πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Critical Flaw in WordPress LiteSpeed Cache Plugin Allows Hackers Admin Access πŸ–‹οΈ

Cybersecurity researchers have disclosed a critical security flaw in the LiteSpeed Cache plugin for WordPress that could permit unauthenticated users to gain administrator privileges. "The plugin suffers from an unauthenticated privilege escalation vulnerability which allows any unauthenticated visitor to gain Administrator level access after which malicious plugins could be uploaded and.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GitHub Patches Critical Security Flaw in Enterprise Server Granting Admin Privileges πŸ–‹οΈ

GitHub has released fixes to address a set of three security flaws impacting its Enterprise Server product, including one critical bug that could be abused to gain site administrator privileges. The most severe of the shortcomings has been assigned the CVE identifier CVE20246800, and carries a CVSS score of 9.5. "On GitHub Enterprise Server instances that use SAML single signon SSO.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ How regulatory standards and cyber insurance inform each other πŸš€

Should the payment of a ransomware demand be illegal? Should it be regulated in some way? These questions are some examples of the legal minefield that cybersecurity teams must deal with.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Backdoor in Mifare Smart Cards Could Open Doors Around the World πŸ“”

Quarklabs researchers claim millions of contactless key cards could be cloned via a backdoor.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Novel Android Malware Steals Card NFC Data For ATM Withdrawals πŸ“”

ESET claims new NGate Android malware relays NFC data to steal card details for ATM cashout.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ British Library issues Β£400,000 tender as rebuild continues after 2023 cyber attack πŸ“’

The British Library's digital transformation project was initially set back by a major cyber attack in October 2023 now its looking to get back on track.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Security Flaws in UK Political Party Donation Platforms Exposed πŸ“”

The donation websites of the UKs seven major political parties are missing critical security features to protect the accounts of donors, according to DataDome.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ The Facts About Continuous Penetration Testing and Why It’s Important πŸ–‹οΈ

What is Continuous Attack Surface Penetration Testing or CASPT? Continuous Penetration Testing or Continuous Attack Surface Penetration Testing CASPT is an advanced security practice that involves the continuous, automated, and ongoing penetration testing services of an organization's digital assets to identify and mitigate security vulnerabilities. CASPT is designed for enterprises with an.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ AI and data protection: What businesses need to know πŸ“’

Generative AI tools such as ChatGPT pose risks to data protection firms still struggling to put an AI strategy in place will struggle down the line.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Hackers could dupe Slack's AI features to expose private channel messages πŸ“’

The companys internal Slack AI feature can be manipulated into disclosing sensitive data from private channels, new research shows.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Cyber Security and IT Leadership: A Growing Threat to Australia’s Renewable Energy Efforts 🦿

Australia is rapidly embracing renewable energy. But for the nation to successfully leverage green energy, it is imperative to establish strong IT foundations.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Microsoft Delays Recall Launch for Windows Insider Members Until October 🦿

An upcoming blog post for members of the Windows Insider Program will explain how to get the AIpowered Recall feature.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Low Media Literacy: A Risk to Australia’s Cybersecurity Landscape 🦿

Explore how low media literacy can have lingering repercussions on Australias tech industry.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Australian Digital ID: TEx System Poised to Boost Security By Sharing Less Data With Businesses 🦿

Australia is building a digital ID and information verification system called Trust Exchange, or TEx, that will see the Government verifying customer details for businesses via a smartphone app.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Get Advanced Ad Blocking and Superior Data Privacy Tools for Just $11 🦿

Block popups, banners and video ads while also protecting yourself from activity trackers, phishing attempts, fraudulent websites and other types of malware with AdGuard.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New macOS Malware "Cthulhu Stealer" Targets Apple Users' Data πŸ–‹οΈ

Cybersecurity researchers have uncovered a new information stealer that's designed to target Apple macOS hosts and harvest a wide range of information, underscoring how threat actors are increasingly setting their sights on the operating system. Dubbed Cthulhu Stealer, the malware has been available under a malwareasaservice MaaS model for 500 a month from late 2023. It's capable of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Latvian Hacker Extradited to U.S. for Role in Karakurt Cybercrime Group πŸ–‹οΈ

A 33yearold Latvian national living in Moscow, Russia, has been charged in the U.S. for allegedly stealing data, extorting victims, and laundering ransom payments since August 2021. Deniss Zolotarjovs aka Sforzacesarini has been charged with conspiring to commit money laundering, wire fraud and Hobbs Act extortion. He was arrested in Georgia in December 2023 and has since been extradited to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hardware Backdoor Discovered in RFID Cards Used in Hotels and Offices Worldwide πŸ–‹οΈ

Cybersecurity researchers have uncovered a hardware backdoor within a particular model of MIFARE Classic contactless cards that could allow authentication with an unknown key and open hotel rooms and office doors. The attacks have been demonstrated against FM11RF08S, a new variant of MIFARE Classic that was released by Shanghai Fudan Microelectronics in 2020. "The FM11RF08S backdoor enables any.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk πŸ–‹οΈ

SolarWinds has issued patches to address a new security flaw in its Web Help Desk WHD software that could allow remote unauthenticated users to gain unauthorized access to susceptible instances. "The SolarWinds Web Help Desk WHD software is affected by a hardcoded credential vulnerability, allowing a remote unauthenticated user to access internal functionality and modify data," the company.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Chinese Hackers Exploit Zero-Day Cisco Switch Flaw to Gain System Control πŸ–‹οΈ

Details have emerged about a Chinanexus threat group's exploitation of a recently disclosed, nowpatched security flaw in Cisco switches as a zeroday to seize control of the appliances and evade detection. The activity, attributed to Velvet Ant, was observed early this year and involved the weaponization of CVE202420399 CVSS score 6.0 to deliver bespoke malware and gain extensive control.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New 'ALBeast' Vulnerability Exposes Weakness in AWS Application Load Balancer πŸ–‹οΈ

As many as 15,000 applications using Amazon Web Services' AWS Application Load Balancer ALB for authentication are potentially susceptible to a configurationbased issue that could expose them to sidestep access controls and compromise applications. That's according to findings from Israeli cybersecurity company Miggo, which dubbed the problem ALBeast. "This vulnerability allows attackers to.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity