πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Defying Covid-19’s Pall: Pwn2Own Goes Virtual ❌

Hacking contest goes virtual with participants remotely winning $295k in prizes for taking down Adobe Reader, Safari and Ubuntu.

πŸ“– Read

via "Threatpost".
❌ Revamped HawkEye Keylogger Swoops in on Coronavirus Fears ❌

Emails claiming to be directly from WHO’s Dr. Tedros Adhanom Ghebreyesus offer "drug advice" -- and malware infections.

πŸ“– Read

via "Threatpost".
πŸ•΄ 200M Records of US Citizens Leaked in Unprotected Database πŸ•΄

Researchers have not determined who owns the database, which was one of several large exposed instances disclosed this week.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-11574

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7487

On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to Ò€œsystemҀ�, which allows remote attackers to execute arbitrary code via TCP port 9000.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  GNU Privacy Guard 2.2.20 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
⚠ Monday review – the hot 23 stories of the week ⚠

From the EARN IT Act to the Martinelli hoax - and everything in between. It’s your weekly security roundup.

πŸ“– Read

via "Naked Security".
⚠ Firefox is dropping FTP support ⚠

Heads up, Firefox users who rely on FTP: the browser is eliminating support for this venerable protocol.

πŸ“– Read

via "Naked Security".
⚠ Stolen data of company that refused REvil ransom payment now on sale ⚠

A comment from one buyer of data purportedly from Brooks International: "It even has credit card number & a password. lol !!"

πŸ“– Read

via "Naked Security".
⚠ Tour guide/Chinese spy gets four years for SD card dead drops ⚠

The dead drops were very James Bond: once, the data mule taped the SD card to the underside of a desk in a hotel.

πŸ“– Read

via "Naked Security".
⚠ Cisco issues urgent fixes for SD-WAN router flaws ⚠

Cisco has patched a clutch of high-priority vulnerabilities in its SD-WAN routes and their management software.

πŸ“– Read

via "Naked Security".
πŸ•΄ From Zero to Hero: CISO Edition πŸ•΄

It's time for organizations to realize that an empowered CISO can effectively manage enterprise risk and even grow the business along the way.

πŸ“– Read

via "Dark Reading: ".
πŸ” 3 ways to revamp the hiring process for cybersecurity jobs πŸ”

Deloitte expert recommends using tactics to compete for the pool of security pros, including offering new incentives like student loan repayment.

πŸ“– Read

via "Security on TechRepublic".
❌ Fake Coronavirus β€˜Vaccine’ Website Busted in DoJ Takedown ❌

Authorities have cracked down on a website that claimed to give out coronavirus vaccine kits - but that was actually stealing victims' payment card data and personal information.

πŸ“– Read

via "Threatpost".
πŸ•΄ 8 Infosec Page-Turners for Days Spent Indoors πŸ•΄

Stuck inside and looking for a new read? Check out these titles written by security practitioners and reporters across the industry.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-11022

NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Cybercriminals now recycling standard phishing emails with coronavirus themes πŸ”

The latest malicious COVID-19 campaigns are repurposing conventional phishing emails with a coronavirus angle, says security trainer KnowBe4.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ FBI Warns of Fake CDC Emails in COVID-19 Phishing Alert πŸ•΄

Fraudsters exploit concerns by claiming to offer virus-related information or promising stimulus checks.

πŸ“– Read

via "Dark Reading: ".
⚠ WhatsApp β€œMartinelli” hoax is back, warning about β€œDance of the Pope” ⚠

Two old WhatsApp hoaxes are back, with a grain-of-truth story in the middle to add a veneer of believability. Don't spread this stuff!

πŸ“– Read

via "Naked Security".
πŸ›  Hyperion Runtime Encrypter 2.3 πŸ› 

Hyperion is a runtime encrypter for 32-bit and 64-bit portable executables. It is a reference implementation and bases on the paper "Hyperion: Implementation of a PE-Crypter".

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".