πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ $100K Paid Out for Google Cloud Shell Root Compromise ❌

A Dutch researcher claimed Google's very first annual Cloud Platform bug-bounty prize, for a clever container escape exploit.

πŸ“– Read

via "Threatpost".
⚠ Firefox 74 offers privacy and security updates ⚠

A month after shipping version 73 of its Firefox browser, Mozilla has released version 74 with a range of privacy and security enhancements.

πŸ“– Read

via "Naked Security".
⚠ Data of millions of eBay and Amazon shoppers exposed ⚠

Eight million customer records belonging to companies including Amazon, eBay, Shopify, PayPal, and Stripe were collected.

πŸ“– Read

via "Naked Security".
πŸ” Cybercriminals raking in $1.5 trillion every year πŸ”

Research from Atlas VPN found that criminals' net proceeds outpace the revenue made by tech giants each year.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Patches Leaked Remote Code Execution Flaw πŸ•΄

A vulnerability in Microsoft's Server Message Block protocol prompted concerns of wormable exploits when it was disclosed this week.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Working from Home? These Tips Can Help You Adapt πŸ•΄

COVID-19 means many people are doing their jobs from outside the confines of the office. That may not be as easy as it sounds.

πŸ“– Read

via "Dark Reading: ".
πŸ” Microsoft Patches SMBv3 Bug πŸ”

Microsoft issued an out-of-band security update for a critical SMB bug (CVE-2020-0796) on Thursday.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Nearly 300 cybersecurity incidents impacted supply chain entities in 2019 πŸ”

A study from Resilience360 listed cyberthreats as one of the biggest issues facing global supply chains in 2020.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ CASB 101: Why a Cloud Access Security Broker Matters πŸ•΄

A CASB isn't a WAF, isn't an NGF, and isn't an SWG. So what is it, precisely, and why do you need one to go along with all the other letters? Read on for the answer.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New Android Malware Strain Sneaks Cookies from Facebook πŸ•΄

Two malware modifications, when combined, can snatch cookies collected by browsers and social networking apps.

πŸ“– Read

via "Dark Reading: ".
❌ Trojan Raids Android Users’ Cookie Jars ❌

Cookiethief steals cookies to infiltrate Facebook and other web service accounts.

πŸ“– Read

via "Threatpost".
❌ Researchers Warn of Novel PXJ Ransomware Strain ❌

While PXJ performs typical ransomware functions, it does not appear to share the same underlying code with most known ransomware families.

πŸ“– Read

via "Threatpost".
πŸ” Facebook cookie-stealing trojans surface on Android devices πŸ”

The trojans are designed to gain control of Facebook user accounts by capturing browser cookies in Android, says Kaspersky.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ New Report Shows Breach Costs Continuing to Grow πŸ•΄

The costs associated with data breaches climb alongside the amount of data managed by the enterprise according to the latest Global Protection Index Snapshot.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Russia-Based Turla APT Group's Infrastructure, Activity Traceable πŸ•΄

Threat actor's practice of using known malware and tactics gives an opening for defenders, says Recorded Future.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-20586

bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-19516

messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-10704

yidashi yii2cmf 2.0 has XSS via the /search q parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18350

bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-3641

bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.

πŸ“– Read

via "National Vulnerability Database".
⚠ Confessions app Whisper spills almost a billion records ⚠

Researchers say the exposure includes exact locations of users' last posts, nicknames, age, and gender.

πŸ“– Read

via "Naked Security".