๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โŒ Working from Home: COVID-19โ€™s Constellation of Security Challenges โŒ

Organizations are sending employees and students home to work and learn -- but implementing the plan opens the door to more attacks, IT headaches and brand-new security challenges.

๐Ÿ“– Read

via "Threatpost".
๐Ÿ•ด DDoS Attack Trends Reveal Stronger Shift to IoT, Mobile ๐Ÿ•ด

Attackers are capitalizing on the rise of misconfigured Internet-connected devices running the WS-Discovery protocol, and mobile carriers are hosting distributed denial-of-service weapons.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ” How hospital CIOs can prepare for the onslaught of coronavirus patients ๐Ÿ”

There are steps that IT departments can take to strengthen their technical infrastructure in advance of COVID-19's arrival at their facility.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ›  AIEngine 1.9.2 ๐Ÿ› 

AIEngine is a packet inspection engine with capabilities of learning without any human intervention. It helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.

๐Ÿ“– Go!

via "Security Tool Files โ‰ˆ Packet Storm".
โš  Monday review โ€“ the hot 23 stories of the week โš 

Amazon and eBay shopper data was exposed, and the EARN IT act threatens end-to-end encryption. These stories and more in the weekly roundup.

๐Ÿ“– Read

via "Naked Security".
โš  Senate bill would ban TikTok from government phones โš 

Concerns over cybersecurity risk and possible spying by China have already brought about bans from DHS, DoD, TSA, and the State Department.

๐Ÿ“– Read

via "Naked Security".
โš  Open source bugs have soared in the past year โš 

Open source bugs have skyrocketed, according to a report from WhiteSource, with XSS flaws account for a quarter of those bugs.

๐Ÿ“– Read

via "Naked Security".
โš  Report calls for web pre-screening to end UKโ€™s child abuse โ€˜explosionโ€™ โš 

The IICSA report cited "unprecedented levels of depravity" and said that encryption is getting in the way of current screening.

๐Ÿ“– Read

via "Naked Security".
โš  Microsoft patches wormable Windows 10 โ€˜SMBGhostโ€™ flaw โš 

Whatโ€™s the difference between a scheduled security update and one thatโ€™s out-of-band? In this case, it's two days.

๐Ÿ“– Read

via "Naked Security".
๐Ÿ•ด 4 Ways Thinking 'Childishly' Can Empower Security Professionals ๐Ÿ•ด

Younger minds -- more agile and less worried by failure -- provide a useful model for cyber defenders to think more creatively.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ” Report: US Health and Human Services department hit by cyberattack amidst coronavirus fears ๐Ÿ”

The Sunday cybersecurity attack was designed to slow down the agency's systems as it tries to grapple with the spread of COVID-19.

๐Ÿ“– Read

via "Security on TechRepublic".
ATENTIONโ€ผ New - CVE-2019-10091

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2018-13063

Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2018-13060

Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2018-10125

Contao before 4.5.7 has XSS in the system log.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Fewer Vulnerabilities in Web Frameworks, but Exploits Remain Steady ๐Ÿ•ด

Attackers continue to focus on web and application frameworks, such as Apache Struts and WordPress, fighting against a decline in vulnerabilities, according to an analysis.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ•ด Hellman & Friedman Acquires Checkmarx for $1.5B ๐Ÿ•ด

The private equity firm will buy Checkmarx from Insight Partners, which will continue to own a minority interest.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ” How to enable 2FA on a per-user basis in Nextcloud ๐Ÿ”

If you want to enable two-factor authentication for Nextcloud on a per-user basis, it's just a simple app installation away.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ” How to enable 2FA on a per-user basis in Nextcloud ๐Ÿ”

If you want to enable two-factor authentication for Nextcloud on a per-user basis, it's just a simple app installation away.

๐Ÿ“– Read

via "Security on TechRepublic".
โŒ Microsoft Edge Shares Privacy-Busting Telemetry, Research Alleges โŒ

An academic study found Microsoft's Edge browser to be the least private, due to it sending device identifiers and web browsing pages to back-end servers.

๐Ÿ“– Read

via "Threatpost".