πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Is CVSS the Right Standard for Prioritization? πŸ•΄

More than 55% of open source vulnerabilities are rated high or critical. To truly understand a vulnerability and how it might affect an organization or product, we need much more than a number.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybersecurity: Half of businesses have had remote working security scares πŸ”

The rapid move to remote working has left many businesses more vulnerable to cybersecurity threats, with nearly half saying they've encountered at least one scare as a direct result of the shift.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Security concerns intensify amid shift to remote working πŸ”

More than half of the professionals surveyed for Barracuda Networks said their workforce isn't properly trained to handle the risks associated with remote working.

πŸ“– Read

via "Security on TechRepublic".
πŸ” 'Hackers Google people': Millions still using sports team, hometown, band, or child names as passwords πŸ”

Ahead of World Password Day, researchers are finding troubling trends despite numerous breaches and hacks.

πŸ“– Read

via "Security on TechRepublic".
❌ Ransomware Attack Takes Down Toll Group Systems, Again ❌

Australian transportation company Toll Group has been hit by the Nefilim ransomware, causing customers to experience delays.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-19169

Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19168

Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox 76.0 released with critical security patches – update now ⚠

Firefox's latest version is out, with new password management features and a raft of security fixes.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-19167

Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19166

Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-4266

IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160199.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Shells Out $100K for IoT Security ❌

A three-month Azure Sphere bug-bounty challenge will offer top rewards for compromising Pluton or Secure World within Microsoft's IoT security suite.

πŸ“– Read

via "Threatpost".
πŸ” Healthcare organizations targeted with password spraying attacks πŸ”

Malicious campaigns are using password spraying as a type of brute-force attack to find weak passwords at healthcare and medical facilities.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Survey: Over half of employees admit to watching adult content on work devices πŸ”

A study from Kaspersky also reveals significant changes in the ways people work since COVID-19.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ When Achieving Deadpool Status Is a Good Thing πŸ•΄

It means attackers have been met with sufficient resistance that it's no longer worth their trouble and have moved on

πŸ“– Read

via "Dark Reading: ".
πŸ” Coronavirus-themed spam surged 14,000% in two weeks says IBM πŸ”

Since February, spam exploiting the novel coronavirus has jumped by 4,300% and 14,000% in the past 14 days, according to IBM X-Force, IBM's threat intelligence group.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Zoom 5.0: How to better secure meetings with the latest features πŸ”

With the new 5.0 version of Zoom, the app has added features to help you protect your virtual meetings from Zoombombing and other unwanted intrusion.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The Price of Fame? Celebrities Face Unique Hacking Threats πŸ•΄

Hackers are hitting the sports industry hard on social media and luring quarantined consumers with offers of free streaming services, a new report shows.

πŸ“– Read

via "Dark Reading: ".
πŸ” CPRA – a.k.a. CCPA 2.0 – Qualifies for 2020 Ballot πŸ”

The California Privacy Rights Act, a new data privacy effort introduced to narrow the scope of the California Consumer Privacy Act, now has enough support to make it onto the November 2020 ballot.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” How to protect yourself from coronavirus-related SMS spam πŸ”

Spammers are sending text messages with deceptive links designed to exploit interest and fear around COVID-19, says AdaptiveMobile Security.

πŸ“– Read

via "Security on TechRepublic".
❌ InfinityBlack Dismantled After Selling Millions of Credentials ❌

In the Europol-led takedown, police shut down databases with more than 170 million entries.

πŸ“– Read

via "Threatpost".