🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🔐 How to restrict the Nextcloud ONLYOFFICE to groups 🔐

If you're the Nextcloud admin for your company or home office, you might want to restrict who has access to the ONLYOFFICE suite of tools. Jack Wallen shows you how.

📖 Read

via "Security on TechRepublic".
🕴 Many Exchange Servers Are Still Vulnerable to Remote Exploit 🕴

A privilege-escalation vulnerability patched in February by Microsoft continues to affect Exchange servers, with more than 80% of Internet-connected servers remaining vulnerable, one firm reports.

📖 Read

via "Dark Reading: ".
Critical SAP ASE Flaws Allow Complete Control of Databases

Researchers warn of critical flaws in SAP's Sybase Adaptive Server Enterprise software.

📖 Read

via "Threatpost".
TrickBot Adds BazarBackdoor to Malware Arsenal

The stealthy backdoor is delivered via mass-market phishing emails that are well-crafted to appear convincing.

📖 Read

via "Threatpost".
Firefox fixes cryptographic data leakage in latest security update

How time flies - the latest four-weekly Firefox update is out.

📖 Read

via "Naked Security".
🔐 How to password protect your mobile Nextcloud app 🔐

If you use the Nextcloud mobile app, you'll want to password protect it to ensure you don't leave your sensitive data open for anyone to see.

📖 Read

via "Security on TechRepublic".
🕴 What Government Contractors Need to Know About NIST, DFARS Password Reqs 🕴

Organizations that fail to comply with these rules can get hit with backbreaking fines and class-action lawsuits.

📖 Read

via "Dark Reading: ".
🔐 TrulySecure biometric solution recognizes users wearing face masks 🔐

The platform from Sensory helps people adapt to the COVID-19 world, providing a way to unlock devices without having to remove protective face coverings.

📖 Read

via "Security on TechRepublic".
🕴 Old Spreadsheet Macro Tech Newly Popular with Criminals 🕴

A 30-year-old macro technology for Microsoft Excel is finding new popularity as a cybersecurity attack vector.

📖 Read

via "Dark Reading: ".
🕴 Chasing RobbinHood: Up Close with an Evolving Threat 🕴

A security researcher details how RobbinHood has changed and why it remains a threat for businesses to watch.

📖 Read

via "Dark Reading: ".
🔏 Govt Experienced Fewer Security Incidents in 2019 but Risk Remains High 🔏

Findings from the latest FISMA report are out and while the number of total cybersecurity incidents in 2019 were down, the federal government continues to face challenges mitigating basic security vulnerabilities.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 Phishing attack impersonates IT staff to target VPN users 🔐

A phishing email claims to send the recipient to a VPN configuration page for home access but instead leads them to a credential-stealing site, said Abnormal Security.

📖 Read

via "Security on TechRepublic".
🕴 Google Faces $5B Lawsuit for Tracking Users in Incognito Mode 🕴

A proposed class-action lawsuit accuses Google of collecting browser data from people who used "private" mode.

📖 Read

via "Dark Reading: ".
Attackers Target 1M+ WordPress Sites To Harvest Database Credentials

An attack over the weekend unsuccessfully targeted 1.3 million WordPress websites, in attempts to download their configuration files and harvest database credentials.

📖 Read

via "Threatpost".
Sophisticated Info-Stealer Targets Air-Gapped Devices via USB

The newly discovered USBCulprit malware is part of the arsenal of an APT known as Cycldek, which targets government entities.

📖 Read

via "Threatpost".
🕴 RATs 101: The Grimy Trojans That Scurry Through Remote Access Pipes 🕴

Remote Access Trojans (RATs) can be the beginning of very bad things on your network or workstations.

📖 Read

via "Dark Reading: ".
🕴 Kaspersky IDs Sophisticated New Malware Targeted at Air-Gapped Systems 🕴

'USBCulprit' is one of several tools that suggest previously known Cycldek group is more dangerous than previous assumed, security vendor says.

📖 Read

via "Dark Reading: ".
🔐 30% of remote employees admit to having an online account compromised on a work device 🔐

A OneLogin survey covered how employees are using work devices for a variety of other things.

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2011-2863

Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-1805

Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

📖 Read

via "National Vulnerability Database".
ZLoader-Laced Emails Target Unemployed Victims

Researchers are warning of spear-phishing emails with CV lures that spread the ZLoader malware, which steals banking credentials from victims.

📖 Read

via "Threatpost".