πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-19454

An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x

πŸ“– Read

via "National Vulnerability Database".
❌ ProLock Ransomware Teams Up With QakBot Trojan to Infect Victims ❌

ProLock is relatively new, but already the ransomware is making waves by using QakBot infections to access networks, gain persistence and avoid detection.

πŸ“– Read

via "Threatpost".
πŸ” Irish Data Protection Commission Issues First Fine Against State Agency πŸ”

Ireland's data protection commission confirmed last week it planned to fine a state agency €75,000 for violating the General Data Protection Regulation, or GDPR.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Top 5 things to know about fleeceware πŸ”

Fleeceware is an important cybersecurity threat to be aware of. Tom Merritt offers five things you should know fleeceware apps.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 things to know about fleeceware πŸ”

Fleeceware is an important cybersecurity threat to be aware of. Tom Merritt offers five things you should know fleeceware apps.

πŸ“– Read

via "Security on TechRepublic".
❌ Ransomware Gang Arrested for Spreading Locky to Hospitals ❌

A group of four people calling themselves "Pentaguard" were arrested in house raids.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-17066

In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.

πŸ“– Read

via "National Vulnerability Database".
❌ Verizon Data Breach Report: DoS Skyrockets, Espionage Dips ❌

Denial of Service (DoS), ransomware, and financially-motivated data breaches were the winners in this year's Verizon DBIR.

πŸ“– Read

via "Threatpost".
πŸ” 86% of data breaches are conducted for financial gain πŸ”

Increases in hacking, phishing, and cloud-based attacks have been even more prevalent with the influx of remote work, Verizon found.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How the dark web is handling the coronavirus pandemic πŸ”

Many on the dark web are expressing the same thoughts and fears about COVID-19 as everyone else, while others are looking for ways to profit from it, says Trustwave.

πŸ“– Read

via "Security on TechRepublic".
❌ Clever Phishing Attack Bypasses MFA to Nab Microsoft Office 365 Credentials ❌

The attack discovered by Cofense can steal sensitive user data stored on the cloud as well as find other victims to target.

πŸ“– Read

via "Threatpost".
πŸ•΄ Hackers Hit Food Supply Company πŸ•΄

The attackers behind the REvil ransomware family has also threatened to release personal data on Madonna and other celebrities to the highest bidders.

πŸ“– Read

via "Dark Reading: ".
πŸ” CEOs, CISOs fear becoming the next big breach target πŸ”

Yet, less than half believe their business has an effective cybersecurity strategy in place, according to a Forcepoint survey.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Cybersecurity Extends Far Beyond Security Teams & Everyone Plays a Part πŸ•΄

Security isn't about tools or technology; it's about establishing a broad, fundamental awareness and sense of responsibility among all employees.

πŸ“– Read

via "Dark Reading: ".
⚠ Firefox to tell you if sites are shortening your passwords ⚠

Mozilla is fixing a longstanding password problem to alert users when their password exceeds the maximum length allowed.

πŸ“– Read

via "Naked Security".
⚠ Cash-flashing rapper charged with money laundering for BTC-e ⚠

The FBI nabbed "Plinofficial" when he arrived at Miami airport carrying $20K cash, allegedly made off of the defunct, fraud-fav exchange.

πŸ“– Read

via "Naked Security".
πŸ›  nfstream 5.1.2 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  Falco 0.23.0 πŸ› 

Sysdig falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
❌ Adobe Patches Critical RCE Flaw in Character Animator App ❌

A critical remote code execution flaw in Adobe Character Animator was fixed in an out-of-band Tuesday patch.

πŸ“– Read

via "Threatpost".
πŸ” Encrypt compressed files the easy way from Windows, macOS, or Linux πŸ”

Learn to secure multiple documents by encrypting compressed files on various OSes using a password.

πŸ“– Read

via "Security on TechRepublic".