πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Google Chrome Redesign Puts Security & Privacy in Users' Hands πŸ•΄

The Chrome browser will tell users if their browser is up to date, malicious extensions are installed, and/or a password has been compromised.

πŸ“– Read

via "Dark Reading: ".
πŸ” Chrome, Firefox Introduce New Password Security Features πŸ”

The line between browsers and password managers keeps blurring. Firefox and Chrome recently incorporated new ways for users to tell if passwords they’re using are compromised.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Productive pandemic: Searches for free online courses are up 309% πŸ”

Available online classes include ways to upgrade your resume, add to current skills, or land a better job.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Magecart Plants Card Skimmers via Old Magento Plugin Flaw πŸ•΄

The FBI has warned ecommerce sites about attacks targeting a more than three-year-old flaw in the Magmi mass importer.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-11048

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

πŸ“– Read

via "National Vulnerability Database".
⚠ FBI finally unlock shooter’s iPhones, berate Apple for not helping ⚠

The FBI's Apple problem.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-5997

Video Insight VMS 7.5 and earlier allows remote attackers to conduct code injection attacks via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
⚠ Office 365 exposed some internal search results to other companies ⚠

It’s not clear how many accounts were involved, but Microsoft is said to have made URLs and metadata available so admins can investigate.

πŸ“– Read

via "Naked Security".
πŸ” Dark Web sees rise in postings selling access to corporate networks πŸ”

These postings provide cybercriminals with the information needed to hack into networks where they can infect critical machines with malware, according to Positive Technologies.

πŸ“– Read

via "Security on TechRepublic".
❌ Alleged Hacker Behind Massive β€˜Collection 1’ Data Dump Arrested ❌

The threat actor known as β€˜Sanix’ had terabytes of stolen credentials at his residence, authorities said.

πŸ“– Read

via "Threatpost".
πŸ” Open source security report finds library-induced flaws in 70% of applications πŸ”

Problems are everywhere, but most fixes are easy to find and implement, according to a Veracode report that analyzed .

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Is Zero Trust the Best Answer to the COVID-19 Lockdown? πŸ•΄

Enterprises need to recognize that remote access and other pandemic-related security challenges cannot be fixed with buzzwords or silver-bullet security tools.

πŸ“– Read

via "Dark Reading: ".
❌ Verizon DBIR: Web App Attacks and Security Errors Surge ❌

Threatpost talks to Verizon DBIR co-author Gabriel Bassett about the top takeaways from this year's Data Breach Investigations Report.

πŸ“– Read

via "Threatpost".
πŸ•΄ Coronavirus-Themed Phishing Fears Largely Overblown, Researchers Say πŸ•΄

As COVID-19-themed spam rises, phishing-not so much. An analysis of newly registered domains finds that only 2.4% are actually phishing sites aiming to steal credentials.

πŸ“– Read

via "Dark Reading: ".
πŸ” New phishing campaign impersonates LogMeIn to steal user credentials πŸ”

LogMeIn is the parent company of LastPass, so attackers may also be attempting to access the password managers of compromised users, says Abnormal Security.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Nearly 70% of major companies will increase cybersecurity spending post-coronavirus πŸ”

With more people working from home, cybercrimes skyrocketed, forcing companies to rethink tech budgets, LearnBonds found.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Working from home: Why it takes a pandemic to improve work-life "fusion" πŸ”

Adjusting to remote work has created many opportunities and challenges in business and IT.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Warns of Vulnerability Affecting Windows DNS Server πŸ•΄

A new security advisory addresses a vulnerability that could be exploited to cause a denial-of-service attack.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10726

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-10725

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Wireshark Analyzer 3.2.4 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".