πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🌊 Head of Talent Acquisition 🌊

The post Head of Talent Acquisition appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… HeptaX: Unauthorized RDP Connections for Cyberespionage Operations πŸ¦…

Key takeaways Cyble Research and Intelligence Labs CRIL came across an ongoing cyberattack campaign originating from malicious LNK files. The sophisticated multistage attack chain relies heavily on PowerShell and BAT scripts to streamline the download and execution of additional payloads, demonstrating the Threat Actors TA preference for scriptbased methods to evade detection by traditional security solutions. The attack involves the creation of an administrative account on the victims system and altering Remote Desktop settings to lower authentication requirements, simplifying unauthorized RDP access for the attacker. The campaign deploys an additional wellknown password recovery tool, ChromePass, which collects saved passwords from Chromiumbased browsers, increasing the ris...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1πŸ”₯1
πŸ¦… Cyble Unveils Four Groundbreaking Capabilities for Enhanced Threat Intelligence πŸ¦…

With rapid digital advancement, organizations face unprecedented challenges in safeguarding their assets and reputation. Recognizing this need, Cyble Inc. has launched four revolutionary capabilities tailored specifically for Cybersecurity for Executives. These innovations significantly advance Executive Protection and digital risk management, ensuring executives are equipped to navigate the complexities of modern threats. From safeguarding executive travels to countering deepfake threats and providing realtime Azure Security Monitoring, these capabilities highlight Cybles unwavering commitment to comprehensive security. Heres a closer look at each innovation and the unique benefits they bring to todays threat landscape.  Physical Threat Intelligence for Executive Travel Ensuring Sa...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… CISA Warns of Critical Vulnerabilities: CVE-2024-20481 and CVE-2024-37383 Require Immediate Attention πŸ¦…

Overview The Cybersecurity and Infrastructure Security Agency CISA has issued urgent advisories regarding two vulnerabilities that pose substantial risks to organizations CVE202420481, a denialofservice DoS vulnerability affecting Cisco Adaptive Security Appliance ASA and Firepower Threat Defense FTD, and CVE202437383, a crosssite scripting XSS vulnerability in RoundCube Webmail. Both vulnerabilities highlight the necessity for immediate action to safeguard against potential exploitation. The relevant CVE IDs for these vulnerabilities are CVE202437383 and CVE202420481. The first vulnerability, CVE202437383, affects Roundcube Webmail versions prior to 1.5.7 and 1.6.x before 1.6.7, while CVE202420481 impacts Cisco products running a vulnerable release of Cisco ASA or FTD Software wi...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… Cyble Sensors Detect New Attacks on CMS; IoT Exploits Continue πŸ¦…

Overview Cybles weekly sensor intelligence report detailed dozens of active attack campaigns against known vulnerabilities. New to the list are attacks on a vulnerability in the SPIP opensource content management CMS and publishing system, while previously reported campaigns targeting vulnerabilities in PHP, Linux systems, Java and Python frameworks, and more have continued unabated. Older vulnerabilities in IoT devices and embedded systems continue to be exploited at alarming rates. New to the report this week are exploits of vulnerabilities that may still be present in some Siemens products and network devices. As these vulnerabilities likely exist within some critical infrastructure environments, organizations with internetfacing IoT devices and embedded systems are advised t...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ•΅οΈβ€β™‚οΈ LinkedIn Hit With $335M Fine for Data Privacy Violations πŸ•΅οΈβ€β™‚οΈ

The networking company found liable for illegally gathering user data for targeted advertising by the Irish Data Protection Commission.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Russia's APT29 Mimics AWS to Steal Windows Credentials πŸ•΅οΈβ€β™‚οΈ

Kremlin intelligence carried out a widescale phishing campaign in contrast to its usual, more targeted operations.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ SEC Fines Companies Millions for Downplaying SolarWinds Breach πŸ•΅οΈβ€β™‚οΈ

Four companies Avaya, Check Point, Mimecast, and Unisys have been charged by the SEC for misleading disclosures in the aftermath of the 2020 SolarWinds compromise.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ UnitedHealth Reveals 100M Compromised in Change Healthcare Breach πŸ•΅οΈβ€β™‚οΈ

Eight months after the breach occurred, Change Healthcare has finally sent out millions of notices of compromised data to affected individuals.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Change Healthcare Cyberattack Exposed Data of Over 100 Million People 🦿

Nearly onethird of Americans may have been affected by the ransomware attack, which has been attributed to the BlackCat gang.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸͺ– Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024 πŸͺ–

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, QA style blogs will be published featuring some of our unique staff members who have interesting backgrounds, stories to tell, and projects in the world of cybersecurity. This years Cybersecurity Awareness Month theme is Secure our World. How does this theme resonate with you, as someone working in cybersecurity? The theme 'Secure our World' resonates deeply with me, as it emphasizes our collective.

