πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-11025

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).

πŸ“– Read

via "National Vulnerability Database".
πŸ” Experts question abrupt decision by New York City to ban Zoom from use in all public schools πŸ”

The hotly debated move does little to address underlying issues many teachers and parents are having with the platform and other tools, educators say.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The Coronavirus & Cybersecurity: 3 Areas of Exploitation πŸ•΄

Criminal, political, and strategic factors are combining to create a perfect storm of cyber infections that target the global supply chain.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-18647

An issue was discovered on Samsung mobile devices with M(6,x) and N(7.0) software. The TA Scrypto v1.0 implementation in Secure Driver has a race condition with a resultant buffer overflow. The Samsung IDs are SVE-2017-8973, SVE-2017-8974, and SVE-2017-8975 (November 2017).

πŸ“– Read

via "National Vulnerability Database".
πŸ” NYDFS Postpones Cybersecurity Certification of Compliance Deadline πŸ”

The New York Department of Financial Services has extended its usual April 15 cybersecurity Certification of Compliance deadline for entities experiencing issues arising from COVID-19

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Mature DevOps Teams Are Secure DevOps Teams πŸ•΄

New research shows the relationship between mature DevOps processes, secure applications, and happy developers.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How Do I Make Sure My Work-From-Home Users Install Updates? πŸ•΄

Most enterprise endpoint solutions will support policies to enforce recommended updates.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9545

An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9544

An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7488

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

πŸ“– Read

via "National Vulnerability Database".
❌ Serious Exchange Flaw Still Plagues 350K Servers ❌

The Microsoft Exchange vulnerability was patched in February and has been targeted by several threat groups.

πŸ“– Read

via "Threatpost".
πŸ•΄ The Edge Names 'Holy Cow' Cartoon Caption Winners πŸ•΄

What can cows possibly have to do with cybersecurity?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cybercriminals Hide Malware & Phishing Sites Under SSL Certificates πŸ•΄

More than half of the top 1 million websites use HTTPS, researchers report, but not all encrypted traffic is safe.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Chinese APT Groups Targeted Enterprise Linux Systems in Decade-Long Data Theft Campaign πŸ•΄

Organizations across multiple industries compromised in a systematic effort to steal IP and other sensitive business data, BlackBerry says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Privacy & Digital-Rights Experts Worry Contact-Tracing Apps Lack Limits πŸ•΄

Mobile-phone-based tracking of people can help fight pandemics, but privacy and security researchers stress that it needs to be done right.

πŸ“– Read

via "Dark Reading: ".
⚠ As if the world couldn’t get any weirder, this AI toilet scans your anus to identify you ⚠

It's what the researchers call "A mountable toilet system for personalized health monitoring via the analysis of excreta."

πŸ“– Read

via "Naked Security".
⚠ Microsoft project proposed to aid Linux IoT code integrity ⚠

Imagine a computer user from 2010 dreaming of a world in which Microsoft is not only an enthusiastic proponent of open source software but actively contributes to it with its own ideas. The time is now.

πŸ“– Read

via "Naked Security".
⚠ Update Firefox again – more RCEs and an Android β€œtakeover” bug too ⚠

Hot on the heels of Firefox's emergency update over the weekend are the four-weekly fixes that Mozilla had in train already. Get 'em now!

πŸ“– Read

via "Naked Security".
❌ COVID-19 CISO Checklist for Securing a Remote Workforce ❌

The CISO Checklist for Secure Remote Working was built to assist CISOs in navigating through COVID-19, providing them with a concise, high-level list of the absolute essentials needed to ensure their organization is well protected in these challenging times.

πŸ“– Read

via "Threatpost".
❌ β€˜Fake Fingerprints’ Bypass Scanners with 3D Printing ❌

New research used 3D printing technology to bypass fingerprint scanners, and tested it against Apple, Samsung and Microsoft mobile products.

πŸ“– Read

via "Threatpost".
πŸ” Talos researchers fabricate a fake that frequently fooled fingerprint locks πŸ”

The 3D printed duplicates worked on phone and a MacBook Pro laptop but not on Windows machines or two USB jump drives.

πŸ“– Read

via "Security on TechRepublic".