πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Google sent ~40K warnings to targets of state-backed attackers in 2019 ⚠

Google has seen a rising number of attackers impersonating news outlets and journalists to spread fake news among other reporters.

πŸ“– Read

via "Naked Security".
⚠ Should governments track your location to fight COVID-19? ⚠

Google Maps data could help governments track patients that a newly-diagnosed COVID-19 sufferer has been in contact with.

πŸ“– Read

via "Naked Security".
⚠ Chrome may bring back β€˜www’ with option to show full URLs ⚠

Google's doing so grudgingly: it still thinks that showing too much will confuse users trying to assess a site's security.

πŸ“– Read

via "Naked Security".
⚠ Apple’s iOS 13.4 hit by VPN bypass vulnerability ⚠

It’s less than a week since iOS 13.4 appeared and already researchers have discovered a bug that puts at risk the privacy of VPN connections.

πŸ“– Read

via "Naked Security".
πŸ•΄ Securing Your Remote Workforce: A Coronavirus Guide for Businesses πŸ•΄

Often the hardest part in creating an effective awareness program is deciding what NOT to teach.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10560

An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.

πŸ“– Read

via "National Vulnerability Database".
⚠ How to stay on top of coronavirus scams – and all the others too ⚠

The bad news is that you have to watch out for a plethora of new coronavirus cyberscams, as well as all the old stuff, too...

πŸ“– Read

via "Naked Security".
πŸ›  Recon Informer πŸ› 

Recon-Informer is a basic real-time anti-reconnaissance detection tool for offensive security systems, useful for penetration testers. It runs on Windows/Linux and leverages scapy.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ” How to protect your organization and remote workers against ransomware πŸ”

Phishing emails and unsecure remote desktop protocol access are two common types of attack methods used to spread ransomware, says cyber breach firm Beazley Breach Response Services.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to use an iPhone or Android device as the security key for your Google account πŸ”

Your smartphone can act as your security key to authenticate your Google credentials on the web. Learn how to set that up on an Android device or an iPhone.

πŸ“– Read

via "Security on TechRepublic".
❌ Zeus Sphinx Banking Trojan Arises Amid COVID-19 ❌

The malware is back after three years, looking to cash in on interest in government relief efforts around coronavirus.

πŸ“– Read

via "Threatpost".
πŸ” Top 5 remote access threats πŸ”

When working from home, it's important to understand the security risks. Tom Merritt lists five remote access threats so you can secure your system.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-7755

In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Top 5 remote access threats πŸ”

When working from home, it's important to understand the security risks. Tom Merritt lists five remote access threats so you can secure your system.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Security policies explain step-by-step solutions for strengthening IT defenses πŸ”

These TechRepublic Premium resources offer a comprehensive solution from responding to a data breach to explaining company-wide security responsibilities.

πŸ“– Read

via "Security on TechRepublic".
πŸ” The dark web: Where coronavirus fraud, profiteering, malware, and scams are discussed πŸ”

COVID-19 is fueling new dark web conversations about cybercriminal activity, says cyber intelligence company Sixgill.

πŸ“– Read

via "Security on TechRepublic".
❌ Zoom Kills iOS App’s Data-Sharing Facebook Feature ❌

Zoom removed its Facebook SDK for iOS feature after a report found the app sending Facebook "unnecessary" user data.

πŸ“– Read

via "Threatpost".
πŸ•΄ HackerOne Drops Mobile Voting App Vendor Voatz πŸ•΄

Bug bounty platform provider cited "Voatz's pattern of interactions with the research community" in its decision to halt the app vendor's vuln disclosure program on HackerOne.

πŸ“– Read

via "Dark Reading: ".
πŸ” Groups Seek to Bump CCPA Enforcement Date Amid Coronavirus Confusion πŸ”

As with many things currently, details of the California Consumer Privacy Act are unclear. That, plus confusion around COVID-19, has many interest groups hoping enforcement around the law is postponed.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2019-17561

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-17560

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. Ò€œApache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

πŸ“– Read

via "National Vulnerability Database".