πŸ“– Read more.

πŸ”— Via "NIST"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ CERT-UA Identifies Malicious RDP Files in Latest Attack on Ukrainian Entities πŸ–‹οΈ

The Computer Emergency Response Team of Ukraine CERTUA has detailed a new malicious email campaign targeting government agencies, enterprises, and military entities. "The messages exploit the appeal of integrating popular services like Amazon or Microsoft and implementing a zerotrust architecture," CERTUA said. "These emails contain attachments in the form of Remote Desktop Protocol '.rdp'.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Notorious Hacker Group TeamTNT Launches New Cloud Attacks for Crypto Mining πŸ–‹οΈ

The infamous cryptojacking group known as TeamTNT appears to be readying for a new largescale campaign targeting cloudnative environments for mining cryptocurrencies and renting out breached servers to thirdparties. "The group is currently targeting exposed Docker daemons to deploy Sliver malware, a cyber worm, and cryptominers, using compromised servers and Docker Hub as the infrastructure.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘3
πŸ–‹οΈ Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions πŸ–‹οΈ

Four members of the nowdefunct REvil ransomware operation have been sentenced to several years in prison in Russia, marking one of the rare instances where cybercriminals from the country have been convicted of hacking and money laundering charges. Russian news publication Kommersant reported that a court in St. Petersburg found Artem Zaets, Alexei Malozemov, Daniil Puzyrevsky, and Ruslan.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘4
πŸ‘½ U.S. Citizens’ Data Allegedly on Sale πŸ‘½

A threat actor claimed that they have and are selling 280 million U.S. citizens personal data on dark web. According to the post of the threat actor, the data includes FirstNameLastName AddressCityStateZIP IndDateOfBirthYearIndAge HomeValueCodeHomeMedianValueCodeMedianIncomeCode EmailPhone They are also claiming that they can provide sample data to the prospects. Meanwhile, they.

πŸ“– Read more.

πŸ”— Via "BE3SEC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘5❀1
πŸ–‹οΈ Researchers Uncover OS Downgrade Vulnerability Targeting Microsoft Windows Kernel πŸ–‹οΈ

A new attack technique could be used to bypass Microsoft's Driver Signature Enforcement DSE on fully patched Windows systems, leading to operating system OS downgrade attacks. "This bypass allows loading unsigned kernel drivers, enabling attackers to deploy custom rootkits that can neutralize security controls, hide processes and network activity, maintain stealth, and much more," SafeBreach.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ The National Public Data breach exposed nearly three billion users – now the company has filed for bankruptcy πŸ“’

National Public Datas decline after a devastating cyber attack took roughly six months, as it failed to stay afloat amid mounting recovery costs.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ LinkedIn fined €310 million for GDPR breaches πŸ“’

The social networking platform has accepted the ruling and will implement changes to its ad tracking processes.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Is Firefox Password Manager Secure? 🦿

Like other password managers, there are risks and drawbacks to consider before trusting Firefox Password Manager with your credentials.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Hiring Kit: Computer Forensic Analyst 🦿

The increasing emphasis on securing sensitive data by regulatory agencies and governments worldwide has opened job opportunities beyond criminal justice for capable individuals with proficient technical skills, inquisitive analytical mindsets, and the tenacious drive to solve seemingly intractable problems. This customizable hiring kit, written by Mark W. Kaelin for TechRepublic Premium, provides a framework you ...

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ THN Cybersecurity Recap: Top Threats, Tools and News (Oct 21 - Oct 27) πŸ–‹οΈ

Cybersecurity news can sometimes feel like a neverending horror movie, can't it? Just when you think the villains are locked up, a new threat emerges from the shadows. This week is no exception, with tales of exploited flaws, international espionage, and AI shenanigans that could make your head spin. But don't worry, we're here to break it all down in plain English and arm you with the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity