πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Sharp drop in overall security spending forecast from Gartner due to COVID-19 πŸ”

The pandemic is causing security spending in 2020 to shrink dramatically in most, but not all, segments, according to a revised estimate.

πŸ“– Read

via "Security on TechRepublic".
⚠ Avon cosmetics suffers β€œcyber incident” – but was it ransomware? ⚠

Ah for the bad old days when a ransomware attack was simply that: a ransomware attack, beginning, middle and end.

πŸ“– Read

via "Naked Security".
❌ Shlayer Mac Malware Returns with Extra Sneakiness ❌

Spreading via poisoned Google search results, this new version of Mac's No. 1 threat comes with added stealth.

πŸ“– Read

via "Threatpost".
πŸ•΄ 3 Things Wilderness Survival Can Teach Us About Email Security πŸ•΄

It's a short hop from shows like 'Naked and Afraid' and 'Alone' to your email server and how you secure it

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-9944

In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-9943

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20840

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20839

libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-16245

OMERO before 5.6.1 makes the details of each user available to all users.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21247

An issue was discovered in LibVNCServer before 0.9.13. There is a memory leak in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What's Anonymous Up to Now? πŸ•΄

The hacker group recently took credit for two high-profile incidents -- but its actions aren't quite the same as they once were, some say.

πŸ“– Read

via "Dark Reading: ".
πŸ” "Woefully Lax" Security Procedures at CIA Led to Data Theft πŸ”

The CIA failed to install safeguards to prevent the theft of its most valuable cyber weapons in 2016.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” How blockchain is transforming online gaming for players πŸ”

With blockchain, gamers can save their in-game purchases and retain their value to resell them to other players or move them into other games for the first time.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Most of the world's most popular passwords can be cracked in under a second πŸ”

Hackers who use brute force attacks can easily compromise accounts with weak passwords, according to Nordpass.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Lazarus Group May Have Been Behind 2019 Attacks on European Targets πŸ•΄

Telemetry hints that the North Korean actor was behind major cyber-espionage campaign focused on military and aerospace companies, ESET says.

πŸ“– Read

via "Dark Reading: ".
❌ Premier League’s Return: A Hat Trick of Cyberthreats? ❌

The beautiful game is back on the pitch in the U.K. -- and cyberattackers will be looking to take advantage of fans streaming the games.

πŸ“– Read

via "Threatpost".
πŸ•΄ What's Anonymous Up to Now? πŸ•΄

The hacker group recently took credit for two high-profile incidents -- but its actions aren't quite the same as they once were, some say.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Packet Fence 10.1.0 πŸ› 

PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Zoom Changes Course on End-to-End Encryption πŸ•΄

The videoconferencing company now says it will offer end-to-end encryption to all users beginning in July.

πŸ“– Read

via "Dark Reading: ".
❌ AcidBox Malware Uncovered Using Repurposed VirtualBox Exploit ❌

A β€œvery rare” malware has been used by an unknown threat actor in cyberattacks against two different Russian organizations in 2017.

πŸ“– Read

via "Threatpost".
πŸ•΄ 7 Tips for Employers Navigating Remote Recruitment πŸ•΄

Hiring experts explain how companies should approach recruitment when employers and candidates are working remotely.

πŸ“– Read

via "Dark Reading: ".