πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Study throws security shade on freelance and student programmers ⚠

A recent study shows that if you aren't prepared to ask or pay for security, you probably won't get it.

πŸ“– Read

via "Naked Security".
πŸ” Business PC users are most at risk in these 10 countries πŸ”

Some 11% of US business computers are at risk of malware infection, compared to 20% of home PCs, according to an Avast report.

πŸ“– Read

via "Security on TechRepublic".
⚠ Facebook sues developers over data-scraping quizzes ⚠

Downloaded by 63K users, the quizzes promised answers to questions such as "What kind of dog are you according to your zodiac sign?"

πŸ“– Read

via "Naked Security".
πŸ” 25% of software vulnerabilities remain unpatched for more than a year πŸ”

Smaller organizations are more agile at patching vulnerabilities, and vendor support goes a long way in easing patching, according to a report from Kenna Security and the Cyentia Institute.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The 12 Worst Serverless Security Risks πŸ•΄

A new guide from the Cloud Security Alliance offers mitigations, best practices, and a comparison between traditional applications and their serverless counterparts.

πŸ“– Read

via "Dark Reading: ".
❌ Adobe Patches Critical Photoshop, Digital Edition Flaws ❌

Adobe fixed two arbitrary code execution flaws in its Photoshop and Digital Edition products.

πŸ“– Read

via "Threatpost".
❌ Unpatched Windows Bug Allows Attackers to Spoof Security Dialog Boxes ❌

Microsoft won't be patching the bug, but a proof of concept shows the potential for successful malware implantation.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cybercriminals Think Small to Earn Big πŸ•΄

As the number of breaches increased 424% in 2018, the average breach size shrunk 4.7 times as attackers aimed for smaller, more vulnerable targets.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-17944

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Misconfigured Box Accounts Yield Sensitive Data πŸ”

Nearly 100 companies were exposing sensitive data, including raw CAD files and Social Security Numbers, on misconfigured Box accounts.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ 5 Essentials for Securing and Managing Windows 10 πŸ•΄

It's possible to intelligently deploy and utilize Windows 10's many security enhancements while avoiding common and costly migration pitfalls.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ It Takes an Average of 3 to 6 Months to Fill a Cybersecurity Job πŸ•΄

Meanwhile, organizations are looking at nonconventional ways to staff up and train their workforce as technical expertise gets even harder to find.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Box Mistakes Leave Enterprise Data Exposed πŸ•΄

User errors in enterprise Box accounts have left hundreds of thousands of sensitive documents exposed to thieves and peeping toms.

πŸ“– Read

via "Dark Reading: ".
❌ ThreatList: Phishing Attacks Doubled in 2018 ❌

Scammers used both older, tested-and-true phishing tactics in 2018 - but also newer tricks, such as fresh distribution methods, according to a new report.

πŸ“– Read

via "Threatpost".
❌ Microsoft Patches Two Win32k Bugs Under Active Attack ❌

Microsoft's March Patch Tuesday updates include 64 fixes, 17 of which are rated critical.

πŸ“– Read

via "Threatpost".
πŸ•΄ How the Best DevSecOps Teams Make Risk Visible to Developers πŸ•΄

DevOps-minded CISOs say enterprise security teams need to do a better job scoring and visualizing risk for developers and business executives.

πŸ“– Read

via "Dark Reading: ".
❌ Federal Focus on Cyber Plays Out in President’s Budget, IoT Legislation ❌

Money earmarked for the Defense Department and DHS, and bipartisan bills to address the security of federal IoT devices, showcase growing federal cyber-efforts.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Patch Tuesday: 64 Vulnerabilities Patched, 2 Under Attack πŸ•΄

Seventeen vulnerabilities patches today are rated critical, four are publicly known, and two have been exploited in the wild.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Citrix Breach Underscores Password Perils πŸ•΄

Attackers used a short list of passwords to knock on every digital door to find vulnerable systems in the vendor's network.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Web Apps are Becoming Less Secure πŸ•΄

Critical vulnerabilities in web applications tripled in 2018, according to a new study.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ There May be A Ceiling on Vulnerability Remediation πŸ•΄

Most organizations are doing all they can to keep up with the release of vulnerabilities, new research shows.

πŸ“– Read

via "Dark Reading: ".