πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Security Flaws Found in Popular WooCommerce Plugin πŸ“”

Despite reported attempts from Patchstack to contact the vendor, no response has been received.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” #Infosec2024: Collaboration is Key to an Effective Security Culture πŸ“”

Organizations need a culture that goes beyond reporting incidents, where the business wants to collaborate with the security team.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Cyber Landscape is Evolving - So Should Your SCA πŸ–‹οΈ

Traditional SCAs Are Broken Did You Know You Are Missing Critical Pieces? Application Security professionals face enormous challenges securing their software supply chains, racing against time to beat the attacker to the mark.  Software Composition Analysis SCA tools have become a basic instrument in the application security arsenal in the last 7 years. Although essential, many platforms.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The AI Debate: Google's Guidelines, Meta's GDPR Dispute, Microsoft's Recall Backlash πŸ–‹οΈ

Google is urging thirdparty Android app developers to incorporate generative artificial intelligence GenAI features in a responsible manner. The new guidance from the search and advertising giant is an effort to combat problematic content, including sexual content and hate speech, created through such tools. To that end, apps that generate content using AI must ensure they don't create.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ With hundreds of Snowflake credentials published on the dark web, it’s time for enterprises to get MFA in order πŸ“’

The recent Snowflake debacle highlights the need for more stringent enterprise MFA practices.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 Open source, open risks: The growing dangers of unregulated generative AI 🧠

While mainstream generative AI models have builtin safety barriers, opensource alternatives have no such restrictions. Heres what that means for cyber crime. Theres little doubt that opensource is the future of software. According to the 2024 State of Open Source Report, over twothirds of businesses increased their use of opensource software in the last year. The post Open source, open risks The growing dangers of unregulated generative AI appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” EmailGPT Exposed to Prompt Injection Attacks πŸ“”

The flaw enables attackers to gain control over the AI service by submitting harmful prompts.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ›  TOR Virtual Network Tunneling Tool 0.4.8.12 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with builtin privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers ISPs. This is the source code release.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ›  jSQL Injection 0.98 πŸ› 

jSQL Injection is a lightweight application used to find database information from a distant server. jSQL Injection is also part of the official penetration testing distribution Kali Linux and is included in various other distributions like Pentest Box, Parrot Security OS, ArchStrike and BlackArch Linux. This is the source code release.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Developing a Plan to Respond to Critical CVEs in Open Source Software πŸ•΅οΈβ€β™‚οΈ

Establishing a clear process for developers to respond to critical CVEs is essential for having a rapid and coordinated response.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Get 2 Lifetime Password Manager Subscriptions for Only $50 🦿

Save your business time and money with Sticky Password Premium and get this twoaccount bundle for 49.99 reg. 399 at TechRepublic Academy.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 'Sticky Werewolf' APT Stalks Aviation Sector πŸ•΅οΈβ€β™‚οΈ

The proUkranian group has upgraded its infection chain, with credentials, strategic info on commercial pilots, or billiondollar designs as the possible prizes.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Ultimate Cyber Hygiene Guide: Learn How to Simplify Your Security Efforts πŸ–‹οΈ

2023 was a year of unprecedented cyberattacks. Ransomware crippled businesses, DDoS attacks disrupted critical services, and data breaches exposed millions of sensitive records. The cost of these attacks? Astronomical. The damage to reputations? Irreparable. But here's the shocking truth many of these attacks could have been prevented with basic cyber hygiene. Are you ready to transform your.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ LightSpy Spyware's macOS Variant Found with Advanced Surveillance Capabilities πŸ–‹οΈ

Cybersecurity researchers have disclosed that the LightSpy spyware allegedly targeting Apple iOS users is in fact a previously undocumented macOS variant of the implant. The findings come from both Huntress Labs and ThreatFabric, which separately analyzed the artifacts associated with the crossplatform malware framework that likely possesses capabilities to infect Android, iOS, Windows, macOS,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ Hotel Check-in Kiosks Expose Guest Data, Room Keys πŸ•΅οΈβ€β™‚οΈ

CVE202437364 affects hospitality kiosks from Ariane Systems, which are used for selfcheckin at more than 3,000 hotels worldwide.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🧨 How to Delete Your Browser History 🧨

Deleting your browsing history has its benefits. For one, it can improve the performance of your device. Secondly, it can... The post How to Delete Your Browser History appeared first on McAfee Blog.

πŸ“– Read more.

πŸ”— Via "McAfee"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ SolarWinds Flaw Flagged by NATO Pen Tester πŸ•΅οΈβ€β™‚οΈ

The latest platform update from SolarWinds includes patches for three vulnerabilities, including two highseverity bugs.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cybersecurity Job Hunting May Come Down to Certifications πŸ•΅οΈβ€β™‚οΈ

If current cybersecurity workers only fill 85 of the need in the US, why are so many people still looking for positions? The data from the privatepublic NIST partnership CyberSeek offers some insight.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ CISO Corner: Red Sox CloudSec; Deepfake Biz Risk; Ticketmaster Takeaways πŸ•΅οΈβ€β™‚οΈ

Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps. Also included Proactive playbooks, a USKenya partnership, and the trouble with shadow engineering.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ GitHub Repos Targeted in Cyber-Extortion Attacks πŸ•΅οΈβ€β™‚οΈ

Since at least February, a threat actor has been attempting to extort victims by stealing or wiping data in their GitHub repositories.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 OpenAI, Anthropic Research Reveals More About How LLMs Affect Security and Bias 🦿

Anthropic opened a window into the black box where features steer a large language models output. OpenAI dug into the same concept two weeks later with a deep dive into sparse autoencoders.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity