πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Ransomware 'Crisis' in US Schools: More Than 1,000 Hit So Far in 2019 πŸ•΄

Meanwhile, the mayor of the city of New Orleans says no ransom money demands were made as her city struggles to recover from a major ransomware attack launched last week.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Weak Crypto Practice Undermining IoT Device Security πŸ•΄

Keyfactor says it was able to break nearly 250,000 distinct RSA keys - many associated with routers, wireless access points, and other Internet-connected devices.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Financial Services Breaches Less Common, More Damaging, Than Those in Other Sectors πŸ•΄

While far less common than breaches in other industry sectors, financial services breaches were more than twice as expensive, per record exposed, than the average for tech businesses.

πŸ“– Read

via "Dark Reading: ".
⚠ Facebook employees’ payroll data nabbed in car smash-and-grab ⚠

Bye-bye, payroll data for 29,000 US Facebook employees that got left on an unencrypted drive in an employee's car.

πŸ“– Read

via "Naked Security".
⚠ Mozilla mandates 2FA security for Firefox developers ⚠

Mozilla last week fired off an important memo to all Firefox extension developers telling them to turn on authentication (2FA) on their addons.mozilla.org (AMO) accounts.

πŸ“– Read

via "Naked Security".
πŸ” Salary survey: Experienced security managers make more than $250,000 a year πŸ”

Security pros in banking and finance make the most money but bonuses were common across all roles and industries.

πŸ“– Read

via "Security on TechRepublic".
⚠ Researchers discover weakness in IoT digital certificates ⚠

IoT devices are using weak digital certificates that could expose them to attack, according to a study released over the weekend.

πŸ“– Read

via "Naked Security".
⚠ Ransomware-seized New Orleans declares state of emergency ⚠

There are signs that the attackers used the particularly pernicious Ryuk strain of ransomware.

πŸ“– Read

via "Naked Security".
πŸ” Ellen DeGeneres, Lisa Kudrow, Facebook, and Google named worst password offenders of 2019 πŸ”

Big business aren't the only ones susceptible to password-related blunders, Dashlane found.

πŸ“– Read

via "Security on TechRepublic".
❌ Alexa, Google Home Eavesdropping Hack Not Yet Fixed ❌

Researchers say that Amazon and Google need to focus on weeding out malicious skills from the getgo, rather than after they are already live.

πŸ“– Read

via "Threatpost".
πŸ•΄ Disarming Disinformation πŸ•΄

Disinformation attacks are just as detrimental to businesses as they are to national elections. Here's what's at stake in 2020 and what infosec teams can do about them.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Data Security Startup Satori Cyber Launches with $5.25M Seed Round πŸ•΄

Satori Cyber aims to help businesses better protect and govern their information with its Secure Data Access Cloud.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Don't Make Security Training a 'One-and-Done' πŸ•΄

How to move beyond one-off campaigns and build a true security awareness program.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Siemens Contractor Sentenced for Writing 'Logic Bombs' πŸ•΄

David Tinley, 62, rigged software he wrote for the company starting in 2014 and into 2016, causing the programs to fail.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Talking to the Board about Cybersecurity πŸ•΄

A chief financial officer shares five winning strategies for an effective board-level conversation about right-sizing risk.

πŸ“– Read

via "Dark Reading: ".
❌ Epilepsy Foundation Bombarded with Seizure-Triggering Twitter Posts ❌

The Epilepsy Foundation has filed a criminal complaint against undisclosed Twitter users who users its Twitter feed to post seizure-inducing content.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2013-0202

Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-2237

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Ten Steps to Stop Intellectual Property Theft πŸ”

For every manufacturing firm, sensitive data is the most valuable asset. If this critical information – in particular, intellectual property (IP) – is ever lost or stolen, manufacturers not only face significant fines and penalties but also suffer a hit to their reputations and public trust. Perhaps most importantly, they risk losing their competitive advantage, which can ultimately lead to business failure and bankruptcy.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Rooster Teeth Attack Showcases New Magecart Approach ❌

The streaming video and podcast content company was hit by a payment-card attack.

πŸ“– Read

via "Threatpost".