πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸͺ– Scalability Challenges in Privacy-Preserving Federated Learning πŸͺ–

This post is part of a series on privacypreserving federated learning. The series is a collaboration between NIST and the UK governments Responsible Technology Adoption Unit RTA, previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NISTs Privacy Engineering Collaboration Space or RTAs blog . Introduction In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong University of Liverpool, Dr. Mat Weldon UK Office of National Statistics ONS, and Sikha Pentyala University of Washington Tacoma, who were winners in the.

πŸ“– Read more.

πŸ”— Via "NIST"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Critical Mozilla Firefox Zero-Day Allows Code Execution πŸ•΅οΈβ€β™‚οΈ

The bug is already being exploited in the wild, but Firefox has provided patches for those who may be vulnerable.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Fidelity Notifies 77K Customers of Data Breach πŸ•΅οΈβ€β™‚οΈ

The thirdparty actor had access for two days, in the financial services company's second major breach of the year.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ•΅οΈβ€β™‚οΈ Microsoft Previews New Windows Feature to Limit Admin Privileges πŸ•΅οΈβ€β™‚οΈ

In its latest Windows preview, Microsoft adds a feature Administrator Protection designed to prevent threat actors from easily escalating privileges and restrict lateral movement.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Fidelity Data Breach Exposes Data of Over 77,000 Customers 🦿

An attacker snuck in by creating two new user accounts. Fidelity assures customers their investments arent affected.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Bohemia and Cannabia Dark Web Markets Taken Down After Joint Police Operation πŸ–‹οΈ

The Dutch police have announced the takedown of Bohemia and Cannabia, which has been described as the world's largest and longestrunning dark web market for illegal goods, drugs, and cybercrime services. The takedown is the result of a collaborative investigation with Ireland, the United Kingdom, and the United States that began towards the end of 2022, the Politie said. The marketplace.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New Critical GitLab Vulnerability Could Allow Arbitrary CI/CD Pipeline Execution πŸ–‹οΈ

GitLab has released security updates for Community Edition CE and Enterprise Edition EE to address eight security flaws, including a critical bug that could allow running Continuous Integration and Continuous Delivery CICD pipelines on arbitrary branches. Tracked as CVE20249164, the vulnerability carries a CVSS score of 9.6 out of 10. "An issue was discovered in GitLab EE.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Marriott’s FTC charge underlines danger of β€˜inheriting’ data breaches during acquisitions πŸ“’

Experts warn businesses should learn from the hotel chains failure to properly assess the implications of acquiring an entity that has glaring security issues.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ NCSC warns organizations of cyber threat from Russian Foreign Intelligence πŸ“’

Attackers linked to the Russian government are exploiting unpatched vulnerabilities, say UK and US security agencies.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“’ UK Public sector at risk from supply chain attacks, new report warns πŸ“’

Research from Blackberry suggests that overconfidence and a lack of visibility are leaving healthcare, education, and government organizations exposed.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Amazon Aurora deep dive πŸ“’

Deploy servers with a secure approach.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Marriot & Starwood Face $52M Settlement After Security Breaches πŸ•΅οΈβ€β™‚οΈ

The hotel giant will be held to higher security standards in a series of proposed requirements, including implementing a new annually reviewed security program.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ The Invisible Army of Non-Human Identities πŸ•΅οΈβ€β™‚οΈ

The future of cybersecurity will be shaped by how well we manage the explosion of NHIs.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Retail CISOs Take on More Risk to Foster Innovation πŸ•΅οΈβ€β™‚οΈ

CISOs in consumer and retail organizations appear to accept greater risks to allow for more innovation, which could be a model for future growth.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Firefox Update Patches Exploited Vulnerability 🦿

Investigation of the useafterfree flaw is ongoing, but organizations and individual users can update Firefox now for a fix.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Deepfakes Can Fool Facial Recognition on Crypto Exchanges 🦿

Creating new accounts under fake identities provides attackers with a way to launder money or commit fraud.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 The Internet Archive Breach: Over 31 Million User Accounts Exposed 🦿

Attackers got hold of a 6.4 GB file containing the email addresses and hashed passwords of users registered with The Internet Archive.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Cybersecurity Awareness Lags as Global Workforce Engages in Risky AI Practices 🦿

46 of Gen Z employees are sharing data with AI, according to new research.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🧠 How governance, risk and compliance (GRC) addresses growing data liability concerns 🧠

In an era where businesses increasingly rely on artificial intelligence AI and advanced data capabilities, the effectiveness of IT services is more critical than ever. Yet despite the advancements in technology, business leaders are increasingly dissatisfied with their IT departments. According to a study by IBMs Institute for Business Value, confidence in the effectiveness of The post How governance, risk and compliance GRC addresses growing data liability concerns appeared first on Security Intelligence.

πŸ“– Read more.

πŸ”— Via "Security Intelligence"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ GitHub, Telegram Bots, and QR Codes Abused in New Wave of Phishing Attacks πŸ–‹οΈ

A new taxthemed malware campaign targeting insurance and finance sectors has been observed leveraging GitHub links in phishing email messages as a way to bypass security measures and deliver Remcos RAT, indicating that the method is gaining traction among threat actors. "In this campaign, legitimate repositories such as the opensource tax filing software, UsTaxes, HMRC, and InlandRevenue were.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ How Hybrid Password Attacks Work and How to Defend Against Them πŸ–‹οΈ

Threat actors constantly change tactics to bypass cybersecurity measures, developing innovative methods to steal user credentials. Hybrid password attacks merge multiple cracking techniques to amplify their effectiveness. These combined approaches exploit the strengths of various methods, accelerating the passwordcracking process.  In this post, well explore hybrid attacks what they are.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity