πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” How state and local governments can better combat cyberattacks πŸ”

Government agencies can suffer from differences in funding, a lack of standard policies, and other issues that affect security, says BlueVoyant.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Fastly to Acquire Signal Sciences for $775M πŸ•΄

Signal Sciences' technology will be used to build a new web application and API security tool called Secure@Edge.

πŸ“– Read

via "Dark Reading: ".
πŸ” How the pandemic and remote work initiatives forced organizations to change IT priorities πŸ”

Global tech professionals reveal recruiting projects fueled by budgets prioritizing staff education, according to a recent IT trends report from Netwrix.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why Vivaldi outshines all other browsers' history management πŸ”

If you're serious about managing your browser's history, Vivaldi makes this task incredibly easy. Jack Wallen shows you how.

πŸ“– Read

via "Security on TechRepublic".
πŸ” North Korean hackers are actively robbing banks around the world, US government warns πŸ”

The BeagleBoyz have made off with nearly $2 billion since 2015, and they're back to attacking financial institutions after a short lull in activity.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to enable guest accounts from the lock screen in Android πŸ”

If you frequently hand your phone over to others, Guest Mode is a feature you should be using on Android. Jack Wallen shows you how to access the feature from your lock screen.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Old Malware Tool Acquires New Tricks πŸ•΄

Latest version of Qbot has acquired a new feature for collecting email threads from Outlook clients.

πŸ“– Read

via "Dark Reading: ".
❌ Ex-Cisco Employee Pleads Guilty to Deleting 16K Webex Teams Accounts ❌

Former Cisco employee Sudhish Kasaba Ramesh admitted to accessing Cisco’s cloud infrastructure and deleting 16,000 Webex Teams employee accounts.

πŸ“– Read

via "Threatpost".
πŸ•΄ Vulnerability Volume Poised to Overwhelm Infosec Teams πŸ•΄

The collision of Microsoft and Oracle patches on the same day has contributed to risk and stress for organizations.

πŸ“– Read

via "Dark Reading: ".
πŸ” A quick and easy way to lock down SSH πŸ”

Anxious to get your Linux server SSH access locked down? Jack Wallen shows you one more step you can take--one that will only take seconds.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ DDoS Attacks Halt NZ Exchange Trading for Third Day πŸ•΄

New Zealand Exchange officials say the motive for the attacks is unclear.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Is China the World's Greatest Cyber Power? πŸ•΄

While the US, Russia, Israel, and several European nations all have sophisticated cyber capabilities, one threat intelligence firm argues that China's aggressive approach to cyber operations has made it "perhaps the world's greatest cyber power."

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10518

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in 2.21.6, 2.20.15, and 2.19.21. The underlying issues contributing to this vulnerability were identified both internally and through the GitHub Security Bug Bounty program.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-10517

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in versions 2.21.6, 2.20.15, and 2.19.21. This vulnerability was reported via the GitHub Bug Bounty program.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Microsoft just made securing Windows 10 PCs a whole lot easier for IT admins πŸ”

New security capabilities designed for SMEs allow IT admins to apply baseline security settings across an organization.

πŸ“– Read

via "Security on TechRepublic".
❌ DoJ Aims to Seize 280 Cryptocurrency Accounts Used by Hackers ❌

Complaint details collaboration with China to funnel $250m in stolen funds as part of state-sponsored attacks.

πŸ“– Read

via "Threatpost".
⚠ Fake Android notifications – first Google, then Microsoft affected ⚠

Were you woken up by a bogus Android notification from Google or Microsoft this week?

πŸ“– Read

via "Naked Security".
πŸ•΄ Redefining What CISO Success Looks Like πŸ•΄

Key to this new definition is the principle that security programs are designed to minimize business risk, not to achieve 100% no-risk.

πŸ“– Read

via "Dark Reading: ".
πŸ” Friday Five 8/28 πŸ”

Ransomware going corporate, Cyber Command changing to a more proactive approach, and cybersecurity professionals weighing in on election security - catch up on all the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Ransomware Red Flags: 7 Signs You're About to Get Hit πŸ•΄

Caught off guard by a ransomware attack? Security experts say the warning signs were there all along.

πŸ“– Read

via "Dark Reading: ".
❌ Elon Musk Confirms, Tesla Factory a Target of Foiled Cyberattack ❌

A Tesla employee was reportedly approached by a Russian national and asked to install malware on the company's systems.

πŸ“– Read

via "Threatpost".