πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ New Ransomware Variant Developed Entirely as Shellcode πŸ•΄

PwndLocker is harder to detect than other crypto-malware, Crypsis Group says.

πŸ“– Read

via "Dark Reading: ".
⚠ IWD: biometrics, machine learning, privacy and being a woman in tech – Naked Security Podcast ⚠

To celebrate International Women's Day we invite you to this all-female splinter episode.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2016-11021

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 29 stories of the week ⚠

From an ultrasonic attack on Siri and Google Assistant to the guy who hacked back at tech support scammers - and everything in between.

πŸ“– Read

via "Naked Security".
⚠ 99% of compromised Microsoft enterprise accounts lack MFA ⚠

Cybercriminals compromise over a million Microsoft enterprise accounts each month as too few customers use multi-factor authentication.

πŸ“– Read

via "Naked Security".
⚠ Now you need a notarized document to get a .gov domain ⚠

The US government is tightening its rules around the registration of government web domains to stop fraudsters impersonating government sites.

πŸ“– Read

via "Naked Security".
⚠ Microsoft: Turn off Memory Integrity if it’s causing problems ⚠

Microsoft has finally clarified how users can fix a Windows security measure that has been causing hardware problems: turn it off.

πŸ“– Read

via "Naked Security".
πŸ” How to install and use the NordPass password manager on Linux πŸ”

The makers of NordVPN have come out with a new version of their NordPass password manager. Find out how to install and use it.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Threat Awareness: A Critical First Step in Detecting Adversaries πŸ•΄

One thing seems certain: Attackers are only getting more devious and lethal. Expect to see more advanced attacks.

πŸ“– Read

via "Dark Reading: ".
⚠ One billion Android smartphones racking up security flaws ⚠

How long do Android devices continue to receive security updates after they’re purchased? The answer is: barely two years.

πŸ“– Read

via "Naked Security".
πŸ” Cyberattackers are delivering malware by using links from whitelisted sites πŸ”

Legitimate-looking links from OneDrive, Google Drive, iCloud, and Dropbox slip by standard security measures.

πŸ“– Read

via "Security on TechRepublic".
❌ AMD Downplays CPU Threat Opening Chips to Data Leak Attacks ❌

New side-channel attacks have been disclosed in AMD CPUs, however AMD said that they are not new.

πŸ“– Read

via "Threatpost".
πŸ•΄ WatchGuard Buys Panda Security for Endpoint Security Tech πŸ•΄

In the long term, Panda Security's technologies will be integrated into the WatchGuard platform.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-7968

nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7344

HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7343

JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Malware Campaign Feeds on Coronavirus Fears πŸ•΄

A new malware campaign that offers a "coronavirus map" delivers a well-known data-stealer.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Richsploit RichFaces Exploitation Toolkit πŸ› 

This tool can be used to exploit vulnerable versions of RichFaces. It has payloads for 4 vulnerabilities that have been identified, which can lead to remote code execution via java deserialization and EL injection.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
❌ Microsoft Exchange Server Flaw Exploited in APT Attacks ❌

A vulnerability is Microsoft Exchange servers is being actively exploited by multiple APT groups, researchers warn.

πŸ“– Read

via "Threatpost".
⚠ It’s not a breach… it’s just that someone else has your data ⚠

If you lose someone's data because of a configuration blunder that lets crooks in without any actual hacking... is that a "breach" or not?

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2016-6918

Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (

πŸ“– Read

via "National Vulnerability Database".