πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Warner Music Group Admits Breach πŸ•΄

The months-long breach hit financial details for customers.

πŸ“– Read

via "Dark Reading: ".
πŸ” Qualcomm unveils new Snapdragon processor to power 5G computers πŸ”

The Snapdragon 8cx Gen 2 5G chip is designed to bring 5G to commercial and consumer Always On, Always Connected PCs. The processor supports Wi-Fi 6 and offers productivity and security benefits.

πŸ“– Read

via "Security on TechRepublic".
πŸ” What SMBs and startups can learn from securing a presidential campaign πŸ”

Mayor Pete Buttigieg's former CISO and Splunk security advisor Mick Baccio explains the cybersecurity best practices he learned from protecting a presidential candidate's campaign.

πŸ“– Read

via "Security on TechRepublic".
πŸ” What SMBs and startups can learn from securing a presidential campaign πŸ”

Mayor Pete Buttigieg's former CISO and Splunk security advisor Mick Baccio explains the cybersecurity best practices he learned from protecting a presidential candidate's campaign.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Ad Fraud: The Multibillion-Dollar Cybercrime CISOs Might Overlook πŸ•΄

Marketing officers may have accepted ad fraud as a cost of doing business, but infosec pros take heed -- fraud can be a step to more significant attacks. Here's what to know and how to take action.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to move Google Authenticator from one iPhone or Android device to another πŸ”

If you migrated to a different iPhone or Android device and need to transfer Google Authenticator to the new hardware, follow these steps.

πŸ“– Read

via "Security on TechRepublic".
πŸ›  Faraday 3.12 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  GNU Privacy Guard 2.2.23 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  Scapy Packet Manipulation Tool 2.4.4 πŸ› 

Scapy is a powerful interactive packet manipulation tool, packet generator, network scanner, network discovery tool, and packet sniffer. It provides classes to interactively create packets or sets of packets, manipulate them, send them over the wire, sniff other packets from the wire, match answers and replies, and more. Interaction is provided by the Python interpreter, so Python programming structures can be used (such as variables, loops, and functions). Report modules are possible and easy to make. It is intended to do the same things as ttlscan, nmap, hping, queso, p0f, xprobe, arping, arp-sk, arpspoof, firewalk, irpas, tethereal, tcpdump, etc.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ DDoS Attacks on Education Escalate in 2020 πŸ•΄

The number of DDoS attacks affecting educational resources was far higher between February and June 2020 compared with 2019.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How Cybercriminals Take the Fun Out of Gaming πŸ•΄

It's all fun and games until someone loses their V-Bucks, right? Here's how cyberattackers are cheating the gaming biz -- and winning big.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-20916

The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Apple will release iOS 14 without this privacy feature: What iPhone users and developers need to know πŸ”

The iOS 14, iPadOS 14, and tvOS 14 anti-tracking feature is on hold until early 2021 to give developers time to make the necessary changes, according to Apple.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Name That Toon: Mask Out πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading: ".
⚠ Monday review – catch up on our latest articles and videos ⚠

Our recent articles and videos, all in one place.

πŸ“– Read

via "Naked Security".
πŸ” Botnets: A cheat sheet for business users and security admins πŸ”

Almost anything with an internet connection can be hijacked and used in a malicious botnet attack--IoT devices are especially popular targets. Learn how to spot and prevent this malware threat.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Farewell Flash Player: Microsoft tells businesses to get ready for the end of support πŸ”

From January 2021, Flash will be disabled by default in IE 11 and Microsoft Edge browser.

πŸ“– Read

via "Security on TechRepublic".
❌ CEOs Could Be Held Personally Liable for Cyberattacks that Kill ❌

As IT systems, IoT and operational technology converge, attacks on cyber-physical systems in industrial, healthcare and other scenarios will come with dire consequences, Gartner predicts.

πŸ“– Read

via "Threatpost".
❌ How Zero Trust and SASE Can Redefine Network Defenses for Remote Workforces ❌

The SASE model for remote access and security coupled with Zero Trust can help redefine network and perimeter defenses when a traditional β€œperimeter” no longer exists.

πŸ“– Read

via "Threatpost".
πŸ” How to enable Canonical Livepatch from the command line πŸ”

If you have Ubuntu Servers in your data center, you should consider adding Canonical Livepatch to keep them up to date with kernel security patches.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Your work laptop may not be as secure as it should be πŸ”

Nearly a quarter of work computers provided by employers lack any additional security software, research from Kaspersky reveals.

πŸ“– Read

via "Security on TechRepublic".