πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ How Do I Make Sure My Work-From-Home Users Install Updates? πŸ•΄

Most enterprise endpoint solutions will support policies to enforce recommended updates.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9545

An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9544

An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7488

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

πŸ“– Read

via "National Vulnerability Database".
❌ Serious Exchange Flaw Still Plagues 350K Servers ❌

The Microsoft Exchange vulnerability was patched in February and has been targeted by several threat groups.

πŸ“– Read

via "Threatpost".
πŸ•΄ The Edge Names 'Holy Cow' Cartoon Caption Winners πŸ•΄

What can cows possibly have to do with cybersecurity?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cybercriminals Hide Malware & Phishing Sites Under SSL Certificates πŸ•΄

More than half of the top 1 million websites use HTTPS, researchers report, but not all encrypted traffic is safe.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Chinese APT Groups Targeted Enterprise Linux Systems in Decade-Long Data Theft Campaign πŸ•΄

Organizations across multiple industries compromised in a systematic effort to steal IP and other sensitive business data, BlackBerry says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Privacy & Digital-Rights Experts Worry Contact-Tracing Apps Lack Limits πŸ•΄

Mobile-phone-based tracking of people can help fight pandemics, but privacy and security researchers stress that it needs to be done right.

πŸ“– Read

via "Dark Reading: ".
⚠ As if the world couldn’t get any weirder, this AI toilet scans your anus to identify you ⚠

It's what the researchers call "A mountable toilet system for personalized health monitoring via the analysis of excreta."

πŸ“– Read

via "Naked Security".
⚠ Microsoft project proposed to aid Linux IoT code integrity ⚠

Imagine a computer user from 2010 dreaming of a world in which Microsoft is not only an enthusiastic proponent of open source software but actively contributes to it with its own ideas. The time is now.

πŸ“– Read

via "Naked Security".
⚠ Update Firefox again – more RCEs and an Android β€œtakeover” bug too ⚠

Hot on the heels of Firefox's emergency update over the weekend are the four-weekly fixes that Mozilla had in train already. Get 'em now!

πŸ“– Read

via "Naked Security".
❌ COVID-19 CISO Checklist for Securing a Remote Workforce ❌

The CISO Checklist for Secure Remote Working was built to assist CISOs in navigating through COVID-19, providing them with a concise, high-level list of the absolute essentials needed to ensure their organization is well protected in these challenging times.

πŸ“– Read

via "Threatpost".
❌ β€˜Fake Fingerprints’ Bypass Scanners with 3D Printing ❌

New research used 3D printing technology to bypass fingerprint scanners, and tested it against Apple, Samsung and Microsoft mobile products.

πŸ“– Read

via "Threatpost".
πŸ” Talos researchers fabricate a fake that frequently fooled fingerprint locks πŸ”

The 3D printed duplicates worked on phone and a MacBook Pro laptop but not on Windows machines or two USB jump drives.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Feline Secure? πŸ•΄

When there's a will, there's a way.

πŸ“– Read

via "Dark Reading: ".
❌ WhatsApp Axes COVID-19 Mass Message Forwarding ❌

Amid rampant misinformation, users of the Facebook-owned messaging platform can no longer send coronavirus messages to more than one user at a time.

πŸ“– Read

via "Threatpost".
πŸ•΄ Why Threat Hunting with XDR Matters πŸ•΄

Extended detection response technology assumes a breach across all your endpoints, networks, SaaS applications, cloud infrastructure, and any network-addressable resource.

πŸ“– Read

via "Dark Reading: ".
πŸ” The seL4 microkernel: Optimized for security and endorsed by the Linux foundation πŸ”

What is seL4, and what does it mean for the future of connected devices?

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Accenture Buys Revolutionary Security in Third Acquisition of 2020 πŸ•΄

The deal is intended to strengthen Accenture's critical infrastructure protection capabilities and address more complex IT and OT challenges.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybercriminals, state-sponsored groups ramping up attacks exploiting COVID-19 pandemic πŸ”

IntSights researchers surveyed the cyberthreat landscape, finding a wide variety of coronavirus-themed phishing lures, malware infections, network intrusions, scams, and disinformation campaigns.

πŸ“– Read

via "Security on TechRepublic".