πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud πŸ•΄

Cosmic Lynx takes a sophisticated approach to business email compromise and represents a shift in tactics for Russian cybercriminals.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Drone Path Often Reveals Operator's Location πŸ•΄

The threat posed by drones to critical infrastructure and other operational technology is made more serious by the inability of law enforcement to locate operators, researchers say.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Seizes Domains Used in COVID-19-Themed Attacks πŸ•΄

Court grants company's bid to shut down infrastructure used in recent campaigns against Office 365 users.

πŸ“– Read

via "Dark Reading: ".
πŸ” FBI Warns of Increase in Fake, COVID-Related Unemployment Claims πŸ”

The Federal Bureau of Investigation said this week that its seen a spike in fraudulent unemployment insurance claims related to the pandemic.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” CompTIA joins the battle to recruit high school and college students into cybersecurity πŸ”

The certification company will host prep sessions for the National Cyber League's cybersecurity competitions for individuals and teams.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why people forget their email passwords the most often πŸ”

Many users save their email password and so don't remember it if they have to enter or reset it, says NordPass.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Treasury Releases Fraud and Money Mule ID Tips πŸ•΄

A new advisory from FinCEN helps financial institutions spot illicit activities and actors.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-20896

WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Keeper Threat Group Rakes in $7M from Hundreds of Compromised E-Commerce Sites ❌

Researchers warn that Keeper, using Magecart code, will launch increasingly sophisticated attacks against online merchants worldwide in the coming months.

πŸ“– Read

via "Threatpost".
❌ BEC Hotshot with Opulent Social Media Presence to Face U.S. Charges ❌

The Nigerian native has been extradited from Dubai after a string of over-the-top Instagram posts.

πŸ“– Read

via "Threatpost".
πŸ•΄ EDP Renewables Confirms Ransomware Attack πŸ•΄

Its North American branch was notified of the attack because intruders reportedly gained access to 'at least some information' stored in its systems.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-15008

A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-12821

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-12736

Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. If the administrator entered template language code in the subject line, that code could be interpreted by the email generation services, potentially resulting in server-side code injection.

πŸ“– Read

via "National Vulnerability Database".
⚠ Kinda sorta weakened version of EARN IT Act creeps closer ⚠

Critics say the amended bill that's headed for a full Senate hearing still threatens encryption, albeit less blatantly.

πŸ“– Read

via "Naked Security".
πŸ” How managed service providers can pose a risk to their customers πŸ”

The US Secret Service has warned organizations about a rise in hacks of MSPs and offers advice on how to beef up security.

πŸ“– Read

via "Security on TechRepublic".
❌ 15 Billion Credentials Currently Up for Grabs on Hacker Forums ❌

Unprecedented amounts of data for accessing bank accounts and streaming services are being flogged on the dark web.

πŸ“– Read

via "Threatpost".
⚠ Mozilla turns off β€œFirefox Send” following malware abuse reports ⚠

Sadly, the easier and safer you make your file sharing service, the more attractive it becomes to the crooks.

πŸ“– Read

via "Naked Security".
πŸ•΄ A Most Personal Threat: Implantable Devices in Secure Spaces πŸ•΄

Do implantable medical devices pose a threat to secure communication facilities? A Virginia Tech researcher says they do, and the problem is growing.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why Cybersecurity's Silence Matters to Black Lives πŸ•΄

The industry is missing an opportunity to educate the public about bad actors who capitalize off of protest, voting rights education and police brutality petitions through social engineering and phishing attacks.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Seizes Malicious Domains Used in Mass Office 365 Attacks ❌

The phishing campaign targeted Office 365 accounts in 62 countries, using business-related reports and the coronavirus pandemic as lures.

πŸ“– Read

via "Threatpost".