🛡 Cybersecurity & Privacy 🛡 - News
26K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
📢 Cyber expert suggests American Water cyber incident was a ransomware attack 📢

The attack left 14 million customers without access to a service portal, disrupting billing processes, though the firm said it does not believe its water facilities were impacted.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity
👍1
🖋️ 6 Simple Steps to Eliminate SOC Analyst Burnout 🖋️

The current SOC model relies on a scarce resource human analysts. These professionals are expensive, in high demand, and increasingly difficult to retain. Their work is not only highly technical and highrisk, but also soulcrushingly repetitive, dealing with a constant flood of alerts and incidents. As a result, SOC analysts often leave in search of better pay, the opportunity to move beyond.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🦅 Cyble Urges ICS Vulnerability Fixes for TEM, Mitsubishi, and Delta Electronics 🦅

Key Takeaways Cyble researchers investigated vulnerabilities in five ICSOT products this week and identified Mitsubishi Electric, TEM, and Delta Electronics products as top priorities for security teams. TEM has been unresponsive to reports of vulnerabilities in Opera Plus FM Family Transmitters, version 35.45, so users are urged to take mitigation steps. Mitsubishi Electric has no plans to fix vulnerabilities in MELSEC iQF FX5OPC communication units and instead recommended mitigation steps. Overview Cyble researchers have identified vulnerabilities in three products used in critical infrastructure environments that merit highpriority attention from security teams. Cybles weekly industrial control systemoperational technology ICSOT vulnerability report for Oct. 17 ...

📖 Read more.

🔗 Via "CYBLE"

----------
👁️ Seen on @cibsecurity
🖋️ Experts Warn of Critical Unpatched Vulnerability in Linear eMerge E3 Systems 🖋️

Cybersecurity security researchers are warning about an unpatched vulnerability in Nice Linear eMerge E3 access controller systems that could allow for the execution of arbitrary operating system OS commands. The flaw, assigned the CVE identifier CVE20249441, carries a CVSS score of 9.8 out of a maximum of 10.0, according to VulnCheck. "A vulnerability in the Nortek Linear eMerge E3 allows.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Walking the Tightrope Between Innovation & Risk 🕵️‍♂️

When employees and leaders engage with CISOs early in innovation projects, security concerns are addressed proactively, building trust and ensuring innovation and security coexist.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🦿 Deloitte: Why Only a Quarter of Cybersecurity Professionals are Women 🦿

Despite a huge talent shortage in the cybersecurity industry, women still feel discouraged from joining it due to concerns over their knowledge, its inclusivity, and the pay.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🛠 Wireshark Analyzer 4.4.1 🛠

Wireshark is a GTKbased network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercialquality analyzer for Unix and Win32 and to give Wireshark features that are missing from closedsource sniffers. This is the source code release.

📖 Read more.

🔗 Via "Packet Storm - Tools"

----------
👁️ Seen on @cibsecurity
🛠 I2P 2.7.0 🛠

I2P is an anonymizing network, offering a simple layer that identitysensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

📖 Read more.

🔗 Via "Packet Storm - Tools"

----------
👁️ Seen on @cibsecurity
🧠 Risk, reward and reality: Has enterprise perception of the public cloud changed? 🧠

Public clouds now form the bulk of enterprise IT environments. According to 2024 Statista data, 73 of enterprises use a hybrid cloud model, 14 use multiple public clouds and 10 use a single public cloud solution. Multiple and single private clouds make up the remaining 3. With enterprises historically reticent to adopt public clouds, adoption The post Risk, reward and reality Has enterprise perception of the public cloud changed? appeared first on Security Intelligence.

📖 Read more.

🔗 Via "Security Intelligence"

----------
👁️ Seen on @cibsecurity
🖋️ OpenAI Blocks 20 Global Malicious Campaigns Using AI for Cybercrime and Disinformation 🖋️

OpenAI on Wednesday said it has disrupted more than 20 operations and deceptive networks across the world that attempted to use its platform for malicious purposes since the start of the year. This activity encompassed debugging malware, writing articles for websites, generating biographies for social media accounts, and creating AIgenerated profile pictures for fake accounts on X. "Threat.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
📔 Disinformation Campaign Targets Moldova Ahead of EU Referendum 📔

Operation MiddleFloor targets Moldovas October elections, spreading EU disinformation via email.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Over 10m Conversations Exposed in AI Call Center Hack 📔

The data breach exposed more than 10m customer conversations from an AI call center platform in the Middle East.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 EU Adopts Cyber Resilience Act for Connected Devices 📔

The EU's Cyber Resilience Act requires cybersecurity standards for all connected products throughout their entire lifecycle.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📔 Marriott Agrees $52m Settlement for Massive Data Breach 📔

Marriott will pay 52m to 50 US states for a data breach impacting 131.5 million American customers, and has agreed to implement stronger security practices.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🪖 Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024 🪖

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, QA style blogs will be published featuring some of our unique staff members who have interesting backgrounds, stories to tell, and projects in the world of cybersecurity. This years Cybersecurity Awareness Month theme is Secure our World. How does this theme resonate with you, as someone working in cybersecurity? The theme Secure our World resonates with me because I enjoy researching about cybersecurity.

📖 Read more.

🔗 Via "NIST"

----------
👁️ Seen on @cibsecurity
🪖 Scalability Challenges in Privacy-Preserving Federated Learning 🪖

This post is part of a series on privacypreserving federated learning. The series is a collaboration between NIST and the UK governments Responsible Technology Adoption Unit RTA, previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NISTs Privacy Engineering Collaboration Space or RTAs blog . Introduction In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong University of Liverpool, Dr. Mat Weldon UK Office of National Statistics ONS, and Sikha Pentyala University of Washington Tacoma, who were winners in the.

📖 Read more.

🔗 Via "NIST"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Critical Mozilla Firefox Zero-Day Allows Code Execution 🕵️‍♂️

The bug is already being exploited in the wild, but Firefox has provided patches for those who may be vulnerable.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Fidelity Notifies 77K Customers of Data Breach 🕵️‍♂️

The thirdparty actor had access for two days, in the financial services company's second major breach of the year.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
1
🕵️‍♂️ Microsoft Previews New Windows Feature to Limit Admin Privileges 🕵️‍♂️

In its latest Windows preview, Microsoft adds a feature Administrator Protection designed to prevent threat actors from easily escalating privileges and restrict lateral movement.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🦿 Fidelity Data Breach Exposes Data of Over 77,000 Customers 🦿

An attacker snuck in by creating two new user accounts. Fidelity assures customers their investments arent affected.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🖋️ Bohemia and Cannabia Dark Web Markets Taken Down After Joint Police Operation 🖋️

The Dutch police have announced the takedown of Bohemia and Cannabia, which has been described as the world's largest and longestrunning dark web market for illegal goods, drugs, and cybercrime services. The takedown is the result of a collaborative investigation with Ireland, the United Kingdom, and the United States that began towards the end of 2022, the Politie said. The marketplace.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity