πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸš€ The job hunter’s guide: Separating genuine offers from scams πŸš€

90,000year, full home office, and 30 days of paid leave, and all for a job as a junior data analyst unbelievable, right? This and many other job offers are fake though made just to ensnare unsuspecting victims into giving up their data.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances πŸ–‹οΈ

The threat actor known as Commando Cat has been linked to an ongoing cryptojacking attack campaign that leverages poorly secured Docker instances to deploy cryptocurrency miners for financial gain. "The attackers used the cmd.catchattr docker image container that retrieves the payload from their own commandandcontrol CC infrastructure," Trend Micro researchers Sunil Bharti and Shubham.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Researchers issue warning over new ransomware variant targeting the education sector πŸ“’

Researchers have published research on a new ransomware variant using compromised VPN credentials to target education organizations in the US.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SPECTR Malware Targets Ukraine Defense Forces in SickSync Campaign πŸ–‹οΈ

The Computer Emergency Response Team of Ukraine CERTUA has warned of cyber attacks targeting defense forces in the country with a malware called SPECTR as part of an espionage campaign dubbed SickSync. The agency attributed the attacks to a threat actor it tracks under the moniker UAC0020, which is also called Vermin and is assessed to be associated with security agencies of the Luhansk.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Supply chain attacks are still plaguing enterprises – here's why πŸ“’

A host of organizations have fallen prey to supply chain attacks over the last month, including Santander, Ticketmaster, and two major hospitals.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ FBI Distributes 7,000 LockBit Ransomware Decryption Keys to Help Victims πŸ–‹οΈ

The U.S. Federal Bureau of Investigation FBI has disclosed that it's in possession of more than 7,000 decryption keys associated with the LockBit ransomware operation to help victims get their data back at no cost. "We are reaching out to known LockBit victims and encouraging anyone who suspects they were a victim to visit our Internet Crime Complaint Center at ic3.gov," FBI Cyber Division.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2024: Cyber Resilience Means Being Willing to Learn From a Crisis πŸ“”

Experts advised that crisis management and recovery is as much about communications and testing as it is about technical defense measures.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Security Flaws Found in Popular WooCommerce Plugin πŸ“”

Despite reported attempts from Patchstack to contact the vendor, no response has been received.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2024: Collaboration is Key to an Effective Security Culture πŸ“”

Organizations need a culture that goes beyond reporting incidents, where the business wants to collaborate with the security team.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Cyber Landscape is Evolving - So Should Your SCA πŸ–‹οΈ

Traditional SCAs Are Broken Did You Know You Are Missing Critical Pieces? Application Security professionals face enormous challenges securing their software supply chains, racing against time to beat the attacker to the mark.  Software Composition Analysis SCA tools have become a basic instrument in the application security arsenal in the last 7 years. Although essential, many platforms.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The AI Debate: Google's Guidelines, Meta's GDPR Dispute, Microsoft's Recall Backlash πŸ–‹οΈ

Google is urging thirdparty Android app developers to incorporate generative artificial intelligence GenAI features in a responsible manner. The new guidance from the search and advertising giant is an effort to combat problematic content, including sexual content and hate speech, created through such tools. To that end, apps that generate content using AI must ensure they don't create.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ With hundreds of Snowflake credentials published on the dark web, it’s time for enterprises to get MFA in order πŸ“’

The recent Snowflake debacle highlights the need for more stringent enterprise MFA practices.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 Open source, open risks: The growing dangers of unregulated generative AI 🧠

While mainstream generative AI models have builtin safety barriers, opensource alternatives have no such restrictions. Heres what that means for cyber crime. Theres little doubt that opensource is the future of software. According to the 2024 State of Open Source Report, over twothirds of businesses increased their use of opensource software in the last year. The post Open source, open risks The growing dangers of unregulated generative AI appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” EmailGPT Exposed to Prompt Injection Attacks πŸ“”

The flaw enables attackers to gain control over the AI service by submitting harmful prompts.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ›  TOR Virtual Network Tunneling Tool 0.4.8.12 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with builtin privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers ISPs. This is the source code release.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ›  jSQL Injection 0.98 πŸ› 

jSQL Injection is a lightweight application used to find database information from a distant server. jSQL Injection is also part of the official penetration testing distribution Kali Linux and is included in various other distributions like Pentest Box, Parrot Security OS, ArchStrike and BlackArch Linux. This is the source code release.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Developing a Plan to Respond to Critical CVEs in Open Source Software πŸ•΅οΈβ€β™‚οΈ

Establishing a clear process for developers to respond to critical CVEs is essential for having a rapid and coordinated response.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Get 2 Lifetime Password Manager Subscriptions for Only $50 🦿

Save your business time and money with Sticky Password Premium and get this twoaccount bundle for 49.99 reg. 399 at TechRepublic Academy.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Sticky Werewolf' APT Stalks Aviation Sector πŸ•΅οΈβ€β™‚οΈ

The proUkranian group has upgraded its infection chain, with credentials, strategic info on commercial pilots, or billiondollar designs as the possible prizes.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Ultimate Cyber Hygiene Guide: Learn How to Simplify Your Security Efforts πŸ–‹οΈ

2023 was a year of unprecedented cyberattacks. Ransomware crippled businesses, DDoS attacks disrupted critical services, and data breaches exposed millions of sensitive records. The cost of these attacks? Astronomical. The damage to reputations? Irreparable. But here's the shocking truth many of these attacks could have been prevented with basic cyber hygiene. Are you ready to transform your.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ LightSpy Spyware's macOS Variant Found with Advanced Surveillance Capabilities πŸ–‹οΈ

Cybersecurity researchers have disclosed that the LightSpy spyware allegedly targeting Apple iOS users is in fact a previously undocumented macOS variant of the implant. The findings come from both Huntress Labs and ThreatFabric, which separately analyzed the artifacts associated with the crossplatform malware framework that likely possesses capabilities to infect Android, iOS, Windows, macOS,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1