πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Podcast: Why Identity Access Management is the New Perimeter ❌

DivvyCloud discusses the changing nature of identity access management (IAM) - and what kind of challenges and opportunities that is creating for businesses.

πŸ“– Read

via "Threatpost".
❌ Apple Jailbreak Zero-Day Gets a Patch ❌

The zero-day vulnerability tracked as CVE-2020-9859 is exploited by the "Uncover" jailbreak tool released last week.

πŸ“– Read

via "Threatpost".
πŸ•΄ Banking on Data Security in a Time of Insecurity πŸ•΄

How banks can maintain security and data integrity in the middle of a pandemic.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to protect your organization against Business Email Compromise attacks πŸ”

BEC scams accounted for half of all cybercrime losses in the US in 2019, according to Check Point Research.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Cybersecurity Spending Hits 'Temporary Pause' Amid Pandemic πŸ•΄

For now, security teams face freezes in projects and hiring - and budget cuts, security industry analysts say.

πŸ“– Read

via "Dark Reading: ".
❌ Octopus Scanner Sinks Tentacles into GitHub Repositories ❌

At least 26 different open-source code repositories were found to be infected with an unusual attack on the open-source software supply chain.

πŸ“– Read

via "Threatpost".
πŸ•΄ Thycotic Buys Onion ID to Extend PAM Portfolio πŸ•΄

The acquisition brings three new products into Thycotic's privileged access management lineup.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybercriminals garnered $1.4B from cryptocurrency crimes in spring 2020 πŸ”

This year could see the second-highest value in cryptocurrency crimes recorded, with coronavirus-themed attacks contributing to growth, CipherTrace found.

πŸ“– Read

via "Security on TechRepublic".
❌ Severe Cisco DoS Flaw Can Cripple Nexus Switches ❌

Cisco has patched a high-severity flaw that could lead to denial-of-service attacks on its Nexus switch lineup.

πŸ“– Read

via "Threatpost".
⚠ The mystery of the expiring Sectigo web certificate ⚠

If you're getting TLS connection errors that suddenly started this weekend, a tired old encryption library might be the problem.

πŸ“– Read

via "Naked Security".
❌ Two Critical Android Bugs Open Door to RCE ❌

Google and Qualcomm both addressed significant vulnerabilities in their June updates.

πŸ“– Read

via "Threatpost".
πŸ•΄ Risk Assessment & the Human Condition πŸ•΄

Five lessons the coronavirus pandemic can teach security professionals to better assess, monitor, manage, and mitigate organizational risk.

πŸ“– Read

via "Dark Reading: ".
πŸ” COVID-19 emergence leads to 37% jump in mobile phishing attacks in 2020 πŸ”

A Lookout study found that organizations could lose millions through the growing number of unmitigated mobile phishing attacks.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-11843

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18624

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18623

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
πŸ” NSA Warns of Exim Flaw Being Exploited by Russian Actors πŸ”

In an advisory last week, the NSA warned that a flaw in the Exim mail transfer agent (MTA) has been exploited by Russian cyber military actors since last August.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Amtrak Breach Rolls Over Frequent Travelers πŸ•΄

The breach exposed usernames and passwords of an undisclosed number of program members.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Companies Fall Short on Mandatory Reporting of Cybercrimes πŸ•΄

Understaffed and under fire, companies fail to report cybercrimes even when they are legally obligated to notify authorities, results of a new survey show.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Mobile Phishing Attacks Increase Sharply πŸ•΄

Organizations need to include smartphones and tablets in their phishing mitigation strategies, a new report suggests.

πŸ“– Read

via "Dark Reading: ".