🛡 Cybersecurity & Privacy 🛡 - News
26K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
📔 Half of Organizations Have Unmanaged Long-Lived Cloud Credentials 📔

Longlived credentials in the cloud put organizations at high risk of breaches, a report from Datadog has found.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🦅 Splunk’s Latest Advisory: Addressing Multiple Vulnerabilities in Splunk Enterprise 🦅

Overview Splunk has recently issued an advisory detailing multiple vulnerabilities discovered in its Splunk Enterprise software. The advisory categorize vulnerabilities into three primary classifications based on their CVSS base scores. In total, there are two vulnerabilities classified as High, with a risk score deemed Critical. The Medium category includes eight vulnerabilities, while there is one vulnerability classified as Low. The advisory identifies several CVE IDs associated with these vulnerabilities, specifically CVE202445731, CVE202445732, CVE202445733, CVE202445734, CVE202445735, CVE202445736, CVE202445737, CVE202445738, CVE202445739, CVE202445740, and CVE202445741. Importantly, Splunk has confirmed that patches are available for all identified vulnerabilities, urgi...

📖 Read more.

🔗 Via "CYBLE"

----------
👁️ Seen on @cibsecurity
🦅 Weekly Industrial Control System (ICS) Intelligence Report: 54 New Vulnerabilities in Siemens, Rockwell Automation, and Delta Products 🦅

Overview Cyble Research Intelligence Labs CRIL has released its latest Weekly Industrial Control System ICS Vulnerability Intelligence Report, sharing multiple vulnerabilities observed by the Cybersecurity and Infrastructure Security Agency CISA between October 8 and October 14, 2024. This weeks analysis focuses on security advisories and vulnerabilities that affect critical industrial infrastructure. The Cybersecurity and Infrastructure Security Agency CISA has published 21 security advisories specifically targeting Industrial Control Systems ICS. These advisories encompass a total of 54 distinct vulnerabilities affecting major vendors, including Siemens, Rockwell Automation, Schneider Electric, and Delta Electronics. Among these, Siemens has reported the highest number of ...

📖 Read more.

🔗 Via "CYBLE"

----------
👁️ Seen on @cibsecurity
📔 50,000 Files Exposed in Nidec Ransomware Attack 📔

The August ransomware attack stole 50,000 documents from Nidec, leaked after ransom refusal.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Anti-Bot Services Help Cybercrooks Bypass Google 'Red Page' 🕵️‍♂️

The emergence of novel antidetection kits for sale on the Dark Web limit the effectiveness of a Chrome browser feature that warns users that they have reached a phishing page.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🦿 Get 9 Courses on Ethical Hacking for Just $50 🦿

Kickstart a lucrative career in pentesting and ethical hacking with this ninecourse bundle from IDUNOVA, now on sale for just 49.99 for a limited time.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
🤔1
📔 Stolen Access Tokens Lead to New Internet Archive Breach 📔

A threat actor claimed to get hold of an exposed GitLab configuration file containing Zendesk API access tokens.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🦿 ISC2 Security Congress 2024: The Landscape of Nation-State Cyber Attacks 🦿

CISA advisor Nicole Perlroth closed out ISC2 Security Congress keynotes with a wakeup call for security teams to watch for nationstatesponsored attacks.

📖 Read more.

🔗 Via "Tech Republic"

----------
👁️ Seen on @cibsecurity
👽 Do U.S. Local Authorities Under Attack? 👽

A threat actor claimed they have and are selling data of two different U.S. local authorities in a dark web forum. The first one is U.S. local authority in Durango durangoco.gov. The threat actor has claimed that another threat actor breached via a vulnerability in the website of the local.

📖 Read more.

🔗 Via "BE3SEC"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Unmanaged Cloud Credentials Pose Risk to Half of Orgs 🕵️‍♂️

These types of "longlived" credentials pose a risk for users across all major cloud service providers, and must meet their very timely ends, researchers say.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Cisco Disables DevHub Access After Security Breach 🕵️‍♂️

The networking company confirms that cyberattackers illegally accessed data belonging to some of its customers.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Internet Archive Gets Pummeled in Round 2 Breach 🕵️‍♂️

This latest breach was through Zendesk, a customer service platform that the organization uses.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🕵️‍♂️ Russia-Linked Hackers Attack Japan's Govt, Ports 🕵️‍♂️

Russialinked hackers have taken aim at Japan, following its ramping up of military exercises with regional allies and the increase of its defense budget.

📖 Read more.

🔗 Via "Dark Reading"

----------
👁️ Seen on @cibsecurity
🚀 Google Voice scams: What are they and how do I avoid them? 🚀

Watch out for schemes where fraudsters trick people into sharing verification codes so they can gain access to their phone numbers.

📖 Read more.

🔗 Via "ESET - WeLiveSecurity"

----------
👁️ Seen on @cibsecurity
📔 Severe Flaws Discovered in Major E2EE Cloud Storage Services 📔

The cryptographic vulnerabilities were found in Sync, pCloud, Icedrive and Seafile by ETH Zurich.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
🖋️ CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack 🖋️

The U.S. Cybersecurity and Infrastructure Security Agency CISA on Monday added a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities KEV catalog, following reports of active exploitation as a zeroday. The vulnerability in question, tracked as CVE20249537 CVSS v4 score 9.3, refers to a bug involving an unspecified thirdparty component that could.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
🖋️ VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability 🖋️

VMware has released software updates to address an already patched security flaw in vCenter Server that could pave the way for remote code execution. The vulnerability, tracked as CVE202438812 CVSS score 9.8, concerns a case of heapoverflow vulnerability in the implementation of the DCERPC protocol. "A malicious actor with network access to vCenter Server may trigger this vulnerability by.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
👽 The Phantom Menace of Social Engineering 👽

Clickjacking Clickfix, also known as a UI redress attack, is a malicious technique where an attacker tricks a user into clicking on something different from what they perceive they are clicking on. This is often achieved by layering invisible or disguised elements over legitimate website content. For example, an attacker.

📖 Read more.

🔗 Via "BE3SEC"

----------
👁️ Seen on @cibsecurity
👽 The Dark Web’s Information Bazaar: How Threat Actors Share Vulnerability Data 👽

Recently, we published an intel about data leakage from some U.S. local authorities. It was about two different local authorities in U.S. and was showing us how threat actors share information between them. To put it very briefly, a threat actor claimed they have data of these authorities and they.

📖 Read more.

🔗 Via "BE3SEC"

----------
👁️ Seen on @cibsecurity
📔 AI-Powered Attacks Flood Retail Websites 📔

AI tools are being used to launch over half a million cyberattacks daily on retailers, according to a new report.

📖 Read more.

🔗 Via "Infosecurity Magazine"

----------
👁️ Seen on @cibsecurity
📢 Cisco confirms attackers stole data, shuts down access to compromised DevHub environment 📢

The tech giant insists that no sensitive customer information has been compromised.

📖 Read more.

🔗 Via "ITPro"

----------
👁️ Seen on @cibsecurity