πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Singapore’s Contact Tracing Wearable Causes Privacy Backlash ❌

Thousands have signed a petition that underscores data privacy issues with Singapore's newly announced contact-tracing wearable, in development.

πŸ“– Read

via "Threatpost".
πŸ•΄ Chinese and Iranian APT Groups Targeted US Presidential Campaigns πŸ•΄

Google analysts report advanced persistent threat groups linked to China and Iran launched phishing attacks against the Biden and Trump campaigns.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ DARPA Launches Bug Bounty Program πŸ•΄

Unlike most crowdsourced vulnerability-hunting projects, this one is targeted at hardware defenses.

πŸ“– Read

via "Dark Reading: ".
πŸ” 10 takeaways from Mimecast's 2020 email security report πŸ”

Phishing is on the rise, ransomware continues to be a threat, and email exploits are more popular than ever. Here are the email security risks, and what you can do about them, in 2020.

πŸ“– Read

via "Security on TechRepublic".
⚠ Brave CEO apologises for adding affiliate links to URLs ⚠

The Brave browser has provoked unhappiness among some of its users after being caught redirecting searches to affiliate links that earned it commission.

πŸ“– Read

via "Naked Security".
πŸ” Security faux pas: 56% of employees use personal computers to WFH πŸ”

Using nonwork authorized tech at home places company data at risk, especially since 23% of employees are unsure what security protocols exist on their devices, Morphisec found.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Cybercrime against retail brands is up 41% during pandemic πŸ”

A dramatic uptick in scams, counterfeiting, and hacking plague retail and e-commerce industries during the coronavirus crisis, as businesses try to define their new normal.

πŸ“– Read

via "Security on TechRepublic".
⚠ Cryptomining criminals under the spotlight – a SophosLabs report ⚠

A new SophosLabs report takes you inside a cryptomining gang.

πŸ“– Read

via "Naked Security".
πŸ•΄ CSO's Guide to 'Employee-First' Security Operations During COVID-19 & Beyond πŸ•΄

As the work-at-home environment continues to inform new ways of doing business, it's important that security teams remain flexible and ready for change.

πŸ“– Read

via "Dark Reading: ".
πŸ” A strong relationship between security and engineering teams accelerates the transition to DevSecOps πŸ”

Embracing an "everyone is part of the security team" approach shifts DevOps to DevSecOps, according to a report from Cobalt.io.

πŸ“– Read

via "Security on TechRepublic".
❌ Dark Basin Hack-For-Hire Group Targeted Thousands Over 7 Years ❌

Thousands of journalists, advocacy groups and politicians worldwide were targeted by Dark Basin.

πŸ“– Read

via "Threatpost".
πŸ•΄ Honda Pauses Production Due to Cyberattack πŸ•΄

The attack reportedly infected internal servers and forced Honda to halt production at plants around the world on Monday.

πŸ“– Read

via "Dark Reading: ".
❌ Adobe Warns of Critical Flaws in Flash Player, Framemaker ❌

Critical Adobe Flash Player and Framemaker flaws could enable arbitrary code execution.

πŸ“– Read

via "Threatpost".
⚠ Facebook labels β€˜state-controlled’ Russian, Chinese, Iranian media ⚠

Facebook users will see notices labeling "state-controlled media", based on criteria such as funding, editorial independence, ownership structure and more.

πŸ“– Read

via "Naked Security".
πŸ›  Haveged 1.9.9 πŸ› 

haveged is a daemon that feeds the /dev/random pool on Linux using an adaptation of the HArdware Volatile Entropy Gathering and Expansion algorithm invented at IRISA. The algorithm is self-tuning on machines with cpuid support, and has been tested in both 32-bit and 64-bit environments. The tarball uses the GNU build mechanism, and includes self test targets and a spec file for those who want to build an RPM.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Hack-for-Hire Firm Connected to Attacks on Nonprofits, Journalists πŸ•΄

The Dark Basin group behind thousands of phishing and malware attacks is likely an India-based "ethical hacking" firm that works on behalf of commercial clients.

πŸ“– Read

via "Dark Reading: ".
❌ Espionage Group Hits U.S. Utilities with Sophisticated Spy Tool ❌

The FlowCloud modular remote-access trojan (RAT) has overlaps with the LookBack malware.

πŸ“– Read

via "Threatpost".
πŸ•΄ Will Vote-by-App Ever Be Safe? πŸ•΄

Even with strong security measures, Internet voting is still vulnerable to abuse from state-sponsored actors and malicious insiders.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft June Patch Tuesday Fixes 129 Flaws in Largest-Ever Update ❌

The June Patch Tuesday update included CVEs for 11 critical remote code-execution vulnerabilities and concerning SMB bugs.

πŸ“– Read

via "Threatpost".
πŸ” Macy’s to Settle 2018 Data Breach Class Action Suit πŸ”

Two years after it happened, the popular department store is electing to settle a class action data breach lawsuit that alleged the company failed to properly secure customer data online.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ DHS Warns on New Exploit of Windows 10 Vulnerability πŸ•΄

The vulnerability was patched in March, but a new proof of concept raises the stakes for organizations that haven't yet updated their software.

πŸ“– Read

via "Dark Reading: ".