πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Celebrity personal data taken in ransomware attack ⚠

Ransomware crooks are apparently threatening to dump personal data for a long of celebs including Lady Gaga, Madonna, Nicki Minaj and more.

πŸ“– Read

via "Naked Security".
❌ Sphinx Malware Returns to Riddle U.S. Targets ❌

The banking trojan has upgraded and is seeing a resurgence on the back of coronavirus stimulus payment themes.

πŸ“– Read

via "Threatpost".
❌ Millions of Thunderbolt-Equipped Devices Open to β€˜ThunderSpy’ Attack ❌

If an attacker can get his hands on a Thunderbolt-equipped device for five minutes, he can launch a new data-stealing attack called "Thunderspy."

πŸ“– Read

via "Threatpost".
πŸ” CISOs forced to adapt to pandemic and other geopolitical risks πŸ”

A new report finds cyber resilience, security culture, and cloud security are hot topics for chief information security officers.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Phishing campaign caught spoofing Zoom πŸ”

The campaign impersonates Zoom emails, but steals the Microsoft account credentials of its victims, says security firm Abnormal Security.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Survey: Teams supported by mature DevOps practices more likely to integrate automated security πŸ”

Adding security into DevOps hasn't been as easy as automating all the things. Sonatype's survey shows the state of the industryβ€”and what you might want to work on next.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Time for a new job? Check out 16 cybersecurity courses on the basics, SOC skills, and new privacy rules πŸ”

Online training classes for newbies, managers, and privacy officers are on sale this week.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Kaspersky: 73% of workers have received no cybersecurity guidance πŸ”

Millions of employees working remotely have gotten no information about how to keep their devices and home networks safe.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-1285

Apache log4net before 2.0.8 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.

πŸ“– Read

via "National Vulnerability Database".
πŸ” FTC To Review Healthcare Data Breach Notification Rule πŸ”

The FTC is seeking comment on whether or not it should make changes to its Health Breach Notification Rule, a rule that compels orgs to disclose when health records are breached.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Researchers Analyze Oracle WebLogic Flaw Under Attack πŸ•΄

Trend Micro researchers explain how attackers bypassed the patch for a deserialization vulnerability in the Oracle WebLogic Server.

πŸ“– Read

via "Dark Reading: ".
πŸ” At UPS, big data is redefining the supply chain πŸ”

Billions of data points are gathered throughout the UPS network every week. Find out how the information collected is revolutionizing the logistics giant.

πŸ“– Read

via "Security on TechRepublic".
❌ Unpatched Bugs in Oracle iPlanet Open Door to Info-Disclosure, Injection ❌

CVE-2020-9315 and CVE-2020-9314 in iPlanet version 7 will not receive patches.

πŸ“– Read

via "Threatpost".
❌ Astaroth’s New Evasion Tactics Make It β€˜Painful to Analyze’ ❌

The infostealer has gone above and beyond in its new anti-analysis and obfuscation tactics.

πŸ“– Read

via "Threatpost".
πŸ•΄ Thunderbolt Vulnerabilities Could Threaten Millions of PCs πŸ•΄

Attackers with physical access to targeted machines could exploit these flaws to access and copy data within minutes, researchers say.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-14200

** REJECT ** Unused CVE for 2017.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 6 Free Cybersecurity Training and Awareness Courses πŸ•΄

Most are designed to help organizations address teleworking risks related to COVID-19 scams.

πŸ“– Read

via "Dark Reading: ".
⚠ Maze ransomware one year on – a SophosLabs report ⚠

The latest SophosLabs report tells the story of how the infamous "Maze" ransomware has evolved over the past 12 months...

πŸ“– Read

via "Naked Security".
❌ Anubis Malware Upgrade Logs When Victims Look at Their Screens ❌

Threat actors are cooking up new features for the sophisticated banking trojan that targets Google Android apps and devices.

πŸ“– Read

via "Threatpost".
⚠ Dating app user logins found on hacking forum ⚠

3.5 million user logins for the MobiFriends dating app are being offered for free on a popular dark web hackers forum.

πŸ“– Read

via "Naked Security".
πŸ•΄ Data Breaches Declined in Q1 2020 Over Q1 2019 -- Or Did They? πŸ•΄

Numbers are down, but that may only be because organizations have been too busy fighting COVID-19-related cyberthreats to notice compromises, Risk Based Security says.

πŸ“– Read

via "Dark Reading: ".