🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🔐 Watch out for these subject lines in email phishing attacks 🔐

Campaigns exploiting COVID-19 remained popular last quarter, but cybercriminals also relied on tried and true subjects, says KnowBe4.

📖 Read

via "Security on TechRepublic".
🕴 Third-Party IoT Vulnerabilities: We Need a Cybersecurity Paradigm Shift 🕴

The only entities equipped to safeguard Internet of Things devices against risks are the IoT device manufacturers themselves.

📖 Read

via "Dark Reading: ".
🔐 Check Point helps Zoom resolve "Vanity URL" security problem 🔐

The loophole gave cybercriminals an opening through specialized Zoom URL links.

📖 Read

via "Security on TechRepublic".
🔐 How COVID-19 has increased the risk of security threats 🔐

During the first half of the year, 80% of companies surveyed saw "slightly to considerably more" cyberattack attempts, says Exabeam.

📖 Read

via "Security on TechRepublic".
🔐 How to use the Google Pixel Safety Check feature 🔐

The Android-powered Google Pixel line of phones received a very important updated feature dedicated to user's personal safety. Learn how to use the Safety Check feature.

📖 Read

via "Security on TechRepublic".
🔐 Credential stuffing attacks on global media companies are spiking 🔐

A new report from Akamai also finds a staggering increase in attacks targeting published content.

📖 Read

via "Security on TechRepublic".
🔐 820% jump in e-gift card bot attacks since COVID-19 lockdowns began 🔐

The biggest victims were online food-delivery services and retailers, says cybersecurity firm PerimeterX.

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2019-4748

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-4747

IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172887.

📖 Read

via "National Vulnerability Database".
Zoom Addresses Vanity URL Zero-Day

An attacker could pose as a company employee, invite customers or partners to meetings, then use socially engineered conversation to extract sensitive information.

📖 Read

via "Threatpost".
🕴 Russian Cyberattacks Target COVID-19 Research, Vaccine Development 🕴

Government agencies in the US, UK, and Canada report Russian group Cozy Bear is targeting organizations developing coronavirus vaccines.

📖 Read

via "Dark Reading: ".
🔐 How to protect your Twitter account from being hacked 🔐

Following the hacks of verified Twitter accounts for several high-profile people, including Bill Gates and Joe Biden, how can you prevent your own account from falling into the wrong hands?

📖 Read

via "Security on TechRepublic".
State-Sponsored Hackers Look to Steal COVID-19 Vaccine Research

The Russia-linked APT29 has set its sights on pharma research in Western nations in a likely attempt to get ahead on a cure for coronavirus.

📖 Read

via "Threatpost".
🕴 Cybersecurity Leaders: Invest In Your People 🕴

Training, especially cross-training, is insanely powerful when team members are able to experience, train, and work together. It also builds trust.

📖 Read

via "Dark Reading: ".
🔐 Cybercriminals disguising as top streaming services to spread malware 🔐

Malicious actors are posing as Netflix, Hulu, and more, to launch phishing attacks, steal passwords, launch spam, and distribute viruses.

📖 Read

via "Security on TechRepublic".
🕴 Twitter Attack Raises Concerns Over its Internal Controls 🕴

Attackers temporarily gained control of the accounts of Joe Biden, Barack Obama, Bill Gates, and others, to tweet a bitcoin scam.

📖 Read

via "Dark Reading: ".
🛠 Falco 0.24.0 🛠

Sysdig falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

📖 Go!

via "Security Tool Files ≈ Packet Storm".
🕴 EU Court Ruling Means New Global Protections for EU Customer Data 🕴

The ruling in a case involving Facebook means that international companies must provide EU-level privacy controls for EU-generated data no matter where it's stored or transferred.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2019-20915

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20914

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20913

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.

📖 Read

via "National Vulnerability Database".