πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Bit-and-Piece DDoS Method Emerges to Torment ISPs ❌

Perpetrators are using smaller, bit-and-piece methods to inject junk into legitimate traffic, causing attacks to bypass detection rather than sounding alarms with large, obvious attack spikes.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ” IoT credential compromise attacks open your devices up to spying πŸ”

Security updates for the lifespan of a given device are critical to protecting your connected device against hackers, according to a Barracuda report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Rise of multicloud: 58% of businesses using combination of AWS, Azure, or Google Cloud πŸ”

Multicloud is much more popular than hybrid cloud, with only 33% of professionals using a hybrid model, according to a Kentik report.

πŸ“– Read

via "Security on TechRepublic".
❌ ThreatList: Credential-Sniffing Phishing Attacks Erupted in 2018 ❌

Credential compromise emerged the main target for phishing campaigns in 2018 - rather than infecting victims' devices with malware.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Cloud Customers Faced 681M Cyberattacks in 2018 πŸ•΄

The most common attacks involved software vulnerabilities, stolen credentials, Web applications, and IoT devices.

πŸ“– Read

via "Dark Reading: ".
πŸ” Hackers are still using cloud services to mask attack origin and build false trust πŸ”

Using Google App Engine to mask the destination of links is a staggeringly easy way to conduct a phishing campaign, but Google claims it is not their problem.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ New Phishing Campaign Hits With Triple Threat πŸ•΄

Attack threatens victims with three "deadly malware" infestations if they don't give up critical email account credentials.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New Phishing Campaign Packs Triple Threat πŸ•΄

Attack threatens victims with three "deadly malware" infestations if they don't give up critical email account credentials.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to integrate SSH key authentication into KeePassXC πŸ”

Make using SSH key authentication a snap with the new ssh-agent feature found in KeePassXC.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Collateral Damage: When Cyberwarfare Targets Civilian Data πŸ•΄

You can call it collateral damage. You can call it trickledown cyberwarfare. Either way, foreign hacker armies are targeting civilian enterprises - as a means of attacking rival government targets.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Database of 24 Million Mortgage, Loan Records Left Exposed Online πŸ•΄

Breach latest example of how misconfigurations, human errors undermine security in a big way, experts say.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cyberattackers Bait Financial Firms with Google Cloud Platform πŸ•΄

A new wave of attacks abuses the Google Cloud Platform URL redirection in PDF decoys, sending users to a malicious link.

πŸ“– Read

via "Dark Reading: ".
❌ Fighting Fire with Fire: API Automation Risks ❌

A look at API attack trends such as the current (and failing) architectural designs for addressing security of these API transactions.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Cisco Study Finds Fewer Data Breaches at GDPR-Ready Firms πŸ•΄

Many organizations find that getting their data privacy house in order is paying off.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-18359

PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty geometries are mishandled.

πŸ“– Read

via "National Vulnerability Database".
⚠ Facebook debuts scam ads reporting tool ⚠

Adverts on Facebook featuring fake celebrity endorsements scam people out of their savings, and Facebook is now doing something about it.

πŸ“– Read

via "Naked Security".
⚠ Cops catch $15m crypto-crook ⚠

A man has been arrested a year after stealing €10m ($15m) of the IoT-focused cryptocurrency IOTA using bogus software that tricked users.

πŸ“– Read

via "Naked Security".
⚠ US gov declares emergency after wave of domain hijacking attacks ⚠

The US Department of Homeland Security (DHS) has issued an emergency directive tightening DNS security after a recent wave of domain hijacking attacks targeting government websites.

πŸ“– Read

via "Naked Security".