πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-21037

Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18576

The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ This Tax Season, Save the Scorn and Protect Customers from Phishing Scams πŸ•΄

As security professionals, it's easy to get cynical about the continued proliferation of tax ID theft and blame the consumers themselves. But that doesn't help anyone.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Security Lessons We've Learned (So Far) from COVID-19 πŸ•΄

Takeaways about fighting new fires, securely enabling remote workforces, and human nature during difficult times.

πŸ“– Read

via "Dark Reading: ".
πŸ” Canadian Govt Prioritizing Rules Around Insider Threats πŸ”

Following a high profile espionage case, Canada is set to roll out a new set of protocols designed to stop insider threats within government departments.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Startup Offering Secure Access to Corporate Apps Emerges from Stealth πŸ•΄

Axis Security has raised $17 million in VC funding.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Attorney General Directs DoJ to Prioritize Coronavirus Crime πŸ•΄

Criminal activity related to the pandemic cannot be tolerated, William Barr states in memo.

πŸ“– Read

via "Dark Reading: ".
❌ This Stalkerware Delivers Extra-Creepy Features ❌

Stalkerware called Monitor Minor gives users the ability to creep on a target’s missives swapped via Instagram, Skype and Snapchat.

πŸ“– Read

via "Threatpost".
❌ A COVID-19 Cybersecurity Poll: Securing a Remote Workforce ❌

COVID-19 is changing how we work. Weigh in on how your organization is securing its remote footprint with our short Threatpost poll.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-11939

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

πŸ“– Read

via "National Vulnerability Database".
❌ Magecart Cyberattack Targets NutriBullet Website ❌

Researchers warn that a Magecart group has set up skimmers on the blender manufacturer's website, in hopes of stealing customer payment-card data.

πŸ“– Read

via "Threatpost".
⚠ Human traffickers use social media oversharing to gain victims’ trust ⚠

Posts about money or family trouble are being used to gain trust by those who force victims into sex work or slavery, the FBI warns.

πŸ“– Read

via "Naked Security".
⚠ DDoS attack on US Health agency part of coordinated campaign ⚠

It coincided with a disinformation campaign carried out via SMS, email and social media claiming that national quarantine was imminent.

πŸ“– Read

via "Naked Security".
⚠ Uber to file federal suit against LA over users’ real-time location data ⚠

Real-time, in-trip geolocation data isn't good for traffic/bike lane planning, a draft of the suit says. What it's good for is surveillance.

πŸ“– Read

via "Naked Security".
⚠ VMware patches virtualisation bugs ⚠

Virtualisation company VMware patched two bugs this week that affected a large proportion of its client-side virtual machines.

πŸ“– Read

via "Naked Security".
❌ Authorities Eye Using Mobile Phone Tracking COVID-19’s Spread ❌

Privacy advocates advise caution when tracking the movements of patients or those infected with the new coronavirus, as an effort to minimize the pandemic’s effect.

πŸ“– Read

via "Threatpost".
❌ Adobe Discloses Dozens of Critical Photoshop, Acrobat Reader Flaws ❌

An out-of-band Adobe security update addressed critical flaws in Photoshop, Acrobat Reader and other products.

πŸ“– Read

via "Threatpost".
πŸ•΄ What the Battle of Britain Can Teach Us About Cybersecurity's Human Element πŸ•΄

During WWII, the British leveraged both technology and human intelligence to help win the war. Security leaders must learn the lessons of history and consider how the human element can make their machine-based systems more effective.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to protect yourself from coronavirus-themed malware πŸ”

Attackers are using phishing emails, ransomware, and malicious apps to target people curious about the virus, says security firm Cybereason.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to control what personal information people see in Android πŸ”

Do you know what information you share within the Google ecosystem? You can easily control what is visible or hidden, from with your Android device. Find out how.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Trend Micro Patches Two Zero-Days Under Attack πŸ•΄

Businesses are urged to update the Apex One and OfficeScan XG enterprise security products as soon as possible.

πŸ“– Read

via "Dark Reading: ".