πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Microsoft June Patch Tuesday Fixes 129 Flaws in Largest-Ever Update ❌

The June Patch Tuesday update included CVEs for 11 critical remote code-execution vulnerabilities and concerning SMB bugs.

πŸ“– Read

via "Threatpost".
πŸ” Macy’s to Settle 2018 Data Breach Class Action Suit πŸ”

Two years after it happened, the popular department store is electing to settle a class action data breach lawsuit that alleged the company failed to properly secure customer data online.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ DHS Warns on New Exploit of Windows 10 Vulnerability πŸ•΄

The vulnerability was patched in March, but a new proof of concept raises the stakes for organizations that haven't yet updated their software.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Vulnerability in Plug-and-Play Protocol Puts Billions of Devices at Risk πŸ•΄

"CallStranger" flaw in UPnP allows attackers to launch DDoS attacks and scan internal ports, security researcher says.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to install sudo 1.9 and use the new policy tool πŸ”

The sudo system is about to undergo some radical changes. Find out how to begin working with the new policy system, to make sudo even more powerful.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Fixes 129 Bugs in Largest Patch Tuesday Release πŸ•΄

The June release of security updates addresses several remote code execution vulnerabilities in SharePoint, Excel, Windows OLE, and other services.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-3617

Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-3613

DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.

πŸ“– Read

via "National Vulnerability Database".
⚠ Billions of devices affected by UPnP vulnerability ⚠

Stop us if you’ve heard this before but a researcher has uncovered a new security vulnerability affecting many devices running the Universal Plug and Play (UPnP) protocol.

πŸ“– Read

via "Naked Security".
⚠ Babylon mobile health app mixes up patient consultation videos ⚠

A heatlh care app user found 50 "consultation replay" videos in his personal profile - but they weren't his.

πŸ“– Read

via "Naked Security".
⚠ β€˜Bot or Not?’ – a game to train us to spot chatbots faking it as humans ⚠

Can you tell whether you're talking to a human or AI?

πŸ“– Read

via "Naked Security".
πŸ” Honda hit by cyberattack that impacted its global operations πŸ”

The automaker's customer service and financial services are unavailable as it deals with an attack that experts believe is ransomware.

πŸ“– Read

via "Security on TechRepublic".
πŸ” 92% of SMBs think they can recover from a disaster, but many don't have plans in place πŸ”

New research shows that the vast majority of small and midsize leaders believe they expect, and can handle, the unexpectedβ€”but 16% don't even know their recovery time objective.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How DNS attacks threaten organizations πŸ”

Application downtime was the most significant side effect of a DNS attack, according to EfficientIP.

πŸ“– Read

via "Security on TechRepublic".
❌ Thanos Ransomware First to Weaponize RIPlace Tactic ❌

Thanos is the first ransomware family to feature the weaponized RIPlace tactic, enabling it to bypass ransomware protections.

πŸ“– Read

via "Threatpost".
❌ Encryption Utility Firm Accused of Bundling Malware Functions in Product ❌

The increasingly prevalent GuLoader malware has been traced back to a far-reaching encryption service that attempts to pass as above-board.

πŸ“– Read

via "Threatpost".
πŸ•΄ 3 Ways the Pandemic Will Affect Enterprise Security in the Future πŸ•΄

While CISOs have been focused on immediate threats, it's time to look ahead to what a post-COVID-19 future will look like.

πŸ“– Read

via "Dark Reading: ".
πŸ” What is Cyber Security? Definition, Best Practices & More πŸ”

Learn about cyber security, why it's important, and how to get started building a cyber security program in this installment of our Data Protection 101 series.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2019-4576

IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-3588

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-3585

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges.

πŸ“– Read

via "National Vulnerability Database".