πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Data breaches cost US companies more than $1.2 trillion last year πŸ”

Unauthorized access was the most common type of attack in 2019, and it was responsible for 40% of all data breaches, says ForgeRock.

πŸ“– Read

via "Security on TechRepublic".
❌ Enterprise Mobile Phishing Attacks Skyrocket Amidst Pandemic ❌

Increase of 37 percent from Q4 2019 to Q1 2020 attributed to creation of remote workforce due to COVID-19 stay-at-home orders.

πŸ“– Read

via "Threatpost".
πŸ•΄ Social Distancing for Healthcare's IoT Devices πŸ•΄

Security pros need to double down around prevention of lateral movement by attackers, especially if IoT devices are connected to the network.

πŸ“– Read

via "Dark Reading: ".
⚠ Amtrak breached, some customers’ logins and PII potentially exposed ⚠

The US rail service hasn't disclosed the number of passengers affected in a 16 April breach.

πŸ“– Read

via "Naked Security".
⚠ VMware flaw allows takeover of multiple private clouds ⚠

VMWare’s VMware Cloud Director has a security flaw that researchers believe could be exploited to compromise multiple customer accounts using the same cloud infrastructure.

πŸ“– Read

via "Naked Security".
πŸ” How to restrict the Nextcloud ONLYOFFICE to groups πŸ”

If you're the Nextcloud admin for your company or home office, you might want to restrict who has access to the ONLYOFFICE suite of tools. Jack Wallen shows you how.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Many Exchange Servers Are Still Vulnerable to Remote Exploit πŸ•΄

A privilege-escalation vulnerability patched in February by Microsoft continues to affect Exchange servers, with more than 80% of Internet-connected servers remaining vulnerable, one firm reports.

πŸ“– Read

via "Dark Reading: ".
❌ Critical SAP ASE Flaws Allow Complete Control of Databases ❌

Researchers warn of critical flaws in SAP's Sybase Adaptive Server Enterprise software.

πŸ“– Read

via "Threatpost".
❌ TrickBot Adds BazarBackdoor to Malware Arsenal ❌

The stealthy backdoor is delivered via mass-market phishing emails that are well-crafted to appear convincing.

πŸ“– Read

via "Threatpost".
⚠ Firefox fixes cryptographic data leakage in latest security update ⚠

How time flies - the latest four-weekly Firefox update is out.

πŸ“– Read

via "Naked Security".
πŸ” How to password protect your mobile Nextcloud app πŸ”

If you use the Nextcloud mobile app, you'll want to password protect it to ensure you don't leave your sensitive data open for anyone to see.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ What Government Contractors Need to Know About NIST, DFARS Password Reqs πŸ•΄

Organizations that fail to comply with these rules can get hit with backbreaking fines and class-action lawsuits.

πŸ“– Read

via "Dark Reading: ".
πŸ” TrulySecure biometric solution recognizes users wearing face masks πŸ”

The platform from Sensory helps people adapt to the COVID-19 world, providing a way to unlock devices without having to remove protective face coverings.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Old Spreadsheet Macro Tech Newly Popular with Criminals πŸ•΄

A 30-year-old macro technology for Microsoft Excel is finding new popularity as a cybersecurity attack vector.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Chasing RobbinHood: Up Close with an Evolving Threat πŸ•΄

A security researcher details how RobbinHood has changed and why it remains a threat for businesses to watch.

πŸ“– Read

via "Dark Reading: ".
πŸ” Govt Experienced Fewer Security Incidents in 2019 but Risk Remains High πŸ”

Findings from the latest FISMA report are out and while the number of total cybersecurity incidents in 2019 were down, the federal government continues to face challenges mitigating basic security vulnerabilities.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Phishing attack impersonates IT staff to target VPN users πŸ”

A phishing email claims to send the recipient to a VPN configuration page for home access but instead leads them to a credential-stealing site, said Abnormal Security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Google Faces $5B Lawsuit for Tracking Users in Incognito Mode πŸ•΄

A proposed class-action lawsuit accuses Google of collecting browser data from people who used "private" mode.

πŸ“– Read

via "Dark Reading: ".
❌ Attackers Target 1M+ WordPress Sites To Harvest Database Credentials ❌

An attack over the weekend unsuccessfully targeted 1.3 million WordPress websites, in attempts to download their configuration files and harvest database credentials.

πŸ“– Read

via "Threatpost".
❌ Sophisticated Info-Stealer Targets Air-Gapped Devices via USB ❌

The newly discovered USBCulprit malware is part of the arsenal of an APT known as Cycldek, which targets government entities.

πŸ“– Read

via "Threatpost".
πŸ•΄ RATs 101: The Grimy Trojans That Scurry Through Remote Access Pipes πŸ•΄

Remote Access Trojans (RATs) can be the beginning of very bad things on your network or workstations.

πŸ“– Read

via "Dark Reading: ".