πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ Highest paying tech jobs of 2022 πŸ“’

A guide to the best paying technology jobs in both the US and UK, and what they entail

πŸ“– Read

via "ITPro".
πŸ“’ IT Pro News in Review: Cyber security exploits surge, Dropbox phishing alert, public cloud spending on the up πŸ“’

Catch up on the biggest headlines of the week in just two minutes

πŸ“– Read

via "ITPro".
πŸ‘1
πŸ•΄ Managing and Mitigating Risk From Unknown Unknowns πŸ•΄

Five practical steps to up-level attack surface management programs and gain greater visibility and risk mitigation around the extended ecosystem.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Lawsuit Seeks Food Benefits Stolen By Skimmers β™ŸοΈ

A nonprofit organization is suing the state of Massachusetts on behalf of thousands of low-income families who were collectively robbed of more than a $1 million in food assistance benefits by card skimming devices secretly installed at cash machines and grocery store checkout lanes across the state. Federal law bars states from replacing these benefits using federal funds, and a recent rash of skimming incidents nationwide has disproportionately affected those receiving food assistance via state-issued prepaid debit cards.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ LockBit Bigwig Arrested for Ransomware Crimes πŸ•΄

A dual Russian-Canadian citizen is being extradited to the US to face charges related to LockBit ransomware activities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Veterans Day Salute: 6 Reasons Why You Want Vets in Your Cyber Platoon πŸ•΄

We commend vets in cyber, with this look at how the training and experience of former military personnel can be a big, differentiating asset in cybersecurity environments.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Twitter's CISO Takes Off, Leaving Security an Open Question πŸ•΄

Lea Kissner was one of three senior executives to quit this week, leaving many to wonder if the social media giant is ripe for a breach and FTC action.

πŸ“– Read

via "Dark Reading".
πŸ‘2
πŸ•΄ Cyberwar and Cybercrime Go Hand in Hand πŸ•΄

The line between criminal and political aims has become blurred, but motivations matter less than the effects of a breach.

πŸ“– Read

via "Dark Reading".
πŸ‘3
πŸ—“οΈ CSRF in Plesk API enabled privilege escalation πŸ—“οΈ

Bugs in programming interfaces of web hosting admin tool patched

πŸ“– Read

via "The Daily Swig".
⚠ Emergency code execution patch from Apple – but not an 0-day ⚠

Not a zero-day, but important enough for a quick-fire patch to one system library...

πŸ“– Read

via "Naked Security".
πŸ‘1
⚠ S3 Ep108: You hid THREE BILLION dollars in a popcorn tin? ⚠

Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!

πŸ“– Read

via "Naked Security".
πŸ›  TOR Virtual Network Tunneling Tool 0.4.7.11 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.

πŸ“– Read

via "Packet Storm Security".
😱1
πŸ•΄ Okta Launches New Workforce Identity Cloud πŸ•΄

Okta Worforce Identity Cloud has all three identity functions – identity access management, identity governance, and privilege access management – under the hood.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Why CVE Management as a Primary Strategy Doesn't Work πŸ•΄

With only about 15% of vulnerabilities actually exploitable, patching every vulnerability is not an effective use of time.

πŸ“– Read

via "Dark Reading".
⚠ Dangerous SIM-swap lockscreen bypass – update Android now! ⚠

A bit like leaving the front door keys under the doormat...

πŸ“– Read

via "Naked Security".
πŸ‘1
πŸ•΄ Knock, Knock: Aiphone Bug Allows Cyberattackers to Literally Open (Physical) Doors πŸ•΄

The bug affects several Aiphone GT models using NFC technology and allows malicious actors to potentially gain access to sensitive facilities.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Uyghurs Targeted With Spyware, Courtesy of PRC πŸ•΄

Chinese government employs spyware to detect so-called "pre-crimes" including using a VPN, religious apps, or WhatsApp, new analysis reveals.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity 'Nutrition' Labels Still a Work in Progress πŸ•΄

Pretty much every aspect of the effort to create easy-to-understand labels for Internet-of-Things (IoT) products is up in the air, according to participants in the process.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-36380 β€Ό

Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27187 β€Ό

Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“– Read

via "National Vulnerability Database".