πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-7061

An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-7056

A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-7041

Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-7035

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.

πŸ“– Read

via "National Vulnerability Database".
πŸ” The secret to get employees to go back to school for cybersecurity: Pay their tuition πŸ”

With the growing need for cybersecurity professionals in the enterprise, sponsored tuition could help fill skill gaps, and 72% of workers are willing to go back to school for it.

πŸ“– Read

via "Security on TechRepublic".
❌ ProtonVPN, NordVPN Flaws Open Door to Privilege Escalation ❌

The flaws disclosed this month are related to a critical bug previously discovered by VerSprite in April 2018.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ GAO Says Equifax Missed Flaws, Intrusion in Massive Breach πŸ•΄

A report from the Government Accountability Office details the issues found and opportunities missed in the huge 2017 Equifax data breach.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Three Trend Micro Apps Caught Collecting MacOS User Data πŸ•΄

After researchers found the security apps collecting and uploading users' browser histories, Apple removed the apps from its macOS app store and Trend Micro removed the apps' browser history collection capability.

πŸ“– Read

via "Dark Reading: ".
☒ Microsoft details for the first time how it classifies Windows security bugs ☒

The Microsoft Security Response Center publishes two documents detailing internal procedures used by its staff to prioritize and classify security bugs.

πŸ“– Read

via "Latest topics for ZDNet in Security".
πŸ•΄ New 'Fallout' EK Brings Return of Old Ransomware πŸ•΄

The Fallout exploit kit carries GandCrab into the Middle East in a new campaign.

πŸ“– Read

via "Dark Reading: ".
☒ Tech support scammers find a home on Microsoft TechNet pages ☒

Security researchers finds over 3,000 TechNet pages flooded with tech support scams pushing shady phone numbers for cryptocurrency exchanges and social media platforms.

πŸ“– Read

via "Latest topics for ZDNet in Security".
☒ Internet Architecture Board warns Australian encryption-busting laws could fragment the internet ☒

Industry groups, associations, and people that know what they are talking about, line up to warn of drawbacks from Canberra's proposed Assistance and Access Bill.

πŸ“– Read

via "Latest topics for ZDNet in Security".
☒ How the industry expects to secure information in a quantum world ☒

With all of the good a quantum computer promises, one of the side effects is that it will be able to break the mechanisms currently used to secure information. But the industry is onto it, and Australia's QuintessenceLabs is playing a key role.

πŸ“– Read

via "Latest topics for ZDNet in Security".
☒ Singapore payments vendor takes app global with UnionPay partnership ☒

Network for Electronic Transfers of Singapore (Nets) has inked an agreement with China's UnionPay to enable consumers to scan and pay for purchases at 7.5 million participating merchants worldwide.

πŸ“– Read

via "Latest topics for ZDNet in Security".
☒ British Airways breach caused by the same group that hit Ticketmaster ☒

Security researchers find clues connecting the Magecart group to the breach at British Airways.

πŸ“– Read

via "Latest topics for ZDNet in Security".
⚠ Microsoft extends security patch support for some Windows 7 users ⚠

Microsoft will provide security updates until 2023 to help business customers migrate to Windows 10 - if they pay.

πŸ“– Read

via "Naked Security".
⚠ Keybase browser extension weakness discovered ⚠

Respected researcher Wladimir Palant has recommended users β€œuninstall the Keybase browser extension ASAP” after discovering a gap in its end-to-end encryption.

πŸ“– Read

via "Naked Security".
☒ How to steal a Tesla Model S in seconds ☒

An attack technique has been revealed which allows threat actors to unlock a Tesla vehicle in no time at all.

πŸ“– Read

via "Latest topics for ZDNet in Security".
☒ ​Trend Micro says sorry after apps grabbed Mac browser history ☒

The company has now removed a browser history data collection feature from its macOS products.

πŸ“– Read

via "Latest topics for ZDNet in Security".
⚠ Yikes: 1 in 5 employees share their email passwords with coworkers ⚠

19% of employees of small and medium-sized businesses share their passwords with coworkers or assistants, according to a recent survey.

πŸ“– Read

via "Naked Security".