Cyber security aggregate rss news

Cyber security aggregator - feeds history

image for Transatlantic Cable  ...

 News

We kick off this week’s Kaspersky Transatlantic Cable podcast with a bit of a PSA from Facebook. With the social giant rolling out tools to help people get a COVID-19 vaccine, Dave and I have some misgivings, although we do both think you should get a vaccine. After that, we chat with Vladimir Kuskov, head of   show more ...

Advanced Threat Research and Software Classification at Kaspersky, for an update on the Microsoft Exchange vulnerabilities and their exploitation.   Then it’s over to the world of deepfakes and a pair of stories. The first involves a machine vs. machine battle wherein new software uses eye reflections to identify whether a video is a deepfake or the real McCoy. The second is about a Pennsylvania woman who created pictures and videos of her daughter’s cheerleading rivals. Moving along, we talk about a UK Home Office campaign that was an “experiment” — but was it really? And to close out the show, we look at Nvidia’s battle against cryptomining. If you liked what you heard, please consider subscribing and sharing with your friends. For more information on the stories we covered, see the links below: To help people find COVID-19 vaccines, Facebook debuts new features Scientists developed a clever way to detect Deepfakes by analyzing light reflections in the eyes Pa. woman created ‘deepfake’ videos to force rivals off daughter’s cheerleading squad: police Home Office tests web-spying powers with help of UK internet firms Nvidia’s new beta driver unlocks RTX 3060 Ethereum cryptocurrency mining

 Trends, Reports, Analysis

The FBI has published its annual report on cybercrime affecting victims in the U.S., noting a record number of complaints and financial losses in 2020 compared to the previous year.

 Malware and Vulnerabilities

The .com and .net sites have seen 2,746 downloads of the malicious Windows executable, and a second-stage malware was then pushed down 129 times. The .org site snared 529 downloads in just two days.

 Malware and Vulnerabilities

A popular line of small business routers made by Cisco Systems is vulnerable to a high-severity vulnerability which could allow a remote, authenticated attacker to execute code or restart devices.

 Trends, Reports, Analysis

Remote Desktop Protocol (RDP) became a hot target for cybercrime as businesses shifted to remote work due to the COVID-19 pandemic. A year later, the trend shows no sign of slowing.

 Trends, Reports, Analysis

A wealthy British art collector was hit by a BEC attack costing him ~$8.35m. It had been sent to the family office that managed his finances by criminals impersonating a genuine art dealer.

 Trends, Reports, Analysis

Among other threats, email scamming proved to the most successful infection vector in the coronavirus era, Kaspersky finds. It also changed the way people understood cybersecurity.

 Malware and Vulnerabilities

Trustwave researchers have spotted a new malspam campaign that is exploiting icon files to deceive victims into executing the NanoCore RAT. 

 Trends, Reports, Analysis

The extent and severity of ransomware attacks witnessed an all-time high in 2020 and there’s no reason to believe that it is going to be any different this year. 

 Malware and Vulnerabilities

TrickBot uses person-in-the-browser attacks to steal information, such as login credentials. Some of TrickBot’s modules spread the malware laterally across a network by abusing the SMB protocol.

 Feed

Red Hat Security Advisory 2021-0933-01 - Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY principle.

 Feed

Red Hat Security Advisory 2021-0931-01 - Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic. OVN, the Open Virtual Network, is a system to support virtual network abstraction. OVN complements the existing capabilities of OVS to add   show more ...

native support for virtual network abstractions, such as virtual L2 and L3 overlays and security groups. Issues addressed include buffer overflow and integer overflow vulnerabilities.

 Feed

Red Hat Security Advisory 2021-0934-01 - KVM is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Issues addressed include a use-after-free vulnerability.

 Feed

Ubuntu Security Notice 4881-1 - It was discovered that containerd incorrectly handled certain environment variables. Contrary to expectations, a container could receive environment variables defined for a different container, possibly containing sensitive information.

 Feed

VestaCP version 0.9.8 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting was discovered in this version in February of 2016 by Necmettin COSKUN.

 Feed

Red Hat Security Advisory 2021-0915-01 - Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY principle.

 Feed

Red Hat Security Advisory 2021-0922-01 - The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly. Issues addressed include a buffer overflow vulnerability.

 Feed

Researchers have disclosed vulnerabilities in multiple WordPress plugins that, if successfully exploited, could allow an attacker to run arbitrary code and take over a website in certain scenarios. The flaws were uncovered in Elementor, a website builder plugin used on more than seven million sites, and WP Super Cache, a tool used to serve cached pages of a WordPress site. According to Wordfence

 Feed

When a user account becomes locked out, the cause is often attributed to a user who has simply entered an old or incorrect password too many times. However, this is far from being the only thing that can cause an account to become locked. Another common cause, for example, is an application or script that is configured to log into the system using an old password. Perhaps the most easily

 Feed

Privacy-focused search engine DuckDuckGo called out rival Google for "spying" on users after the search giant updated its flagship app to spell out the exact kinds of information it collects for personalization and marketing purposes. "After months of stalling, Google finally revealed how much personal data they collect in Chrome and the Google app. No wonder they wanted to hide it," the company

 Feed

Are you looking to becoming a malware analyst? Then continue reading to discover how to gain the training you need and start a career in malware analysis career.Did you know that new malware is released every seven seconds? As more and more systems become reliant on the internet, the proliferation of malware becomes increasingly destructive. Once upon a time, a computer virus might cause

 Feed

A pair of critical vulnerabilities in a popular bulletin board software called MyBB could have been chained together to achieve remote code execution (RCE) without the need for prior access to a privileged account. The flaws, which were discovered by independent security researchers Simon Scannell and Carl Smith, were reported to the MyBB Team on February 22, following which it released an

 Data loss

How are cheerleaders being creeped out by deepfakes? What might Tinder tell potential dates about your murky past? And how should companies respond to the press when a security breach occurs? All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Yvonne Eskenzi.

2021-03
Aggregator history
Thursday, March 18
MON
TUE
WED
THU
FRI
SAT
SUN
MarchAprilMay