employees work from home.

📖 Read

via "Dark Reading: ".
🕴 Election Security in the Age of Social Distancing 🕴

Although the controversial option of voting by mobile app is one pressing consideration, cybersecurity experts agree that there are other, older issues that need to be resolved before November 3.

📖 Read

via "Dark Reading: ".
🕴 Average Ransomware Payments Soared in the First Quarter 🕴

Criminals extorting large amounts of money from big enterprises pulled up the overall average significantly compared with the fourth quarter of 2019, Coveware says.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2016-11061

Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.

📖 Read

via "National Vulnerability Database".
Critical WordPress e-Learning Plugin Bugs Open Door to Cheating

The flaws in LearnPress, LearnDash and LifterLMS could have allowed unauthenticated students to change their grades, cheat on tests and gain teacher privileges.

📖 Read

via "Threatpost".
🔐 Nintendo data breach reportedly caused by credential stuffing 🔐

Attackers used an account checker tool to identify Nintendo accounts with compromised and vulnerable login credentials, says SpyCloud.

📖 Read

via "Security on TechRepublic".
Shade Threat Actors Call It Quits, Release 750K Encryption Keys

The team behind the ransomware, first spotted in late 2014 and typically targeting Russian victims, apologized to victims in a post on GitHub.

📖 Read

via "Threatpost".