🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2011-3629

Joomla! core 1.7.1 allows information disclosure due to weak encryption

📖 Read

via "National Vulnerability Database".
🕴 Kubernetes Shows Built-in Weakness 🕴

A Shmoocon presentation points out several weaknesses built in to Kubernetes configurations and how a researcher can exploit them.

📖 Read

via "Dark Reading: ".
🕴 Twitter Suspends Fake Accounts Abusing Feature that Matches Phone Numbers and Users 🕴

The company believes state-sponsored actors may also be involved.

📖 Read

via "Dark Reading: ".
🕴 7 Ways SMBs Can Secure Their Websites 🕴

Here's what small and midsize businesses should consider when they decide it's time to up their website security.

📖 Read

via "Dark Reading: ".
Medtronic Patches Implanted Device, CareLink Programmer Bugs

The medical device giant has issued fixes for bugs first disclosed in 2018 and 2019.

📖 Read

via "Threatpost".
Two Critical Android Bugs Get Patched in February Update

As part of its February bug fixes, Google is patching a critical severity remote code execution vulnerability and an information disclosure bug.

📖 Read

via "Threatpost".
🕴 Ransomware Attacks: Why It Should Be Illegal to Pay the Ransom 🕴

For cities, states and towns, paying up is short-sighted and only makes the problem worse.

📖 Read

via "Dark Reading: ".
🔏 HHS Issues Coronavirus HIPAA Guidance 🔏

In the healthcare sector, concerns about the spreading coronavirus outbreak have reignited the discussion around HIPAA, protected health information, and when it's legal for healthcare providers to disclose patient records.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 Why many security pros lack confidence in their implementation of Zero Trust 🔐

Almost half of security professionals don't know where or how to use Zero Trust policies in a hybrid IT environment, says a survey commissioned by security provider Pulse Secure.

📖 Read

via "Security on TechRepublic".
🔐 How to sign up for Firefox breach alerts 🔐

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. Find out how to use Firefox Monitor.

📖 Read

via "Security on TechRepublic".
🔐 How to sign up for Firefox breach alerts 🔐

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. Find out how to use Firefox Monitor.

📖 Read

via "Security on TechRepublic".
🔐 Untested app and no training for volunteers are fatal in Iowa caucus 🔐

HR experts and tech leaders say organizations that skip training during a tech transition almost always pay a high price.

📖 Read

via "Security on TechRepublic".
Ransomware Attack Hinders Toll Group Operations

Customers took to Twitter to air their grievances after some of the transportation giant's operations were downed.

📖 Read

via "Threatpost".
🕴 Microsoft DART Finds Web Shell Threat on the Rise 🕴

Various APT groups are successfully using Web shell attacks on a more frequent basis.

📖 Read

via "Dark Reading: ".
Community Housing Nonprofit Hit with $1.2M Loss in BEC Scam

Red Kite said that domain-spoofing and convincing scam emails claiming to be from suppliers were the cause.

📖 Read

via "Threatpost".
🕴 SharePoint Bug Proves Popular Weapon for Nation-State Attacks 🕴

Thousands of servers could be exposed to SharePoint vulnerability CVE-2019-0604, recently used in cyberattacks against Middle East government targets.

📖 Read

via "Dark Reading: ".
🕴 8 of the 10 Most Exploited Bugs Last Year Involved Microsoft Products 🕴

Six of them were the same as from the previous year, according to new Recorded Future analysis.

📖 Read

via "Dark Reading: ".
🕴 Companies Pursue Zero Trust, but Implementers Are Hesitant 🕴

Almost three-quarters of enterprises plan to have a zero-trust access model by the end of the year, but nearly half of cybersecurity professionals lack the knowledge to implement the right technologies, experts say.

📖 Read

via "Dark Reading: ".
🔐 Why certain companies are more heavily targeted by DDoS attacks 🔐

Most of the targets in 2019 were in the gaming and gambling industries, says security company Imperva.

📖 Read

via "Security on TechRepublic".
🔐 How to protect your organization from infrastructure as code security risks 🔐

Infrastructure as code offers advantages in automating your data center management but also carries certain risks, says Unit 42, the global threat intelligence team at Palo Alto Networks.

📖 Read

via "Security on TechRepublic".
Gamaredon APT Improves Toolset to Target Ukraine Government, Military

The Gamaredon advanced persistent threat (APT) group has been supercharging its operations lately, improving its toolset and ramping up attacks on Ukrainian national security targets. Vitali Kremez, head of SentinelLabs, said in research released on Wednesday that he has been tracking an uptick in Gamaredon cyberattacks on Ukrainian military and security institutions that started in […]

📖 Read

via "Threatpost".