πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ What Cyber Skills Shortage? πŸ•΄

Employers can solve the skills gap by first recognizing that there isn't an archetypal "cybersecurity job" in the same way that there isn't an archetypal "automotive job." Here's how.

πŸ“– Read

via "Dark Reading: ".
❌ A New Approach for Combating Insider Threats ❌

Threat detection tools don't take into account the emotional aspect of insider threats, a panel of experts said at Infosecurity Europe this week.

πŸ“– Read

via "Threatpost".
πŸ•΄ Imperva Snaps Up Distil Networks for API, App Security πŸ•΄

Distil Networks' technology will be integrated into Imperva's security stack following the acquisition.

πŸ“– Read

via "Dark Reading: ".
❌ AI Isn’t Good Enough When Lives Are on the Line, Experts Warn ❌

During Infosecurity Europe in London this week, cybersecurity experts sounded off on worries about artificial intelligence being used for nation state cyber weapons.

πŸ“– Read

via "Threatpost".
πŸ•΄ Medical Debt Collector Breach Highlights Supply Chain Dangers πŸ•΄

The breach of the website of American Medical Collection Agency leaves the personal and financial information of nearly 12 million patients at risk.

πŸ“– Read

via "Dark Reading: ".
πŸ” GandCrab Ransomware Gang Calling It Quits πŸ”

The cybercriminals are reportedly winding down operations around the ransomware after claiming to have made $2 billion in ransom payments

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Why FedRAMP Matters to Non-Federal Organizations πŸ•΄

Commercial companies should explore how FedRAMP can help mitigate risk as they move to the cloud.

πŸ“– Read

via "Dark Reading: ".
πŸ” 6 questions to consider before implementing a disaster recovery plan πŸ”

DRP's are about backing up data and recovering from loss as efficiently as possible, but a plan is only as good as its weakest link.

πŸ“– Read

via "Security on TechRepublic".
❌ Zebrocy: A Russian APT Specializing in Victim Profiling, Access ❌

The Russian-speaking APT acts as a support group for high-profile APTs like Sofacy and BlackEnergy.

πŸ“– Read

via "Threatpost".
πŸ•΄ How Today's Cybercriminals Sneak into Your Inbox πŸ•΄

The tactics and techniques most commonly used to slip past security defenses and catch employees off guard.

πŸ“– Read

via "Dark Reading: ".
❌ Zero-Day No More: Windows Bug Gets a Fix ❌

0patch has released an interim micropatch for the dangerous LPE bug while we wait for Microsoft's official patch.

πŸ“– Read

via "Threatpost".
πŸ•΄ 7 Container Components That Increase a Network's Security πŸ•΄

A proof of concept at Interop19 showed just how simple a container deployment can be.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Robbinhood: Inside the Ransomware That Slammed Baltimore πŸ•΄

Attackers appear to have used a ransomware-as-a-service platform to wage the attack.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 2.8 Billion US Consumer Records Lost in 2018 πŸ•΄

Healthcare breaches grew 400%, study shows.

πŸ“– Read

via "Dark Reading: ".
❌ Is β€˜Sign in with Apple’ Marketing Spin or Privacy Magic? Experts Weigh In ❌

The login scheme promises it won't share data -- and will be required for all developers using third-party sign-ins.

πŸ“– Read

via "Threatpost".
πŸ•΄ Carbanak Attack: Two Hours to Total Compromise πŸ•΄

Investigation of the cybercrime group's attack on an East European bank shows how some attackers require very little time to broaden their access and establish persistence on a network.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-13384

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13382

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13381

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13380

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13379

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

πŸ“– Read

via "National Vulnerability Database".