πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ What Should I Do About Vulnerabilities Without Fixes? πŸ•΄

With better tools that identify potential threats even before developers address them, a new problem has arisen.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-10992

In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.

πŸ“– Read

via "National Vulnerability Database".
πŸ” HHS Finalizes New Health Data Rules To Improve Data Governance πŸ”

The U.S. Department of Health and Human Services finalized two new rules designed to give patients better control over their data.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Paradise Ransomware Variant Hides in Office IQY Files πŸ•΄

The uncommon Internet Query file format lets attacks slip past defenses to effectively break into target networks.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 3 Tips to Stay Secure When You Lose an Employee πŸ•΄

Whether they leave for a better job or get fired, and whether they mean to cause problems or do so out of ignorance, ex-workers can pose a threat to your company.

πŸ“– Read

via "Dark Reading: ".
❌ High-Severity Flaws Plague Intel Graphics Drivers ❌

Intel patched six high-severity flaws in its graphics drivers, as well as other vulnerabilities in its NUC firmware, and a load value injection vulnerability that could allow attackers to steal sensitive data.

πŸ“– Read

via "Threatpost".
❌ Firefox Bug Opens iPhone AirPods to Third-Party Snooping ❌

Mozilla Foundation snuffs out bugs with the introduction of Firefox 74 and ESR 68.6.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2012-1096

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1094

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Bitsight and Microsoft Disrupt Necurs Botnet πŸ•΄

But roughly 2 million infected systems remain in the wild, and infected systems could be reactivated at any time.

πŸ“– Read

via "Dark Reading: ".
❌ Popular ThemeREX WordPress Plugin Opens Websites to RCE ❌

The bug has been under active attack as a zero-day.

πŸ“– Read

via "Threatpost".
πŸ•΄ Researchers Develop New Side-Channel Attacks on Intel CPUs πŸ•΄

Load Value Injection (LVI) takes advantage of speculative execution processes just like Meltdown and Spectre, say security researchers from Bitdefender and several universities.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Zeek 3.1.1 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
❌ Microsoft Patches 26 Critical Bugs in Big March Update ❌

March security updates include 115 CVEs patching everything from Windows, Office and Microsoft’s new Chromium-based Edge web browser.

πŸ“– Read

via "Threatpost".
❌ Critical Bugs in Rockwell, Johnson Controls ICS Gear ❌

Bugs affecting programmable logic controllers (PLC) and physical access-control systems for facilities are rated 9.8 in severity.

πŸ“– Read

via "Threatpost".
πŸ” Two attendees at RSA tech conference in San Francisco stricken with COVID-19 πŸ”

The organizers of the popular security conference, RSA, which drew over 36,000 people to San Francisco in February, confirmed that at least two people who attended have tested positive for COVID-19.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Closing the cybersecurity gender gap would boost the US economy by $30B πŸ”

82% of women in cybersecurity jobs agree the industry has a gender bias problem. Fixing it would not only improve morale and confidence, but also result in an economic boost to the cybersecurity industry.

πŸ“– Read

via "Security on TechRepublic".
⚠ Brave browser to block web fingerprinting with randomisation ⚠

Brave is testing a new defence against fingerprinting: confusing algorithms by randomising some of the data they collect.

πŸ“– Read

via "Naked Security".
⚠ Trial for accused CIA leaker ends in hung jury ⚠

The US is expected to press for a retrial in the high-stakes trial of Joshua Schulte, suspected of raiding the CIA's cyber arsenal.

πŸ“– Read

via "Naked Security".
⚠ FBI arrests alleged owner of Deer.io, top market for stolen accounts ⚠

Started around 2013, the site claims to host over 24,000 active shops doing brisk business in stolen PII and hacking services.

πŸ“– Read

via "Naked Security".