πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Report: UK businesses are less secure when using police-endorsed cyber security tool πŸ“’

The cyber security researcher found the developer of the free software to be "incompetent" and the myriad flaws in the cyber crime-fighting monitoring tool left businesses more at risk of cyber attacks

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-25762 β€Ό

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ SMBs expected to suffer as cyber security salaries equalise across the UK πŸ“’

Smaller businesses stand to lose out on top talent as post-pandemic hybrid and remote working setups drive salaries closer to London levels

πŸ“– Read

via "ITPro".
πŸ“’ Australian state transport agency hit by cyber attack πŸ“’

It warned that scammers might try to capitalise on the incident and told customers not to respond to unsolicited contact from anyone claiming to be from the agency

πŸ“– Read

via "ITPro".
πŸ“’ Rental car company Sixt confirms cyber attack, leaves scores of UK customers in the dark πŸ“’

The rental car giant announced a cyber attack on Sunday and has been largely uncontactable for days, but insists disruption is temporary and minimal

πŸ“– Read

via "ITPro".
πŸ“’ Securing endpoints amid new threats πŸ“’

Ensuring employees have the flexibility and security to work remotely

πŸ“– Read

via "ITPro".
πŸ“’ Five Eyes leaders issue guidance for MSPs to prevent second SolarWinds attack πŸ“’

The joint advisory published today said MSPs and customers need more vigilant in the wake of Russia's invasion of Ukraine

πŸ“– Read

via "ITPro".
πŸ“’ Dell calls time on the age-old on-prem vs cloud rivalry πŸ“’

The tech giant champions multi-cloud at one of the best conferences out there, unless you’re immunosuppressed, that is – our Dell Technologies World 2022 view from the airport

πŸ“– Read

via "ITPro".
πŸ“’ Apple, Google, Microsoft expand their support for password-less sign-ins πŸ“’

New approach promises to offer β€œsimpler, stronger authentication” across leading platforms to help protect users from malicious activity

πŸ“– Read

via "ITPro".
πŸ“’ Landmark amendments to international cyber crime treaty set to be signed next week πŸ“’

It's only the second amendment to the historically significant Budapest Convention since it was introduced in 2001

πŸ“– Read

via "ITPro".
πŸ“’ National security leaders fear Ukraine conflict could inform a 'blueprint' for cyber war πŸ“’

Learning from the successes and failures of the ongoing conflict could help foreign adversaries carry out more effective cyber attacks in the future, according to one national cyber security chief

πŸ“– Read

via "ITPro".
πŸ“’ Red Hat reveals new software supply chain security pattern πŸ“’

New cross-portfolio capabilities aim to help customers improve security posture and enable DevSecOps

πŸ“– Read

via "ITPro".
πŸ“’ Actively exploited Windows vulnerability reaches peak severity when paired with popular attack πŸ“’

May 2022's routine Patch Tuesday fixes seven 'critical' issues, including a familiar headache for IT administrators

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft announces new business security services led by in-house experts πŸ“’

The new services will see Microsoft's security experts providing hands-on, proactive threat hunting for businesses unable to fully build out a SOC due to the industry's skills shortage

πŸ“– Read

via "ITPro".
πŸ“’ WannaCry showed the world how not to write ransomware πŸ“’

Despite its devastating impact, cyber security researchers reflect on how much worse the attacks could have been

πŸ“– Read

via "ITPro".
πŸ“’ NCSC unveils email security-checking tool for private sector organisations at CYBERUK πŸ“’

The free service will focus on checking for TLS and DMARC compliance to protect against anti-spoofing and email hijacking

πŸ“– Read

via "ITPro".
πŸ“’ Costa Rica declares state of emergency following Conti ransomware attack πŸ“’

The US has released a $10 million bug bounty for information on the attackers

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft makes Defender for Business generally available πŸ“’

Small businesses can look forward to enterprise-grade endpoint security as well as automated investigation and remediation capabilities

πŸ“– Read

via "ITPro".
πŸ“’ GitHub to introduce two-factor authentication by 2023 πŸ“’

GitHub.com will require 2FA by the end of 2023, as the company works to secure the software ecosystem through improved account security

πŸ“– Read

via "ITPro".
πŸ“’ Researcher discovers simple tweak that neutralises Conti, REvil, WannaCry attacks πŸ“’

This one trick can stop ransomware executing file encryption

πŸ“– Read

via "ITPro".
πŸ“’ Five Eyes and US governments finally confirm Russia was behind Ukrainian government, Viasat cyber attacks πŸ“’

NCSC detailed the government-level attribution process at CYBERUK 2022 and why it took so much longer to assign blame compared to the private sector

πŸ“– Read

via "ITPro".