🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🔐 How to protect yourself from coronavirus-related SMS spam 🔐

Spammers are sending text messages with deceptive links designed to exploit interest and fear around COVID-19, says AdaptiveMobile Security.

📖 Read

via "Security on TechRepublic".
InfinityBlack Dismantled After Selling Millions of Credentials

In the Europol-led takedown, police shut down databases with more than 170 million entries.

📖 Read

via "Threatpost".
ATENTION New - CVE-2018-8956

ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.

📖 Read

via "National Vulnerability Database".
🕴 Microsoft Reportedly in Talks to Acquire CyberX 🕴

CyberX was founded in 2013 and has raised $48 million to build its cybersecurity platform for IoT and industrial control systems.

📖 Read

via "Dark Reading: ".
🕴 Half of Companies Have Suffered a Cybersecurity Issue Amid COVID-19 Crisis 🕴

Survey shows 49% expect to experience a data breach or cybersecurity incident in the next month.

📖 Read

via "Dark Reading: ".
🕴 Financial Phishing Attacks Take Off, Malware Declines 🕴

In the past year, the number of digital threats increased by nearly half as phishing swamped malware to become the most dominant attack technique.

📖 Read

via "Dark Reading: ".
🕴 What is an 'Endpoint'? 🕴

Some companies' endpoint security strategies may now cover an ever-widening array of devices, as Dark Reading's latest State of Endpoint Security survey discovered.

📖 Read

via "Dark Reading: ".
🔐 Alarming number of pharma executive login credentials available on the Dark Web 🔐

A new report details major vulnerabilities among the executive suite at some of the largest pharmaceutical companies.

📖 Read

via "Security on TechRepublic".
Lazarus Group Hides macOS Spyware in 2FA Application

The Dacls RAT has been ported from an existing Linux version.

📖 Read

via "Threatpost".
🕴 Attacks on WordPress Sites Surge 🕴

Defiant says it observed a 30-fold increase in attacks in just the past few days.

📖 Read

via "Dark Reading: ".
🕴 Maze Ransomware Operators Step Up Their Game 🕴

Investigations show Maze ransomware operators leave "nothing to chance" when putting pressure on victims to pay.

📖 Read

via "Dark Reading: ".
Police nab InfinityBlack hackers

Five alleged members of hacking group InfinityBlack got some unexpected visitors last week when Polish law enforcement arrested them.

📖 Read

via "Naked Security".
Fake news Facebook accounts used coronavirus to attract followers

In April, the company yanked 1,887 misleading accounts, pages and groups tied to eight influencer networks building fake engagement.

📖 Read

via "Naked Security".
🔐 Businesses are overconfident about the state of their security 🔐

60% of remote workers use personal devices, many without protection from their business' cybersecurity, a new report found.

📖 Read

via "Security on TechRepublic".
🔐 Businesses: Beware of COVID-19 email compromise scams 🔐

Palo Alto Networks has found 10 separate coronavirus-themed business email compromise campaigns, and all can be tied back to a single Nigerian group called SilverTerrier.

📖 Read

via "Security on TechRepublic".
Naikon APT Hid Five-Year Espionage Attack Under Radar

The Chinese APT has been discovered behind a five-year espionage campaign that compromises government servers - and uses that as leverage for other attacks.

📖 Read

via "Threatpost".
🔐 Report: Chinese-linked hacking group has been infiltrating APAC governments for years 🔐

Newly released evidence points to the Naikon APT being at the head of a 5-year espionage campaign that has phished information from countries all around the Asia-Pacific region.

📖 Read

via "Security on TechRepublic".
🔐 A passwordless future: How security keys and biometrics are taking over 🔐

Passwords are no longer a secure method of identity verification, resulting in many organizations to turn to other tactics, Yubico found.

📖 Read

via "Security on TechRepublic".
🕴 7 Ways Parents Can Better Protect Their Online-Gamer Offspring 🕴

It's 11 a.m. Are your kids locked in their rooms playing games online?

📖 Read

via "Dark Reading: ".
🔐 Microsoft: We'll give you $100,000 if you can hack our Azure Sphere IoT platform 🔐

Microsoft is offering researchers $100,000 if they can crack the company's custom-built Linux OS for Internet of Things devices.

📖 Read

via "Security on TechRepublic".
Hackers Dumpster Dive for Taxpayer Data in COVID-19 Relief Money Scams

Threat actors are buying and selling taxpayer data on hacker forums as well as using phishing and other campaigns to steal various U.S. government payouts.

📖 Read

via "Threatpost".