πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-17028

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-17027

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Elastic Security Makes Case For Blending 'Human Element,' Election Security πŸ•΄

Nate Fick, general manager of Elastic and former CEO of Endgame, talks about the impact of AI and machine learning on security professionals, and how what technologies can be tapped to improve security in the runup to November's election.

πŸ“– Read

via "Dark Reading: ".
πŸ” RSA: What it's like to attend the first tech conference after the coronavirus epidemic πŸ”

San Francisco is the site of the RSA 2020 conference, which took place despite cancellations from IBM, Verizon and AT&T.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Sophos Boosts Threat Hunting, Managed Detection and Response Capabilities πŸ•΄

JJ Thompson, senior director of managed threat response for Sophos digs deep into how organizations can start to make sense of the seemingly unlimited data that's available from endpoints, cloud, and on-premises networks. And that's a critical capability as attacker behaviors start to change.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US State Dept. Shares Insider Tips to Fight Insider Threats πŸ•΄

The insider threat is a technology, security, and personnel issue, officials said in explaining an approach that addresses all three factors.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How Should I Answer a Nontech Exec Who Asks, 'How Secure Are We?' πŸ•΄

Consider this your opportunity to educate.

πŸ“– Read

via "Dark Reading: ".
❌ RSAC 2020: Lack of Machine Learning Laws Open Doors To Attacks ❌

When it comes to machine learning, research and cybercriminal activity is full speed ahead - but legal policy has not yet caught up.

πŸ“– Read

via "Threatpost".
πŸ•΄ Tufin: How to Make Better Sense of the Cloud Security Equation πŸ•΄

CEO Reuven Harrison examines how cloud services have changed how enterprises manage their apps and data, and also offers some tips for security pros tasked with managing either hybrid- or multi-cloud implementations. Harrison also takes on Kubernetes and container security in this News Desk interview.

πŸ“– Read

via "Dark Reading: ".
πŸ” Digital Guardian Wins Best Data Loss Prevention (DLP) Solution at SC Awards 2020! πŸ”

We're thrilled to share that Digital Guardian won the Best Data Loss Prevention (DLP) Solution at the 2020 SC Trust Awards at RSA Conference!

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ RSAC 2020: Smart Baby Monitor Vulnerable to Remote Hackers ❌

A popular baby monitor has been found riddled with vulnerabilities that give attackers full access to personal information and sensitive video footage.

πŸ“– Read

via "Threatpost".
❌ Billions of Devices Open to Wi-Fi Eavesdropping Attacks ❌

The Kr00k bug arises from an all-zero encryption key in Wi-Fi chips that reveals communications from devices from Amazon, Apple, Google, Samsung and others.

πŸ“– Read

via "Threatpost".
πŸ•΄ 'Cloud Snooper' Attack Circumvents AWS Firewall Controls πŸ•΄

Possible nation-state supply chain attack acts like a "wolf in sheep's clothing," Sophos says.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-12882

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-19668

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-17963. Reason: This candidate is a reservation duplicate of CVE-2018-17963. Notes: All CVE users should reference CVE-2018-17963 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6371

Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6363

** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'"

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-5861

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000020. Reason: This candidate is a reservation duplicate of CVE-2017-1000020. Notes: All CVE users should reference CVE-2017-1000020 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-5686

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

πŸ“– Read

via "National Vulnerability Database".
⚠ Facebook bans coronavirus β€˜miracle cure’ ads ⚠

Facebook, like other platforms, has seen fake news, mass-buying of face masks, and misinformation about bleach being a cure for COVID-19.

πŸ“– Read

via "Naked Security".
πŸ” Why city and state governments may be unprepared for ransomware attacks πŸ”

Despite the rise in ransomware, a lack of prevention training and stagnant security budgets are putting local governments at risk, according to IBM Security.

πŸ“– Read

via "Security on TechRepublic".