πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Critical RCE Bug in Rockwell Automation PLCs Zaps Industrial Sites πŸ•΄

Rockwell Automation and CISA warn of security vulnerabilities that affect power plants, factories, and other critical infrastructure sites.

πŸ“– Read

via "Dark Reading".
🦿 Top 7 multicloud security solution providers for 2023 🦿

There are a lot of considerations when adopting a multicloud infrastructure. Use our guide to compare the top 7 multicloud security solutions.

πŸ“– Read

via "Tech Republic".
πŸ•΄ WormGPT Heralds An Era of Using AI Defenses to Battle AI Malware πŸ•΄

AI-aided BEC, malware, and phishing attacks will push organizations to level up with generative AI and better protect their users, data, and networks.

πŸ“– Read

via "Dark Reading".
🦿 Gartner: Due to stress, half of cyber leaders will change jobs, and a quarter will quit the field 🦿

Among the strategic propositions in Gartner's 2023-2024 cybersecurity outlook are that organizations need to institute cultural changes to lower pressure on security teams.

πŸ“– Read

via "Tech Republic".
🀯1
πŸ•΄ How the EU AI Act Will Affect Businesses, Cybersecurity πŸ•΄

The draft AI Act represents a significant step in regulating AI technologies, recognizing the need to address the potential risks and ethical concerns.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Orca Sues Wiz for 'Copying' Its Cloud Security Tech πŸ•΄

Two fierce cloud security competitors are locked in a legal battle, as Orca accuses Wiz of ripping off its intellectual property.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34458 β€Ό

mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's sender account nonce. This could have contributed to a limited DoS attack on a targeted account. The fix is a breaking change so a new flag `RelayedNonceFixEnableEpoch` was needed. This was a strict processing issue while validating blocks on a chain. This vulnerability has been patched in version 1.4.17.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42045 β€Ό

Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware 3.2.28.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30559 β€Ό

The configuration from the PCU can be modified without authentication using physical connection to the PCU.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30560 β€Ό

The configuration from the PCU can be modified without authentication using physical connection to the PCU.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Linux Hacker Exploits Researchers With Fake PoCs Posted to GitHub πŸ•΄

A cyber attacker gives defenders a taste of their own medicine, with GitHub honeypots concealing infostealers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity Leaders Report Reduction in Disruptive Cyber Incidents With MSS/MDR Solutions πŸ•΄

Optiv survey highlights organizations' need for talent, challenges with sophistication of threat actors and expanding attack surface.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Facebook and Microsoft are the Most Impersonated Brands in Phishing Attacks πŸ•΄

Vade's phishing and malware report reveals phishing volumes increased by more than 54% in H1 2023.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Safe Security Acquires RiskLens πŸ•΄

A combination of SAFE Platform's industry defining AI capabilities coupled with the industry standard FAIR model for cyber risk quantification, that was pioneered by RiskLens.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Black Hat Announces Sustainability Pledge πŸ•΄

Pledge stems from Black Hat’s commitment to become a net zero carbon business by 2030.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ SEO Expert Hired and Fired By Ashley Madison Turned on Company, Promising Revenge β™ŸοΈ

[This is Part II of a story published here last week on reporting that went into a new Hulu documentary series on the 2015 Ashley Madison hack.]It was around 9 p.m. on Sunday, July 19, when I received a message through the contact form on KrebsOnSecurity.com that the marital infidelity website AshleyMadison.com had been hacked. The message contained links to confidential Ashley Madison documents, and included a manifesto that said a hacker group calling itself the Impact Team was prepared to leak data on all 37 million users unless Ashley Madison and a sister property voluntarily closed down within 30 days.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ White House Fills in Details Of National Cybersecurity Strategy πŸ•΄

While the plan may convey the right kind of urgency, it lacks both funding and bipartisan support, industry professionals say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-37598 β€Ό

A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.

πŸ“– Read

via "National Vulnerability Database".