Cyber Security News
Open in Telegram
Be Cyber Aware. Our chat: t.me/cybersecuritynewschat Our vacancies channel: @CyberSecurityJobs LinkedIn: https://www.linkedin.com/company/securitynews/ Improve Your Cyber Skills: https://linktr.ee/cybersecuritynews ๐ฉ Cooperation: @cybersecadmin
Show more2025 year in numbers

54 706
Subscribers
-324 hours
+277 days
+31230 days
Posts Archive
๐ฉ CyberWeekly by Hacklido โ Issue โ7; 28th of September, 2024
Long time no see, but here is the latest CyberWeekly Newsletter, from our partners at Hacklido.
Dive in to explore the following industry topics:
โข EPA
โข NIST
โข CUPS
โข Patches
โข Malware
โข Logistics
โข ATG systems
โข Cyberattacks
โข Cybersecurity
โข Vulnerabilities
โข Transportation
โข Water treatment
โข Remote code execution
โข Authentication guidelines
Along with a variety of other useful materials.
Find the full article via this link.
-----
โ If your Company / Project / Community wants to become a partner of Cyber Security News...
Please, do not hesitate to contact us by sending a direct message to @cybersecadmin
-----
@Cyber_Security_Channel
๐ฉ CyberWeekly by Hacklido โ Issue โ7; 28th of September, 2024
Long time no see, but here is the latest CyberWeekly Newsletter, from our partners at Hacklido.
Dive in to explore the following industry topics:
โข EPA
โข NIST
โข CUPS
โข Patches
โข Malware
โข Logistics
โข ATG systems
โข Cyberattacks
โข Cybersecurity
โข Vulnerabilities
โข Transportation
โข Water treatment
โข Remote code execution
โข Authentication guidelines
Along with a variety of other useful materials.
Find the full article here.
-----
โ If your Company / Project / Community wants to become a partner of Cyber Security News...
Please, do not hesitate to contact us by sending a direct message to @cybersecadmin
-----
@Cyber_Security_Channel
Millions of Kia Cars Were Vulnerable to Remote Hacking: Researchers
After registering on the Kia dealer website โ a link to it is sent via email to new users for registration purposes โ using the same request used when registering to the ownersโ portal, the researchers could generate an access token that allowed them to call the backend dealer APIs.
Cyber_Security_Channel
๐ 9๐ 2๐ 2โค 1
Thousands of US Congress Emails Exposed to Takeover
However, the share of US political email addresses exposed on the dark web (20%) pales in comparison to that of British MPs (68%) and members of the European Parliament (44%), which the researchers discovered in an earlier iteration of the study.
Cyber_Security_Channel
๐ 5๐ 4๐คก 3โค 2๐ค 1๐คฉ 1๐คฃ 1
Severe Unauthenticated RCE Flaw (CVSS 9.9) in GNU/Linux Systems Awaiting Full Disclosure
Interestingly, there has been a delay in assigning Common Vulnerabilities and Exposures (CVE) identifiers to this issue.
Margaritelli suggests that there should be at least three CVEs assigned, possibly up to six, due to the multifaceted nature of the vulnerabilities involved.
Cyber_Security_Channel
๐ 14๐ฅ 8โค 2
Google Now Syncing Passkeys Across Desktop, Android Devices
To ensure that passkeys are kept end-to-end encrypted and protected, the internet giant has introduced a new Google Password Manager PIN, that the user will be prompted to provide when attempting to access a passkey.
Cyber_Security_Channel
๐ 12๐ฅ 6๐ 3โค 2
How Hackers Are Using Legitimate Tools to Distribute Phishing Links
These platforms are particularly popular in the education sector, a growing target for threat actors, as well as being commonly used by businesses and creative professionals.
Cyber_Security_Channel
๐ 11โค 2
Where Are Governments in Their Zero-Trust Journey?
The deadline is prompting action.
With a goal in sight, federal agencies have a systematic and organized path toward stronger defenses.
In an era where cyber threats advance in sophistication and intensity, this proactive stance is paramount for securing critical systems and data.
This is something state and local governments must consider when fortifying for the future.
Cyber_Security_Channel
๐ 15โค 3๐ฅ 1
Google AI Model Faces EU Data Privacy Investigation
Irelandโs Data Protection Commission (DPC) is examining whether the tech giant performed a legally required data protection impact assessment.
The organization is examining whether this action was done before processing European Union residentsโ personal data.
