πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Octopus Scanner Sinks Tentacles into GitHub Repositories ❌

At least 26 different open-source code repositories were found to be infected with an unusual attack on the open-source software supply chain.

πŸ“– Read

via "Threatpost".
πŸ•΄ Thycotic Buys Onion ID to Extend PAM Portfolio πŸ•΄

The acquisition brings three new products into Thycotic's privileged access management lineup.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybercriminals garnered $1.4B from cryptocurrency crimes in spring 2020 πŸ”

This year could see the second-highest value in cryptocurrency crimes recorded, with coronavirus-themed attacks contributing to growth, CipherTrace found.

πŸ“– Read

via "Security on TechRepublic".
❌ Severe Cisco DoS Flaw Can Cripple Nexus Switches ❌

Cisco has patched a high-severity flaw that could lead to denial-of-service attacks on its Nexus switch lineup.

πŸ“– Read

via "Threatpost".
⚠ The mystery of the expiring Sectigo web certificate ⚠

If you're getting TLS connection errors that suddenly started this weekend, a tired old encryption library might be the problem.

πŸ“– Read

via "Naked Security".
❌ Two Critical Android Bugs Open Door to RCE ❌

Google and Qualcomm both addressed significant vulnerabilities in their June updates.

πŸ“– Read

via "Threatpost".
πŸ•΄ Risk Assessment & the Human Condition πŸ•΄

Five lessons the coronavirus pandemic can teach security professionals to better assess, monitor, manage, and mitigate organizational risk.

πŸ“– Read

via "Dark Reading: ".
πŸ” COVID-19 emergence leads to 37% jump in mobile phishing attacks in 2020 πŸ”

A Lookout study found that organizations could lose millions through the growing number of unmitigated mobile phishing attacks.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-11843

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18624

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18623

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
πŸ” NSA Warns of Exim Flaw Being Exploited by Russian Actors πŸ”

In an advisory last week, the NSA warned that a flaw in the Exim mail transfer agent (MTA) has been exploited by Russian cyber military actors since last August.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Amtrak Breach Rolls Over Frequent Travelers πŸ•΄

The breach exposed usernames and passwords of an undisclosed number of program members.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Companies Fall Short on Mandatory Reporting of Cybercrimes πŸ•΄

Understaffed and under fire, companies fail to report cybercrimes even when they are legally obligated to notify authorities, results of a new survey show.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Mobile Phishing Attacks Increase Sharply πŸ•΄

Organizations need to include smartphones and tablets in their phishing mitigation strategies, a new report suggests.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 10 Tips for Maintaining Information Security During Layoffs πŸ•΄

Insider cyber threats are always an issue during layoffs -- but with record numbers of home office workers heading for the unemployment line, it's never been harder to maintain cybersecurity during offboarding.

πŸ“– Read

via "Dark Reading: ".
❌ Joomla Resources Directory Users Exposed in Leaky AWS Bucket ❌

Full backup copies of website, including all user data, was exposed for 2,700 JRD users.

πŸ“– Read

via "Threatpost".
⚠ We won! Naked Security scoops β€œLegends of security” award ⚠

We're absolutely delighted - delighted and proud! - to report that we won not one but two awards at last night's European Security Blogger Awards 2020.

πŸ“– Read

via "Naked Security".
πŸ” Return to work: Three tech jobs that companies will be trying to fill πŸ”

Cybersecurity, remote IT troubleshooting and cloud support will be the most sought-after skills for businesses in the months following the COVID-19 pandemic, according to a survey of CIOs and tech executives.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Report: Working from home jeopardizes network security πŸ”

Here's how employees in the US, UK, France and Germany are putting systems at risk, according to CyberArk.

πŸ“– Read

via "Security on TechRepublic".