πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” How to password protect your mobile Nextcloud app πŸ”

If you use the Nextcloud mobile app, you'll want to password protect it to ensure you don't leave your sensitive data open for anyone to see.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ What Government Contractors Need to Know About NIST, DFARS Password Reqs πŸ•΄

Organizations that fail to comply with these rules can get hit with backbreaking fines and class-action lawsuits.

πŸ“– Read

via "Dark Reading: ".
πŸ” TrulySecure biometric solution recognizes users wearing face masks πŸ”

The platform from Sensory helps people adapt to the COVID-19 world, providing a way to unlock devices without having to remove protective face coverings.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Old Spreadsheet Macro Tech Newly Popular with Criminals πŸ•΄

A 30-year-old macro technology for Microsoft Excel is finding new popularity as a cybersecurity attack vector.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Chasing RobbinHood: Up Close with an Evolving Threat πŸ•΄

A security researcher details how RobbinHood has changed and why it remains a threat for businesses to watch.

πŸ“– Read

via "Dark Reading: ".
πŸ” Govt Experienced Fewer Security Incidents in 2019 but Risk Remains High πŸ”

Findings from the latest FISMA report are out and while the number of total cybersecurity incidents in 2019 were down, the federal government continues to face challenges mitigating basic security vulnerabilities.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Phishing attack impersonates IT staff to target VPN users πŸ”

A phishing email claims to send the recipient to a VPN configuration page for home access but instead leads them to a credential-stealing site, said Abnormal Security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Google Faces $5B Lawsuit for Tracking Users in Incognito Mode πŸ•΄

A proposed class-action lawsuit accuses Google of collecting browser data from people who used "private" mode.

πŸ“– Read

via "Dark Reading: ".
❌ Attackers Target 1M+ WordPress Sites To Harvest Database Credentials ❌

An attack over the weekend unsuccessfully targeted 1.3 million WordPress websites, in attempts to download their configuration files and harvest database credentials.

πŸ“– Read

via "Threatpost".
❌ Sophisticated Info-Stealer Targets Air-Gapped Devices via USB ❌

The newly discovered USBCulprit malware is part of the arsenal of an APT known as Cycldek, which targets government entities.

πŸ“– Read

via "Threatpost".
πŸ•΄ RATs 101: The Grimy Trojans That Scurry Through Remote Access Pipes πŸ•΄

Remote Access Trojans (RATs) can be the beginning of very bad things on your network or workstations.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Kaspersky IDs Sophisticated New Malware Targeted at Air-Gapped Systems πŸ•΄

'USBCulprit' is one of several tools that suggest previously known Cycldek group is more dangerous than previous assumed, security vendor says.

πŸ“– Read

via "Dark Reading: ".
πŸ” 30% of remote employees admit to having an online account compromised on a work device πŸ”

A OneLogin survey covered how employees are using work devices for a variety of other things.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2011-2863

Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-1805

Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

πŸ“– Read

via "National Vulnerability Database".
❌ ZLoader-Laced Emails Target Unemployed Victims ❌

Researchers are warning of spear-phishing emails with CV lures that spread the ZLoader malware, which steals banking credentials from victims.

πŸ“– Read

via "Threatpost".
⚠ Google deletes Indian app that deleted Chinese apps ⚠

Google has deleted an app from the Play Store that offered to delete Android software associated with China.

πŸ“– Read

via "Naked Security".
πŸ” Cybercriminals now spoofing job hunters to deploy password-stealing malware πŸ”

Malicious files masquerading as curriculum vitae are being sent to businesses to install malware that can capture passwords and other sensitive information, says Check Point Research.

πŸ“– Read

via "Security on TechRepublic".
⚠ Nuclear missile contractor hacked in Maze ransomware attack ⚠

Attackers hacked and encrypted the computers of a contractor whose clients include the US military, government agencies and major military contractors.

πŸ“– Read

via "Naked Security".
πŸ•΄ What Usability Means to Security Pros πŸ•΄

The last thing cybersecurity executives and practitioners need are even more tools that are difficult to operate. Here's what they look for when assessing new tools.

πŸ“– Read

via "Dark Reading: ".
❌ Google Faces Privacy Lawsuit Over Tracking Users in Incognito Mode ❌

A $5 billion class-action lawsuit filed in a California federal court alleges that Google's Chrome incognito mode collects browser data without people’s knowledge or consent.

πŸ“– Read

via "Threatpost".