πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Cybercrime against retail brands is up 41% during pandemic πŸ”

A dramatic uptick in scams, counterfeiting, and hacking plague retail and e-commerce industries during the coronavirus crisis, as businesses try to define their new normal.

πŸ“– Read

via "Security on TechRepublic".
⚠ Cryptomining criminals under the spotlight – a SophosLabs report ⚠

A new SophosLabs report takes you inside a cryptomining gang.

πŸ“– Read

via "Naked Security".
πŸ•΄ CSO's Guide to 'Employee-First' Security Operations During COVID-19 & Beyond πŸ•΄

As the work-at-home environment continues to inform new ways of doing business, it's important that security teams remain flexible and ready for change.

πŸ“– Read

via "Dark Reading: ".
πŸ” A strong relationship between security and engineering teams accelerates the transition to DevSecOps πŸ”

Embracing an "everyone is part of the security team" approach shifts DevOps to DevSecOps, according to a report from Cobalt.io.

πŸ“– Read

via "Security on TechRepublic".
❌ Dark Basin Hack-For-Hire Group Targeted Thousands Over 7 Years ❌

Thousands of journalists, advocacy groups and politicians worldwide were targeted by Dark Basin.

πŸ“– Read

via "Threatpost".
πŸ•΄ Honda Pauses Production Due to Cyberattack πŸ•΄

The attack reportedly infected internal servers and forced Honda to halt production at plants around the world on Monday.

πŸ“– Read

via "Dark Reading: ".
❌ Adobe Warns of Critical Flaws in Flash Player, Framemaker ❌

Critical Adobe Flash Player and Framemaker flaws could enable arbitrary code execution.

πŸ“– Read

via "Threatpost".
⚠ Facebook labels β€˜state-controlled’ Russian, Chinese, Iranian media ⚠

Facebook users will see notices labeling "state-controlled media", based on criteria such as funding, editorial independence, ownership structure and more.

πŸ“– Read

via "Naked Security".
πŸ›  Haveged 1.9.9 πŸ› 

haveged is a daemon that feeds the /dev/random pool on Linux using an adaptation of the HArdware Volatile Entropy Gathering and Expansion algorithm invented at IRISA. The algorithm is self-tuning on machines with cpuid support, and has been tested in both 32-bit and 64-bit environments. The tarball uses the GNU build mechanism, and includes self test targets and a spec file for those who want to build an RPM.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Hack-for-Hire Firm Connected to Attacks on Nonprofits, Journalists πŸ•΄

The Dark Basin group behind thousands of phishing and malware attacks is likely an India-based "ethical hacking" firm that works on behalf of commercial clients.

πŸ“– Read

via "Dark Reading: ".
❌ Espionage Group Hits U.S. Utilities with Sophisticated Spy Tool ❌

The FlowCloud modular remote-access trojan (RAT) has overlaps with the LookBack malware.

πŸ“– Read

via "Threatpost".
πŸ•΄ Will Vote-by-App Ever Be Safe? πŸ•΄

Even with strong security measures, Internet voting is still vulnerable to abuse from state-sponsored actors and malicious insiders.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft June Patch Tuesday Fixes 129 Flaws in Largest-Ever Update ❌

The June Patch Tuesday update included CVEs for 11 critical remote code-execution vulnerabilities and concerning SMB bugs.

πŸ“– Read

via "Threatpost".
πŸ” Macy’s to Settle 2018 Data Breach Class Action Suit πŸ”

Two years after it happened, the popular department store is electing to settle a class action data breach lawsuit that alleged the company failed to properly secure customer data online.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ DHS Warns on New Exploit of Windows 10 Vulnerability πŸ•΄

The vulnerability was patched in March, but a new proof of concept raises the stakes for organizations that haven't yet updated their software.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Vulnerability in Plug-and-Play Protocol Puts Billions of Devices at Risk πŸ•΄

"CallStranger" flaw in UPnP allows attackers to launch DDoS attacks and scan internal ports, security researcher says.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to install sudo 1.9 and use the new policy tool πŸ”

The sudo system is about to undergo some radical changes. Find out how to begin working with the new policy system, to make sudo even more powerful.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Fixes 129 Bugs in Largest Patch Tuesday Release πŸ•΄

The June release of security updates addresses several remote code execution vulnerabilities in SharePoint, Excel, Windows OLE, and other services.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-3617

Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-3613

DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.

πŸ“– Read

via "National Vulnerability Database".
⚠ Billions of devices affected by UPnP vulnerability ⚠

Stop us if you’ve heard this before but a researcher has uncovered a new security vulnerability affecting many devices running the Universal Plug and Play (UPnP) protocol.

πŸ“– Read

via "Naked Security".