πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Verizon DBIR: Web App Attacks and Security Errors Surge ❌

Threatpost talks to Verizon DBIR co-author Gabriel Bassett about the top takeaways from this year's Data Breach Investigations Report.

πŸ“– Read

via "Threatpost".
πŸ•΄ Coronavirus-Themed Phishing Fears Largely Overblown, Researchers Say πŸ•΄

As COVID-19-themed spam rises, phishing-not so much. An analysis of newly registered domains finds that only 2.4% are actually phishing sites aiming to steal credentials.

πŸ“– Read

via "Dark Reading: ".
πŸ” New phishing campaign impersonates LogMeIn to steal user credentials πŸ”

LogMeIn is the parent company of LastPass, so attackers may also be attempting to access the password managers of compromised users, says Abnormal Security.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Nearly 70% of major companies will increase cybersecurity spending post-coronavirus πŸ”

With more people working from home, cybercrimes skyrocketed, forcing companies to rethink tech budgets, LearnBonds found.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Working from home: Why it takes a pandemic to improve work-life "fusion" πŸ”

Adjusting to remote work has created many opportunities and challenges in business and IT.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Warns of Vulnerability Affecting Windows DNS Server πŸ•΄

A new security advisory addresses a vulnerability that could be exploited to cause a denial-of-service attack.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10726

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-10725

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Wireshark Analyzer 3.2.4 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
⚠ Beware of emails with β€œhorrible charts” about Covid-19 ⚠

These charts aren't "horrible" because of their coronavirus data - they're horrible because they could let criminals conquer your computer.

πŸ“– Read

via "Naked Security".
πŸ” Cybercriminals threatening to auction off stolen files from Lady Gaga, Madonna, and (maybe) Donald Trump πŸ”

The hackers claim the high-profile law firm where the files originated has refused to pay their ransom.

πŸ“– Read

via "Security on TechRepublic".
❌ Fraudulent Unemployment, COVID-19 Relief Claims Earn BEC Gang Millions ❌

The business email compromise (BEC) gang Scattered Canary has filed more than 200 fraudulent claims for unemployment benefits and for COVID-19 relief funds.

πŸ“– Read

via "Threatpost".
❌ NetWalker Ransomware Gang Hunts for Top-Notch Affiliates ❌

The operators behind the Toll Group attack are taking applications for technically advanced partners.

πŸ“– Read

via "Threatpost".
πŸ•΄ Digital Transformation Risks in Front-end Code πŸ•΄

Why making every front-end developer a DevSecOps expert will lead to a more holistic approach to web and native application security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Offers to Sell Enterprise Network Access Surge on Dark Web πŸ•΄

In contrast, Q1 2019 saw more interest in selling and buying access to individual servers.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to install sudo 1.9 and use the new policy tool πŸ”

The sudo system is about to undergo some radical changes. Find out how to begin working with the new policy system, to make sudo even more powerful.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 60% of Insider Threats Involve Employees Planning to Leave πŸ•΄

Researchers shows most "flight-risk" employees planning to leave an organization tend to start stealing data two to eight weeks before they go.

πŸ“– Read

via "Dark Reading: ".
πŸ” Money Behind 86 Percent of Data Breaches πŸ”

The number of data breaches for financial gain are up, so are cloud-based data attacks, while cyber-espionage is down, according to the annual report.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Centralized Contact Tracing Raises Concerns Among Privacy-Conscious Citizens πŸ•΄

The long debate over whether encryption and anonymity shield too much criminal behavior also has staged a resurgence.

πŸ“– Read

via "Dark Reading: ".
πŸ” How healthcare organizations can combat cyberattacks during the coronavirus πŸ”

Cyberattacks against hospitals and medical facilities have risen this year, often via ransomware and social engineering exploits, says IntSights.

πŸ“– Read

via "Security on TechRepublic".
⚠ Chrome 83 adds DNS-over-HTTPS support and privacy tweaks ⚠

This week sees the early arrival of Chrome 83 with a longer list of new security features than originally planned.

πŸ“– Read

via "Naked Security".