πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“” Penn State Settles for $1.25M Over Cybersecurity Violations πŸ“”

Penn State will pay 1.25m for failing federal cybersecurity standards in DoD and NASA contracts.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” White House Issues AI National Security Memo πŸ“”

The National Security Memorandum on AI sets out actions for the federal government to ensure the safe, secure and trustworthy development of AI.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Fortinet Confirms Exploitation of Critical FortiManager Zero-Day Vulnerability πŸ“”

This highseverity flaw, dubbed FortiJump by security researcher Kevin Beaumont, has been added to CISAs KEV catalog.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Government Introduces New Data Governance Legislation πŸ“”

The Data Use and Access Bill governs digital verification services and the use of personal data in public services, and will revamp the Information Commissioners Office.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Cybersecurity Teams Largely Ignored in AI Policy Development πŸ“”

A new ISACA study has revealed that cybersecurity professionals are often overlooked in the development of AI policies.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… CISA Flags Critical Vulnerability (CVE-2024-47575) in Fortinet’s FortiManager πŸ¦…

Overview  The Cybersecurity and Infrastructure Security Agency CISA has added Fortinets FortiManager to its known Exploited Vulnerabilities KEV catalog, indicating a pressing need for organizations to address the associated risks.  The critical vulnerability identified as CVE202447575 has been assigned a CVSS score of 9.8. This vulnerability affects various versions of FortiManager, including FortiManager 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, and 6.2.0 through 6.2.12, as well as multiple iterations of FortiManager Cloud.   The vulnerability stems from a missing authentication issue within the critical functions of the FortiManager fgfmd daemon, allowing remote, unauthenticated attackers to execute arbitrary commands or code ...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Weekly Industrial Control System (ICS) Vulnerability Intelligence Report: New Flaws Affecting Siemens, Schneider Electric, and More πŸ¦…

Overview  Cyble Research Intelligence Labs CRIL has shared new details about weekly industrial control systems ICS vulnerabilities. These vulnerabilities were issued by the Cybersecurity and Infrastructure Security Agency CISA from October 15 to October 21, 2024. The report outlines critical security concerns affecting various vendors and highlights the urgency for organizations to address these vulnerabilities promptly.   During the reporting period, CISA released seven security advisories targeting ICS, which collectively identified 13 distinct vulnerabilities across several companies, including Siemens, Schneider Electric, Elvaco, Mitsubishi Electric, HMS Networks, KiebackPeter, and LCDS Leo Consultoria e Desenvolvimento de Sistemas Ltda ME. Notably, Elvaco disclosed four vul...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ•΅οΈβ€β™‚οΈ AI Chatbots Ditch Guardrails After 'Deceptive Delight' Cocktail πŸ•΅οΈβ€β™‚οΈ

The latest GenAI jailbreak technique tricks chatbots into returning restricted content by blending different prompt topics together.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cisco ASA, FTD Software Under Active VPN Exploitation πŸ•΅οΈβ€β™‚οΈ

Unauthenticated threat actors can remotely cause a denialofservice DoS cyberattack within the Remote Access VPN software in Cisco's ASA and Firepower software.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Lazarus Group Exploits Google Chrome Flaw in New Campaign πŸ“”

Lazarus Group exploited Google Chrome zeroday, infecting systems with Manuscrypt malware.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ New Qilin.B Ransomware Variant Emerges with Improved Encryption and Evasion Tactics πŸ–‹οΈ

Cybersecurity researchers have discovered an advanced version of the Qilin ransomware sporting increased sophistication and tactics to evade detection. The new variant is being tracked by cybersecurity firm Halcyon under the moniker Qilin.B. "Notably, Qilin.B now supports AES256CTR encryption for systems with AESNI capabilities, while still retaining Chacha20 for systems that lack this support.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Critical Bug Exploited in Fortinet's Management Console πŸ•΅οΈβ€β™‚οΈ

An attacker compromised one of Fortinet's most sensitive products and mopped up all kinds of reconnaissance data helpful for future mass device attacks.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
😱1
πŸ•΅οΈβ€β™‚οΈ AWS's Predictable Bucket Names Make Accounts Easier to Crack πŸ•΅οΈβ€β™‚οΈ

Amazon's open source Cloud Development Kit generates dangerously predictable naming patterns that could lead to an account takeover.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Microsoft: Healthcare Sees 300% Surge in Ransomware Attacks πŸ•΅οΈβ€β™‚οΈ

Even after the ransom is paid, such attacks lead to spikes in strokes and heart attacks and increased wait times for patients.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Irish Watchdog Imposes Record €310 Million Fine on LinkedIn for GDPR Violations πŸ–‹οΈ

The Irish data protection watchdog on Thursday fined LinkedIn 310 million 335 million for violating the privacy of its users by conducting behavioral analyses of personal data for targeted advertising. "The inquiry examined LinkedIn's processing of personal data for the purposes of behavioral analysis and targeted advertising of users who have created LinkedIn profiles members," the Data.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
🌊 vCISO GRC Auditor 🌊

The post vCISO GRC Auditor appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” MacOS-Focused Ransomware Attempts Leverage LockBit Brand πŸ“”

An unidentified threat actor has attempted to develop ransomware targeting macOS devices, posing as LockBit.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Everything you need to know about the β€˜mass exploitation’ of FortiManager appliances πŸ“’

A missing authentication flaw could allow an attacker to use a compromised FortiManager device to move laterally to other Fortinet devices and target enterprise environments.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Human error is cybersecurity’s number one concern, Kaseya report finds πŸ“’

IT professionals highlight bad user behavior and a lack of security training as key hurdles to overcome this year.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Eliminating AI Deepfake Threats: Is Your Identity Security AI-Proof? πŸ–‹οΈ

Artificial Intelligence AI has rapidly evolved from a futuristic concept to a potent weapon in the hands of bad actors. Today, AIbased attacks are not just theoretical threatsthey're happening across industries and outpacing traditional defense mechanisms.  The solution, however, is not futuristic. It turns out a properly designed identity security platform is able to deliver defenses.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ SEC Charges 4 Companies Over Misleading SolarWinds Cyberattack Disclosures πŸ–‹οΈ

The U.S. Securities and Exchange Commission SEC has charged four current and former public companies for making "materially misleading disclosures" related to the largescale cyber attack that stemmed from the hack of SolarWinds in 2020. The SEC said the companies Avaya, Check Point, Mimecast, and Unisys are being penalized for how they handled the disclosure process in the aftermath of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1