πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-20839

libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-16245

OMERO before 5.6.1 makes the details of each user available to all users.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21247

An issue was discovered in LibVNCServer before 0.9.13. There is a memory leak in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What's Anonymous Up to Now? πŸ•΄

The hacker group recently took credit for two high-profile incidents -- but its actions aren't quite the same as they once were, some say.

πŸ“– Read

via "Dark Reading: ".
πŸ” "Woefully Lax" Security Procedures at CIA Led to Data Theft πŸ”

The CIA failed to install safeguards to prevent the theft of its most valuable cyber weapons in 2016.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” How blockchain is transforming online gaming for players πŸ”

With blockchain, gamers can save their in-game purchases and retain their value to resell them to other players or move them into other games for the first time.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Most of the world's most popular passwords can be cracked in under a second πŸ”

Hackers who use brute force attacks can easily compromise accounts with weak passwords, according to Nordpass.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Lazarus Group May Have Been Behind 2019 Attacks on European Targets πŸ•΄

Telemetry hints that the North Korean actor was behind major cyber-espionage campaign focused on military and aerospace companies, ESET says.

πŸ“– Read

via "Dark Reading: ".
❌ Premier League’s Return: A Hat Trick of Cyberthreats? ❌

The beautiful game is back on the pitch in the U.K. -- and cyberattackers will be looking to take advantage of fans streaming the games.

πŸ“– Read

via "Threatpost".
πŸ•΄ What's Anonymous Up to Now? πŸ•΄

The hacker group recently took credit for two high-profile incidents -- but its actions aren't quite the same as they once were, some say.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Packet Fence 10.1.0 πŸ› 

PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Zoom Changes Course on End-to-End Encryption πŸ•΄

The videoconferencing company now says it will offer end-to-end encryption to all users beginning in July.

πŸ“– Read

via "Dark Reading: ".
❌ AcidBox Malware Uncovered Using Repurposed VirtualBox Exploit ❌

A β€œvery rare” malware has been used by an unknown threat actor in cyberattacks against two different Russian organizations in 2017.

πŸ“– Read

via "Threatpost".
πŸ•΄ 7 Tips for Employers Navigating Remote Recruitment πŸ•΄

Hiring experts explain how companies should approach recruitment when employers and candidates are working remotely.

πŸ“– Read

via "Dark Reading: ".
⚠ Adobe drops slew of critical patches ⚠

Adobe released another set of patches for its products on Tuesday, a week after dropping its first set of fixes for the month.

πŸ“– Read

via "Naked Security".
❌ InvisiMole Group Resurfaces Touting Fresh Toolset, Gamaredon Partnership ❌

InvisiMole is back, targeting Eastern Europe organizations in the military sector and diplomatic missions with an updated toolset and new APT partnership.

πŸ“– Read

via "Threatpost".
⚠ Crypto founder admits $25 million ICO backed by celebrities was a scam ⚠

Endorsed by boxer Floyd Mayweather and DJ Khaled, the Centra Tech ICO debacle has led to the guilty plea of co-founder Robert Farkas.

πŸ“– Read

via "Naked Security".
❌ Phishing Campaign Targeting Office 365, Exploits Brand Names ❌

Attackers use trusted entities to trick victims into giving up their corporate log-in details as well as to bypass security protections.

πŸ“– Read

via "Threatpost".
❌ Five Password Tips for Securing the New WFH Normal ❌

Darren James, product specialist with Specops Software, warned that password resets, for example, are a particularly vexing issue for sysadmins, as they can often lockout end-users from their accounts.

πŸ“– Read

via "Threatpost".
❌ BofA Phish Gets Around DMARC, Other Email Protections ❌

The June campaign was targeted and aimed at stealing online banking credentials.

πŸ“– Read

via "Threatpost".
πŸ” IT leaders say productivity went up during lockdown despite delaying projects and security work πŸ”

Survey finds that IT leaders plan to increase security measures when offices reopen.

πŸ“– Read

via "Security on TechRepublic".