๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด Avatier Achieves ISO 27001 Certification for its Information Security Management System ๐Ÿ•ด

Designation recognizes highest caliber of information security.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Privacy4Cars Secures Fourth Patent to Remove Privacy Information From Vehicles and Create Compliance Logs ๐Ÿ•ด

Data-deletion service's patent covers removing personal information such as geolocation, biometrics, and phone records from a vehicle by using a user-computing device

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘1
๐Ÿ—“๏ธ All Day DevOps: Third of Log4j downloads still pull vulnerable version despite threat of supply chain attacks ๐Ÿ—“๏ธ

AppSec engineer keynote says Log4j revealed lessons were not learned from the Equifax breach

๐Ÿ“– Read

via "The Daily Swig".
โš  โ€œGucci Masterโ€ business email scammer Hushpuppi gets 11 years โš 

Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Unpatched Zimbra Platforms Are Probably Compromised, CISA Says ๐Ÿ•ด

Attackers are targeting Zimbra systems in the public and private sectors, looking to exploit multiple vulnerabilities, CISA says.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘1
๐Ÿ•ด Australia Declares War on Cybercrime Syndicates ๐Ÿ•ด

An international counter-ransomware task force has been announced by Australian authorities following the recent Optus and Medibank data breaches.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿคฏ2๐Ÿ‘1
๐Ÿ•ด Researchers Sound Alarm on Dangerous BatLoader Malware Dropper ๐Ÿ•ด

BatLoader has spread rapidly to roost in systems globally, tailoring payloads to its victims.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘1๐Ÿค”1
๐Ÿ•ด Evolving Security for Government Multiclouds ๐Ÿ•ด

As the threat landscape increases, public cloud security needs to evolve.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ—“๏ธ Mastodon users vulnerable to password-stealing attacks ๐Ÿ—“๏ธ

Patched bug could have leaked credentials

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ•ด Nasty SQL Injection Bug in Zendesk Endangers Sensitive Customer Data ๐Ÿ•ด

The API-related vulnerabilities put conversations, email addresses, tickets, and more in danger of exposure via the Zendesk Explore reporting service.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Yakima Neighborhood Health Services Notice of Data Security Incident ๐Ÿ•ด

.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Red Canary Provides First-Ever MITRE Engenuityโ„ข ATT&CKยฎ Evaluations for Managed Services ๐Ÿ•ด

.

๐Ÿ“– Read

via "Dark Reading".
โ™Ÿ๏ธ Top Zeus Botnet Suspect โ€œTankโ€ Arrested in Geneva โ™Ÿ๏ธ

Vyacheslav โ€œTankโ€ Penchukov, the accused 40-year-old Ukrainian leader of a prolific cybercriminal group that stole tens of millions of dollars from small to mid-sized businesses in the United States and Europe, has been arrested in Switzerland, according to multiple sources.

๐Ÿ“– Read

via "Krebs on Security".
๐Ÿ—“๏ธ Zendesk Explore flaws opened the door to account pillage ๐Ÿ—“๏ธ

Patched SQLi and logical access vulnerabilities posed serious risk

๐Ÿ“– Read

via "The Daily Swig".
๐Ÿ•ด Google Forks Over $391.5M in Record-Setting US Consumer Privacy Settlement ๐Ÿ•ด

A misleading location-tracking practice ensnared the search-engine giant in massive privacy case spanning 40 states.

๐Ÿ“– Read

via "Dark Reading".
โš  โ€œGucci Masterโ€ business email scammer Hushpuppi gets 11 years โš 

Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด How Routine Pen Testing Can Reveal the Unseen Flaws in Your Cybersecurity Posture ๐Ÿ•ด

Testing is an ongoing mission, not a one-and-done fix.

๐Ÿ“– Read

via "Dark Reading".
โš  Log4Shell-like code execution hole in popular Backstage dev tool โš 

Researchers at cloud coding security company Oxeye have written up a critical bug that they recently discovered in the popular cloud development toolkit Backstage. Their report includes an explanation of how the bug works, plus proof-of-concept (PoC) code showing how to exploit it. Backstage is whatโ€™s known as a cloud developer portal โ€“ a sort [โ€ฆ]

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด Where Can Third-Party Governance and Risk Management Take Us? ๐Ÿ•ด

Part 2 in our series addressing the top 10 unanswered questions in security: How will TPGRM evolve?

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Wipermania: Malware Remains a Potent Threat, 10 Years Since 'Shamoon' ๐Ÿ•ด

An in-depth analysis of system-destroying malware families presented at Black Hat Middle East & Africa shows a growing nuance in terms of how they're deployed.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ‘2
โ€ผ CVE-2022-34313 โ€ผ

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

๐Ÿ“– Read

via "National Vulnerability Database".