πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 You definitely don't want to play: Squid Game-themed malware is here 🦿

The stakes may not be as high as in the hit Netflix show, but you could still lose your data or identity if you fail to follow the rules for dodging the latest brand of pop-culture-themed scams.

πŸ“– Read

via "Tech Republic".
❌ Lazarus Attackers Turn to the IT Supply Chain ❌

Kaspersky researchers saw The North Korean state APT use a new variant of the BlindingCan RAT to breach a Latvian IT vendor and then a South Korean think tank.

πŸ“– Read

via "Threat Post".
πŸ•΄ Cybersecurity Talent Gap Narrows as Workforce Grows πŸ•΄

Job satisfaction and salaries have both increased for cybersecurity professionals, as younger workers seek specific training to prepare for a cybersecurity career.

πŸ“– Read

via "Dark Reading".
πŸ•΄ CISA Announces Appointment of Washington Secretary of State Kim Wyman as Senior Election Security Lead πŸ•΄

As an expert on elections, her appointment speaks to the Agency’s dedication to working with election officials throughout the nation in a non-partisan manner to ensure the security and resilience of our election infrastructure.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Gas Stations in Iran Downed by Cyberattack πŸ•΄

Unknown attackers hijacked gasoline pump machines and defaced them with a message that reportedly included a phone number for Supreme Leader Ayatollah Ali Khamenei's office.

πŸ“– Read

via "Dark Reading".
πŸ•΄ IBM Announces Advances and New Collaborations in AI-Powered Automation, 5G Connectivity and Security at Mobile World Congress Los Angeles πŸ•΄

IBM collaborates with Boston Dynamics, Cisco, Palo Alto Networks and Turnium Technology Group to help equip businesses in next phase of digital transformation.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ready to Play? Squid Game Becomes an Attractive Lure to Spread Cyberthreats πŸ•΄

Following demand from viewers, cybercriminals are not shy in taking advantage of fans’ eagerness to watch the show, with well-known fraud schemes hitting the web.

πŸ“– Read

via "Dark Reading".
❌ Public Clouds & Shared Responsibility: Lessons from Vulnerability Disclosure ❌

Much is made of shared responsibility for cloud security. But Oliver Tavakoli, CTO at Vectra AI, notes there's no guarantee that Azure or AWS are delivering services in a hardened and secure manner.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2019-3556 β€Ό

HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which specifies where on the filesystem to write this data. The parameter is not validated, allowing a malicious user to overwrite arbitrary files where the user running HHVM has write access. This issue affects HHVM versions prior to 4.56.2, all versions between 4.57.0 and 4.78.0, as well as 4.79.0, 4.80.0, 4.81.0, 4.82.0, and 4.83.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ North Korea's Lazarus Group Turns to Supply Chain Attacks πŸ•΄

State-backed group is among a growing number of threat actors looking at supply chain companies as an entry point into enterprise networks.

πŸ“– Read

via "Dark Reading".
❌ SquirrelWaffle Loader Malspams, Packing Qakbot, Cobalt Strike ❌

Say hello to what could be the next big spam player: SquirrelWaffle, which is spreading with increasing frequency via spam campaigns and infecting systems with a new malware loader.

πŸ“– Read

via "Threat Post".
πŸ•΄ Free Tool Helps Security Teams Measure Their API Attack Surface πŸ•΄

Data Theorem's free API Attack Surface Calculator helps security teams understand potential API exposures.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2021-23877 β€Ό

Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-22864 β€Ό

A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41866 β€Ό

MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.

πŸ“– Read

via "National Vulnerability Database".
❌ Cyber Attack Cripples Iranian Fuel Distribution Network ❌

The incident triggered shutdowns at pumps across the country as attackers flashed the phone number of Supreme Leader Ali Khamenei across video screens.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Attack the block – How a security researcher cracked 70% of urban WiFi networks in one hit πŸ—“οΈ

A new attack takes advantage of weak WiFi passwords

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Identity-Focused Security Controls Prevail πŸ•΄

How identity and access management strategies held up during the pandemic and tips for putting together an identity security road map.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Annual Cyber Risk Survey Finds Businesses Are Sharpening Their Focus on Cybersecurity but Also Reveals Much Room for Improvement in Building Cyber-Resilience πŸ•΄

This year's survey features the highest percentage of cyber insurance buyers since the beginning of the survey 11 years ago.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cynerio Launches IoT Attack Detection and Response Module for Healthcare IoT Devices πŸ•΄

Module helps hospitals identify, contain, and mitigate threats on devices exhibiting malicious or suspicious behavior.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Onfido Acquires EYN to Provide Acoustic-Based Liveness Detection πŸ•΄

Technology will be incorporated into Onfido’s Real Identity Platform.

πŸ“– Read

via "Dark Reading".