πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ A Closer Look at State and Local Government Cybersecurity Priorities πŸ•΄

Complexity impedes the universal and consistent application of security policy, which is an obstacle to adequately securing government environments.

πŸ“– Read

via "Dark Reading".
🦿 Sandworm, a Russian Threat Actor, Disrupted Power in Ukraine Via Cyberattack 🦿

Any company that is strategic could be targeted for the same kind of actions as this cyberattack. Follow these tips to mitigate your company’s risk to this cybersecurity threat.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 'Hunters International' Cyberattackers Take Over Hive Ransomware πŸ•΄

Hunters International appears to have acquired Hive ransomware from its original operators and may be seeking to cash in on the malware's reputation.

πŸ“– Read

via "Dark Reading".
πŸ›  Samhain File Integrity Checker 4.5.0 πŸ› 

Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.

πŸ“– Read

via "Packet Storm Security".
πŸ‘2
πŸ•΄ Steps CISOs Should Take Before, During & After a Cyberattack πŸ•΄

By creating a plan of action, organizations can better respond to attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Molerats Group Wields Custom Cybertool to Steal Secrets in the Middle East πŸ•΄

The so-called TA402 group continues to focus on cyber espionage against government agencies.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Royal Ransom Demands Exceed $275M, Rebrand in Offing πŸ•΄

The swift-moving ransomware crew continues to evolve quickly and has already attacked more than 350 victims since it was first detected just over a year ago.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Google Goes After Scammers Abusing Its Bard AI Chatbot πŸ•΄

A pair of lawsuits are part of a wider strategy to establish guardrails preventing AI-powered scams, frauds, and harassment, Google's general counsel says.

πŸ“– Read

via "Dark Reading".
🦿 Red Hat: UK Leads Europe in IT Automation, But Key Challenges Persist 🦿

The U.K.'s position as a financial services hub puts it ahead in enterprise-wide IT automation, says Red Hat. But skills shortages remain an issue for all IT leaders surveyed.

πŸ“– Read

via "Tech Republic".
πŸ›  Faraday 4.6.2 πŸ› 

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

πŸ“– Read

via "Packet Storm Security".
πŸ•΄ Danish Energy Attacks Portend Targeting More Critical Infrastructure πŸ•΄

Targeted attacks against two dozen related companies is just the latest evidence that hackers want a piece of energy.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Zero-Days Allow Defender Bypass, Privilege Escalation πŸ•΄

Another two bugs in this month's set of fixes for 63 CVEs were publicly disclosed previously but have not been exploited yet.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ Microsoft Patch Tuesday, November 2023 Edition β™ŸοΈ

Microsoft today released updates to fix more than five dozen security holes in its Windows operating systems and related software, including three "zero day" vulnerabilities that Microsoft warns are already being exploited in active attacks.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Combining Agentless and Agent-Based Cloud Security in CNAPPs πŸ•΄

Combining both approaches using a cloud-native application protection platform helps organizations make their cybersecurity holistic by tapping into richer automation and prioritization features.

πŸ“– Read

via "Dark Reading".
πŸ‘1
πŸ•΄ Defending Against Attacks on Vulnerable IoT Devices πŸ•΄

Organizations must approach cybersecurity as if they are defending themselves in a cyberwar.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Oil Giant Aramco Drills Down on Saudi ICS Security πŸ•΄

Saudi Arabia's national oil and gas company is investing in an operational technology security training academy for organizations across the Kingdom.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Qatar & Rwanda Partner to Boost Cybersecurity in Africa πŸ•΄

The two countries will work on AI security guardrails, public key infrastructure, smart city cyber, and more.

πŸ“– Read

via "Dark Reading".
πŸ•΄ After Critical Bug Disclosures, TETRA Emergency Comms Code Goes Public πŸ•΄

After the encryption algorithm used by public safety, military, and governments globally was found to allow eavesdropping, standard maintainers are making TETRA open source.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cyber Resilience Requires Maturity, Persistence & Board Engagement πŸ•΄

Women in Cyber Security Middle East highlight a requirement for resilience in the face of increased business and cyber challenges.

πŸ“– Read

via "Dark Reading".
πŸ•΄ EU Tightens Cybersecurity Requirements for Critical Infrastructure and Services πŸ•΄

Organizations in sectors deemed "essential" or "important" have until October 2024 to comply with the Network and Information Systems Directive 2022 (NIS2).

πŸ“– Read

via "Dark Reading".
πŸ•΄ 'AlphaLock' Hacker Organization Launches Pen-Testing Training Group πŸ•΄

With a two-pronged approach, the group trains its hackers in penetration testing, only to set them free to build a marketplace for pen-testing services.

πŸ“– Read

via "Dark Reading".