Such details were used in its Pathways Language Model 2, according to a press release which was published on Thursday 12th of September.
A Google spokesman provided this statement:
โWe take seriously our obligations under the GDPR and will work constructively with the DPC to answer their questions.โ
@Cyber_Security_Channel
๐ 9โค 8๐ฅ 3๐ 2๐ 2
TfL Admits Some Services Are Down Following Cyber-Attack
โDue to the ongoing TfL-wide cybersecurity incident, we are currently able to process only a limited number of booking requests,โ the notice read.
โIn addition, many of our staff have limited access to systems and email and, as a result, we may be delayed or unable to respond to your query.โ
Cyber_Security_Channel
๐ 8๐คก 4โค 2๐ฅ 2๐ 2๐ค 2๐ 1
Photo unavailableShow in Telegram
๐ค Opportunity to Support the Cyber Security News Community
If you are looking to create a free Revolut account:
1. Do it via this link.
2. Follow the steps in the image.
Once you complete all the requirements, message us on Telegram @cybersecadmin.
To express our graditude, we will send you a unique cybersecurity-related gift.
Enjoy your Revolut account, and thank you for the support!
-----
@Cyber_Security_Channel
๐ 15๐ฅ 7โค 5๐ 2๐ 1
UK Staffing Agency Exposes Gig Workers: Passports, Visas, and More Made Public
On August 5th, during a routine investigation, our research team discovered a misconfigured Amazon AWS S3 bucket, which they managed to attribute to GigtoGig.
Unfortunately, the database, which contained 217,000 sensitive files, was exposed to the public, meaning that anyone could access it without having to enter a username and password.
Cyber_Security_Channel
๐ 14โค 8๐ 3๐ 2๐ 1๐ฅ 1๐ 1๐ซก 1
7 Password Rules to Live by in 2024, According to Security Experts
For a simpler, more practical collection of guidelines, try the Secure Our World website, run by the Cybersecurity & Infrastructure Security Agency (CISA).
It's targeted at an audience of consumers without a technical background, which makes it a solid source of information you can share with friends and family to help them deal with common threats.
Cyber_Security_Channel
๐ 29โค 8๐ 6๐ฅ 4๐ 3๐ฑ 3
Africa Data Protection Association Launches E-Learning Platform on Data Protection
Available in French and English, the platform is aimed at a wide audience, including corporate executives, civil servants, and students, as well as any other profile wishing to learn.
It features interactive modules, case studies and online assessments, enabling learners to progress at their own pace.
Cyber_Security_Channel
๐ 22๐ 6โค 3๐ 3๐ค 3๐ 3๐ฅ 2๐คก 2
Repost from N/a
Prizes of the draw5 Telegram Premium subscriptions for 3 months
Completion date
All channel subscribers (2):

N/a
1
~0
0.00%
54.7k
~5.2k
9.55%
๐ 31๐ซก 8๐ฅ 6
Apple, TikTok, Google, and Facebook Give Your Data to Law Enforcement Up to 80% of the Time
Google also disclosed โsomeโ information to law enforcement when asked. In May 2023, 81% of requests made by law enforcement resulted in the disclosure of โsome information.โ
Big tech companies often donโt disclose what information was shared and tend to just say that โsomeโ of the information was shared with law enforcement.
Cyber_Security_Channel
๐ 17๐คฌ 5๐คฎ 3โค 1๐ฅ 1
A Third of Organizations Suffer SaaS Data Breaches
Responding organizations said they worry most about lost IP (34%), reputational damage (30%) and breaches of customer data (27%).
Just 32% are confident in the security of corporate or customer data stored in their SaaS apps, down from 42% last year.
Cyber_Security_Channel
๐ฅ 6๐ 5โค 4๐ฑ 1
After Cybersecurity Lab Wouldnโt Use AV Software, US Accuses Georgia Tech of Fraud
One of the rules says that machines storing or accessing such "controlled unclassified information" need to have endpoint antivirus software installed.
But according to the US government, Antonakakis really, really doesn't like putting AV detection software on his lab's machines.
Cyber_Security_Channel
๐ 12โค 9๐ค 3
NSA Issues Tips for Better Logging, Threat Detection in LotL Incidents
The guidelines are directed toward senior IT "decision makers," operational technology operators, and network administrator and operators, and focus on:
โ Secure storage and log integrity
โ Enterprise-approved logging policy
โ Detection strategy for relevant threats
โ Centralized log access and correlation
Cyber_Security_Channel
โค 10๐ฅ 5
