πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 'KryptoCibule' Uses Several Tricks to Maximize Cryptocurrency Theft πŸ•΄

The malware family uses multiple tactics to steal as much cryptocurrency as possible while flying under the radar.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Don't Forget Cybersecurity on Your Back-to-School List πŸ•΄

School systems don't seem like attractive targets, but they house lots of sensitive data, such as contact information, grades, health records, and more.

πŸ“– Read

via "Dark Reading: ".
πŸ” Organizations facing nearly 1,200 phishing attacks each month πŸ”

A new study found that email phishing attacks have become more successful during the COVID-19 pandemic.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2020-12621

The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Hidden Costs of Losing Security Talent πŸ•΄

One person's exit can set off a chain of costly events.

πŸ“– Read

via "Dark Reading: ".
πŸ” Data Privacy Legislation in California Keeps Moving Forward πŸ”

Bills that would regulate the sharing of genetic data and carve out coverage in the CCPA of some HIPAA data are close to being laws in California.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Triple-Threat Cryptocurrency RAT Mines, Steals and Harvests ❌

KryptoCibule spreads via pirated software and game torrents.

πŸ“– Read

via "Threatpost".
❌ BEC Wire Transfers Average $80K Per Attack ❌

That number represents a big uptick over Q1.

πŸ“– Read

via "Threatpost".
❌ U.S. Agencies Must Adopt Vulnerability-Disclosure Policies by March 2021 ❌

U.S. agencies must implement vulnerability-disclosure policies by March 2021, according to a new CISA mandate.

πŸ“– Read

via "Threatpost".
πŸ•΄ New Jersey Man Sentenced to 7+ Years for Cyber Breaking & Entering πŸ•΄

The man installed keyloggers, stealing credentials and information on emerging technology development.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Facebook & Twitter Remove Russian Accounts Spreading Disinformation πŸ•΄

The Russia-backed Internet Research Agency has returned with new strategies to sway voters ahead of the 2020 presidential election.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 55% of Cybersquatted Domains Are Malicious or Potentially Fraudulent πŸ•΄

The largest online companies, such as Apple and PayPal, and banks are being targeted by cybersquatters, who are also taking advantage of the pandemic, a study finds.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Most IoT Hardware Dangerously Easy to Crack πŸ•΄

Manufacturers need to invest more effort into protecting root-level access to connected devices, security researcher says.

πŸ“– Read

via "Dark Reading: ".
πŸ” MIT scientists unveil cybersecurity aggregation platform to gauge effective measures πŸ”

The platform allows researchers to analyze cyberattacks without sensitive information being released.

πŸ“– Read

via "Security on TechRepublic".
❌ NSA Mass Surveillance Program Illegal, U.S. Court Rules ❌

The NSA argued its mass surveillance program stopped terrorist attacks - but a new U.S. court ruling found that this is not, and may have even been unconstitutional.

πŸ“– Read

via "Threatpost".
πŸ•΄ 5 Ways for Cybersecurity Teams to Work Smarter, Not Harder πŸ•΄

Burnout is real and pervasive, but some common sense tools and techniques can help mitigate all that.

πŸ“– Read

via "Dark Reading: ".
πŸ” Verizon announces 5G network security advances and deploys Quantum Key Distribution network πŸ”

The carrier conducted trials ahead of 5G launches and says it is one of the first to pilot QKD in the US.

πŸ“– Read

via "Security on TechRepublic".
❌ Python-based Spy RAT Emerges to Target FinTech ❌

The Evilnum APT has added the RAT to its arsenal as part of a big change-up in its TTPs.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2020-12058

Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10679

Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions.

πŸ“– Read

via "National Vulnerability Database".
⚠ Vishing scams use Amazon and Prime as lures – don’t get caught! ⚠

How do you deal with scam calls on a phone number you keep for emergencies?

πŸ“– Read

via "Naked Security".