πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🧠 Is AI saving jobs… or taking them? 🧠

Artificial intelligence AI is coming to take your cybersecurity job. Or, AI will save your job. Well, which is it? As with all things securityrelated, AIrelated and employmentrelated, its complicated. How AI creates jobs A major reason its complicated is that AI is helping to increase the demand for cybersecurity professionals in two broad ways. The post Is AI saving jobs or taking them? appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” 31 New Ransomware Groups Join the Ecosystem in 12 Months πŸ“”

Secureworks reports a 30 increase in active ransomware groups despite law enforcement efforts, with 31 new groups emerging in the past year.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘3
πŸ“’ Do more with less: Optimizing servers with HPE to maximize VMware licensing πŸ“’

Your trusted guide through the changes in the virtualization market.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Ex-Uber CISO Requests a New, 'Fair' Trial πŸ•΅οΈβ€β™‚οΈ

Attorneys for Joseph Sullivan argue the jury didn't hear essential facts of the case during the original trial and that his conviction must be overturned.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ 5 CVEs in Microsoft's October Update to Patch Immediately πŸ•΅οΈβ€β™‚οΈ

Threat actors are actively exploiting two of the vulnerabilities, while three others are publicly known and ripe for attack.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Healthcare's Grim Cyber Prognosis Requires Security Booster πŸ•΅οΈβ€β™‚οΈ

As healthcare organizations struggle against operational issues, twothirds of the industry suffered ransomware attacks in the past year, and an increasing number are caving to extortion and paying up.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ How Major Companies Are Honoring Cybersecurity Awareness Month πŸ•΅οΈβ€β™‚οΈ

The annual event reinforces best practices while finding new ways to build a culture where employees understand how their daily decisions affect company security. Find out how AWS, IBM, Intuit, SentinelOne, and Gallo are spreading the word.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ The Perils of Ignoring Cybersecurity Basics πŸ•΅οΈβ€β™‚οΈ

The massive outage involving a faulty Falcon update is an excellent illustration of what happens when organizations neglect security fundamentals.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Your IT Systems Are Being Attacked. Are You Prepared? πŸ•΅οΈβ€β™‚οΈ

Company leadership needs to ensure technology teams are managing continuous monitoring, automated testing, and alignment with business needs across their enterprise.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ American Water Suffers Network Disruptions After Cyberattack πŸ•΅οΈβ€β™‚οΈ

The largest publicly traded water utility in the US was forced to disconnect some of its online systems, and its website and telecommunications system remained unavailable as of Tuesday morning, Oct. 8.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ›  NIELD (Network Interface Events Logging Daemon) 0.6.2 πŸ› 

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the netlink socket and generates logs related to link state, neighbor cache ARP,NDP, IP address IPv4,IPv6, route, FIB rules, and traffic control.

πŸ“– Read more.

πŸ”— Via "Packet Storm - Tools"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Patch Tuesday, October 2024 Edition β™ŸοΈ

Microsoft today released security updates to fix at least 117 security holes in Windows computers and other software, including two vulnerabilities that are already seeing active attacks. Also, Adobe plugged 52 security holes across a range of products, and Apple has addressed a bug in its new macOS 15 "Sequoia" update that broke many cybersecurity tools.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited πŸ–‹οΈ

Ivanti has warned that three new security vulnerabilities impacting its Cloud Service Appliance CSA have come under active exploitation in the wild. The zeroday flaws are being weaponized in conjunction with another flaw in CSA that the company patched last month, the Utahbased software services provider said. Successful exploitation of these vulnerabilities could allow an authenticated.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Gamers Tricked Into Downloading Lua-Based Malware via Fake Cheating Script Engines πŸ–‹οΈ

Users searching for game cheats are being tricked into downloading a Luabased malware that is capable of establishing persistence on infected systems and delivering additional payloads. "These attacks capitalize on the popularity of Lua gaming engine supplements within the student gamer community," Morphisec researcher Shmuel Uzan said in a new report published today, adding "this malware.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” American Water Hit by Cyber-Attack, Billing Systems Disrupted πŸ“”

American Water, the largest water utility in the US, discovered a cyberattack impacting internal systems on October 3.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cloud Security Risks Surge as 38% of Firms Face Exposures πŸ“”

Tenables latest report reveals 38 of organizations face risks from a toxic cloud triad of security gaps.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Apple Issues Urgent Security Advisory for iOS and iPadOS Vulnerabilities πŸ¦…

Overview Apple has released a new security advisory highlighting the issues affecting Apples iOS and iPadOS platforms. As detailed in the advisory, two vulnerabilities have been identified, both of which affect Apple iOS and iPadOS up to version 18.0. The vendor is Apple, and patches are available for these vulnerabilities.  The first vulnerability, CVE202444204, relates to information disclosure and has been assigned a CVSSv3.1 score of 5.5, indicating a medium severity level. This vulnerability allows saved passwords to be read aloud by the VoiceOver feature, posing a significant privacy risk for users on affected iOS and iPadOS versions. A patch is available for this vulnerability. The second vulnerability, CVE202444207, also relates to information disclosure, with a CVSSv3...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… MisterioLNK: The Open-Source Builder Behind Malicious Loaders πŸ¦…

Cyble Research and Intelligence Labs CRIL has uncovered a new, previously undetected loader builder known as "MisterioLNK." This discovery follows our earlier analysis of Quantum Software, another LNK filebased builder that has been gaining traction in the cyber landscape. MisterioLNK, available on GitHub, presents a significant challenge to security defenses, as files generated by this tool currently exhibit minimal or zero detection rates by conventional security systems. As described on GitHub, MisterioLNK is an opensource loader builder that leverages Windows script engines to execute malicious payloads while employing obfuscation as well. It is crafted to operate discreetly, downloading files into temporary directories before launching them, thereby enhancing its evasive capabi...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks πŸ–‹οΈ

Microsoft is warning of cyber attack campaigns that abuse legitimate file hosting services such as SharePoint, OneDrive, and Dropbox that are widely used in enterprise environments as a defense evasion tactic. The end goal of the campaigns are broad and varied, allowing threat actors to compromise identities and devices and conduct business email compromise BEC attacks, which ultimately result.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the Wild πŸ–‹οΈ

Microsoft has released security updates to fix a total of 118 vulnerabilities across its software portfolio, two of which have come under active exploitation in the wild. Of the 118 flaws, three are rated Critical, 113 are rated Important, and two are rated Moderate in severity. The Patch Tuesday update doesn't include the 25 additional flaws that the tech giant addressed in its Chromiumbased.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Microsoft Fixes Five Zero-Days in October Patch Tuesday πŸ“”

Octobers Patch Tuesday saw Microsoft patch over 100 CVEs including five zeroday vulnerabilities.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity