πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-36521 β€Ό

Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox 104 is out – no critical bugs, but update anyway ⚠

Two trust-spoofing bugs were the main culprits this month - but neither one was a zero-day.

πŸ“– Read

via "Naked Security".
πŸ•΄ 'Sliver' Emerges as Cobalt Strike Alternative for Malicious C2 πŸ•΄

Microsoft and others say they have observed nation-state actors, ransomware purveyors, and assorted cybercriminals pivoting to an open source attack-emulation tool in recent campaigns.

πŸ“– Read

via "Dark Reading".
❌ Ransomware Attacks are on the Rise ❌

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

πŸ“– Read

via "Threat Post".
πŸ” Friday Five 8/26 πŸ”

Read about why Twitter is coming under fire, how a cybersecurity organization may have gone on the offensive, possible big changes coming for software vendors, and much more in this week’s Friday Five!


πŸ“– Read

via "".
πŸ“’ Snapchat settles for $35 million in Illinois biometrics lawsuit πŸ“’

The social media giant had been accused of improperly collecting, storing facial geometry in violation of state legislation

πŸ“– Read

via "ITPro".
πŸ“’ SolarWinds hackers strike again with a new β€œMagicWeb” authentication exploit πŸ“’

Microsoft warns MagicWeb can abuse admin credentials to hijack AD FS enterprise identity system

πŸ“– Read

via "ITPro".
πŸ“’ PyPI packages succumb to Mailchimp phishing scam πŸ“’

The news comes after "fairly convincing" phishing emails from a Mailchimp account swindled developers into revealing credentials

πŸ“– Read

via "ITPro".
πŸ“’ French telco giant Altice reportedly hit by Hive ransomware attack πŸ“’

Dark web listings indicate that the French multinational was attacked in early August, but the company has made no announcement

πŸ“– Read

via "ITPro".
πŸ“’ Companies House reveals overhaul to WebFiling accounts system πŸ“’

Businesses will be able to control those with filing permissions more easily, as the new accounts mark a new streamlining of the government's digital filing requirements

πŸ“– Read

via "ITPro".
πŸ“’ Plex confirms passwords, emails stolen in β€œlimited” data breach πŸ“’

The video streaming giant is requiring all users to reset their passwords in case the stolen hashed passwords can be cracked

πŸ“– Read

via "ITPro".
πŸ“’ Avast launches Ransomware Shield for small businesses πŸ“’

The new cyber security solution is available as part of Avast Essential, Premium, and Ultimate Business Security packages

πŸ“– Read

via "ITPro".
πŸ“’ What's the difference between antimalware and antivirus? πŸ“’

We help you navigate the worlds of antimalware and antivirus

πŸ“– Read

via "ITPro".
πŸ“’ LockBit hacking group to be 'more aggressive' after falling victim to large-scale DDoS attack πŸ“’

The ransomware group is currently embroiled in a battle after it leaked data belonging to cyber security company Entrust

πŸ“– Read

via "ITPro".
πŸ“’ Oracle's massive advertising database operates without user consent, lawsuit claims πŸ“’

Rights organisers have accused Oracle of collecting an undue level of sensitive data to identify consumers online

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft 365 business users targeted with new DocuSign phishing scam πŸ“’

Threat actors are using fake login forms to trick users into changing their payment details

πŸ“– Read

via "ITPro".
πŸ“’ India forced Twitter to hire a government agent, whistleblower claims πŸ“’

Former employee Peiter Zatko says the social media platform gave the agent direct unsupervised access to the company’s systems and user data

πŸ“– Read

via "ITPro".
πŸ“’ CMS Distribution partners with GuardYoo for new Attack Surface Management offering πŸ“’

The hosted service has been designed to strengthen resilience against vulnerabilities without sacrificing growth, company says

πŸ“– Read

via "ITPro".
πŸ“’ Digital transformation giant Orion Innovation hit by LockBit ransomware, hacker group claims πŸ“’

The company has a star-studded client list that includes some of the biggest sports organisations in the world and an assortment of tech behemoths

πŸ“– Read

via "ITPro".
πŸ“’ LastPass breach: CEO says 'no evidence' of customer data being stolen πŸ“’

The company said the incident was confined to a single developer account and its associated environment

πŸ“– Read

via "ITPro".