πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” ICO Releases New Data Protection Audit Framework πŸ“”

The UKs ICO said the framework is designed to help businesses build trust and encourage a positive data protection culture.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” EU Urged to Harmonize Incident Reporting Requirements πŸ“”

Risk managers association FERMA has warned that new EU cyber legislation means there is an inconsistent approach to incident reporting requirements.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Tech Professionals Highlight Critical AI Security Skills Gap πŸ“”

A new OReilly survey showed a shortage of AI security skills, while AIenabled security tools become tech professionals top priority for the coming year.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fraud Repayment Rules Could Leave Victims Struggling, CTSI Claims πŸ“”

The Chartered Trading Standards Institute is concerned a new cap on fraud reimbursement is too low.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Project Coordinator 🌊

The post Project Coordinator appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Board-CISO Mismatch on Cyber Responsibility, NCSC Research Finds πŸ“”

The UK NCSC found that there is a lot of confusion between board members and security leaders of who is responsible for cybersecurity within their organizations.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Universal Music Group Admits Data Breach πŸ“”

UMG, a major music corporation, reported a July 2024 data breach affecting 680 US residents.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Advanced Threat Group GoldenJackal Exploits Air-Gapped Systems πŸ“”

GoldenJackal targeted airgapped government systems from May 2022 to March 2024, ESET found.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Modern enterprise cybersecurity πŸ“’

Cultivating resilience with reduced detection and response times.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Mideast, Turkey Cyber Threats Spike, Prompting Defense Changes πŸ•΅οΈβ€β™‚οΈ

The vast majority of organizations in the region saw more attacks in the past year, but most don't feel prepared for future incidents.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ GorillaBot Goes Ape With 300K Cyberattacks Worldwide πŸ•΅οΈβ€β™‚οΈ

Among those affected by all this monkeying around with DDoS in September were some 4,000 organizations in the US.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Salt Typhoon APT Subverts Law Enforcement Wiretapping: Report πŸ•΅οΈβ€β™‚οΈ

The Chinese statesponsored cyberattack threat managed to infiltrate the "lawful intercept" network connections that police use in criminal investigations.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ CISO Paychecks: Worth the Growing Security Headaches? πŸ•΅οΈβ€β™‚οΈ

CISOs' cash compensation tops 400,000 now, but with the high pay comes struggles, rapidly changing responsibilities, and tight budgets.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Malicious Chrome Extensions Skate Past Google's Updated Security πŸ•΅οΈβ€β™‚οΈ

Google's Manifest V3 offers better privacy and security controls for browser extensions than the previous M2, but too many lax permissions and gaps remain.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Timeline: 15 Notable Cyberattacks and Data Breaches 🦿

These 15 cyber attacks or data breaches impacted large swaths of users across the United States and changed what was possible in cybersecurity.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Pro-Ukrainian Hackers Strike Russian State TV on Putin's Birthday πŸ–‹οΈ

Ukraine has claimed responsibility for a cyber attack that targeted Russia state media company VGTRK and disrupted its operations, according to reports from Bloomberg and Reuters. The incident took place on the night of October 7, VGTRK confirmed, describing it as an "unprecedented hacker attack." However, it said "no significant damage" was caused and that everything was working normally.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Qualcomm Urges OEMs to Patch Critical DSP and WLAN Flaws Amid Active Exploits πŸ–‹οΈ

Qualcomm has rolled out security updates to address nearly two dozen flaws spanning proprietary and opensource components, including one that has come under active exploitation in the wild. The highseverity vulnerability, tracked as CVE202443047 CVSS score 7.8, has been described as a userafterfree bug in the Digital Signal Processor DSP Service that could lead to "memory corruption.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” MoneyGram Reveals Data Breach After Incident Downed Services πŸ“”

MoneyGram has issued a data breach notification to customers following a security incident.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… CISA Flags Multiple Critical Vulnerabilities Exposed Across Major Platforms πŸ¦…

The Cybersecurity and Infrastructure Security Agency CISA has added multiple vulnerabilities to its known Exploited Vulnerabilities KEV catalog. A total of six vulnerabilities have been identified across various products, including Zimbra Collaboration, Ivanti, DLink, DrayTek, GPAC, and SAP. Notably, these vulnerabilities span a range of severity levels, from critical to medium, demanding immediate attention. One of the most interesting entries is CVE202445519, associated with Zimbra Collaboration. This critical vulnerability has been assigned a CVSS score of 9.8, indicating its severe nature. The issue arises from the postjournal service in specific versions of Zimbra, which may permit unauthenticated users to execute commands.  This vulnerability was first analyzed by researche...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Global Police Track Human Traffickers in Online Crackdown πŸ“”

Europol claims its EMPACT operation has revealed dozens of human trafficking victims and suspects.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GoldenJackal Target Embassies and Air-Gapped Systems Using Malware Toolsets πŸ–‹οΈ

A littleknown threat actor tracked as GoldenJackal has been linked to a series of cyber attacks targeting embassies and governmental organizations with an aim to infiltrate airgapped systems using two disparate bespoke toolsets. Victims included a South Asian embassy in Belarus and a European Union government E.U. organization, Slovak cybersecurity company ESET said. "The ultimate goal of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity