πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-11022

NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Cybercriminals now recycling standard phishing emails with coronavirus themes πŸ”

The latest malicious COVID-19 campaigns are repurposing conventional phishing emails with a coronavirus angle, says security trainer KnowBe4.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ FBI Warns of Fake CDC Emails in COVID-19 Phishing Alert πŸ•΄

Fraudsters exploit concerns by claiming to offer virus-related information or promising stimulus checks.

πŸ“– Read

via "Dark Reading: ".
⚠ WhatsApp β€œMartinelli” hoax is back, warning about β€œDance of the Pope” ⚠

Two old WhatsApp hoaxes are back, with a grain-of-truth story in the middle to add a veneer of believability. Don't spread this stuff!

πŸ“– Read

via "Naked Security".
πŸ›  Hyperion Runtime Encrypter 2.3 πŸ› 

Hyperion is a runtime encrypter for 32-bit and 64-bit portable executables. It is a reference implementation and bases on the paper "Hyperion: Implementation of a PE-Crypter".

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  Mandos Encrypted File System Unattended Reboot Utility 1.8.10 πŸ› 

The Mandos system allows computers to have encrypted root file systems and at the same time be capable of remote or unattended reboots. The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key that is unique to each client. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ” How to protect your organization and remote workers against ransomware πŸ”

Phishing emails and unsecure remote desktop protocol access are two common types of attack methods used to spread ransomware, says cyber breach firm Beazley Breach Response Services.

πŸ“– Read

via "Security on TechRepublic".
❌ Microsoft Warns of Critical Windows Zero-Day Flaws ❌

The unpatched Windows zero day flaws are being exploited in "limited, targeted" attacks, according to Microsoft.

πŸ“– Read

via "Threatpost".
πŸ” Ex-Google Engineer Pleads Guilty to Trade Secret Theft πŸ”

Ex-Google engineer Anthony Levandowski plead guilty to trade secret theft last week, acknowleding he took a sensitive Google file before joining Uber.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Hackers Actively Exploit 0-Day in CCTV Camera Hardware ❌

Criminals behind botnets Chalubo, FBot and Moobot attack unpatched vulnerabilities in the commercial DVRs made by LILIN.

πŸ“– Read

via "Threatpost".
❌ Apache Tomcat Exploit Poised to Pounce, Stealing Files ❌

Researchers said that a working exploit for CVE-2020-1938 leaked on GitHub makes is a snap to compromise webservers.

πŸ“– Read

via "Threatpost".
πŸ•΄ 538 Million Weibo Users' Info for Sale on Dark Web πŸ•΄

The user data, which does not include passwords, purportedly comes from a mid-2019 breach.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Three Ways Your BEC Defense Is Failing & How to Do Better πŸ•΄

Business email compromises cost the economy billions of dollars. Experts have advice on how to stop them from hitting you for millions at a pop.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Publishes Advisory for Windows Zero-Day πŸ•΄

There is no available patch for the vulnerabilities, which Microsoft says exist in all supported versions of Windows.

πŸ“– Read

via "Dark Reading: ".
⚠ Feds shut down bogus COVID-19 vaccine site ⚠

A vaccine for $4.95!? Nah, we didn't think so, either. Shuttering the alleged rip-off site is the DOJ's 1st takedown of COVID-19 flimflam.

πŸ“– Read

via "Naked Security".
πŸ” Microsoft Defender for Linux is coming. This is what you need to know πŸ”

Microsoft's security tools extend beyond the company's own platforms. While the ambition for Defender for Linux is broad, the first preview is aimed just at servers and does less than on Windows.

πŸ“– Read

via "Security on TechRepublic".
⚠ Russia’s FSB wanted its own IoT botnet ⚠

If you thought the Mirai botnet was bad, what about a version under the control of Russia's military that it could point like an electronic cannon at people it didn't like?

πŸ“– Read

via "Naked Security".
⚠ Facebook Messenger may ban mass-forwarding of messages ⚠

Facebook has done this before: it did it with WhatsApp, following an outbreak of lynchings sparked by viral social media hoaxes.

πŸ“– Read

via "Naked Security".
❌ Tekya Malware Threatens Millions of Android Users via Google Play ❌

The ad-fraud malware lurks in dozens of childrens' and utilities apps.

πŸ“– Read

via "Threatpost".
❌ Domain Name Security: Important Measures You Need to Know ❌

A domain name that points to a website hosting your generated content is still one of the most secure means to ensure that an online identity does not fall prey to hackers or hijackers.

πŸ“– Read

via "Threatpost".