πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Shopify Acknowledges Insider Breach of 200 Stores πŸ”

A breach at the popular e-commerce site was linked back to two "rogue" support team employees.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Google Cloud Debuts Threat-Detection Service πŸ•΄

Lockdown economics are driving a threat-intelligence business boom. Chronicle Detect is Google's answer to monitoring so much log data created by the distributed workforce.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Shopify's Employee Data Theft Underscores Risk of Rogue Insiders πŸ•΄

The e-commerce platform has alerted more than 100 merchants of a data breach, highlighting the danger of malicious insiders.

πŸ“– Read

via "Dark Reading: ".
❌ Zerologon Patches Roll Out Beyond Microsoft ❌

A Samba patch and a micropatch for end-of-life servers have debuted in the face of the critical vulnerability.

πŸ“– Read

via "Threatpost".
πŸ•΄ Gaming Industry Hit With 10B+ Attacks In Past Two Years πŸ•΄

Criminals scored big with credential stuffing and web app attacks, yet many gamers seem unfazed.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-4719

The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
⚠ iPhone 12 scam pretends to be Apple β€œchatbot” – don’t fall for it! ⚠

If you got someone else's "free offer" in what looked like a misdirected message, would you take a peek?

πŸ“– Read

via "Naked Security".
πŸ” Synack: Federal agencies and banks have made the most cybersecurity improvements πŸ”

The overall Attacker Resistance Score for the IT sector dropped this year due in part to digital transformation work, according to the 2020 Trust Report.

πŸ“– Read

via "Security on TechRepublic".
❌ Alien Android Banking Trojan Sidesteps 2FA ❌

A new 'fork' of the Cerberus banking trojan, called Alien, targets victims' credentials from more than 200 mobile apps, including Bank of America and Microsoft Outlook.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Warns of Attackers Now Exploiting 'Zerologon' Flaw πŸ•΄

The Security Intelligence team at Microsoft is tracking newly waged exploits in the wild.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ CrowdStrike Agrees to Acquire Preemptive Security for $96M πŸ•΄

CrowdStrike plans to use Preemptive Security's conditional access technology to strengthen its Falcon platform.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to install the Graylog system log manager on Ubuntu Server 20.04 πŸ”

Combing through logs on numerous servers can be a chore. Learn how to simplify that with the Graylog monitoring server.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ CrowdStrike Agrees to Acquire Preempt Security for $96M πŸ•΄

CrowdStrike plans to use Preempt Security's conditional access technology to strengthen its Falcon platform.

πŸ“– Read

via "Dark Reading: ".
❌ Free Apple iPhone 12? Chatbot Scam Spreads Via Texts ❌

Convincing SMS messages tell victims that they've been selected for a pre-release trial for the soon-to-be-launched device.

πŸ“– Read

via "Threatpost".
πŸ” SEC Looks to Tamp Down Credential Stuffing πŸ”

The SEC's compliance arm is encouraging banks and financial institutions to remain vigilant in the face of an uptick in credential stuffing attacks.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ›  Falco 0.26.0 πŸ› 

Sysdig Falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  Wireshark Analyzer 3.2.7 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Critical Instagram Flaw Could Let Attackers Spy on Victims πŸ•΄

A now-patched remote code execution vulnerability could be exploited with a specially sized image file, researchers report.

πŸ“– Read

via "Dark Reading: ".
❌ Cisco Patch-Palooza Tackles 29 High-Severity Bugs ❌

Patches and workaround fixes address flaws on networking hardware running Cisco IOS XE software.

πŸ“– Read

via "Threatpost".