πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Facebook Privacy Glitch Gave 5K Developers Access to β€˜Expired’ Data ❌

Facebook has fixed a privacy issue that gave developers access to user data long after the 90-day "expiration" date.

πŸ“– Read

via "Threatpost".
❌ Apache Guacamole Opens Door for Total Control of Remote Footprint ❌

Several vulnerabilities can be chained together for a full exploit.

πŸ“– Read

via "Threatpost".
❌ Trojans, Backdoors and Droppers: The Most-Analyzed Malware ❌

Even so, backdoors and droppers are rare in the wild.

πŸ“– Read

via "Threatpost".
πŸ” Fed Offers Guidance on Curbing Synthetic Identity Fraud πŸ”

The Federal Reserve shared insights around mitigating synthetic identity fraud, one of the quickest growing financial threats, this week.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ 22,900 MongoDB Databases Affected in Ransomware Attack πŸ•΄

An attacker scanned for databases misconfigured to expose information and wiped the data, leaving a ransom note behind.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Considerations for Seamless CCPA Compliance πŸ•΄

Three steps to better serve consumers, ensure maximum security, and achieve compliance with the California Consumer Privacy Act.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Anatomy of a Long-Con Phish πŸ•΄

A fraudster on LinkedIn used my online profile in an apparent attempt to pull off a wide-ranging scam business venture.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-20894

Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Making Sense of EARN IT & LAED Bills' Implications for Crypto πŸ•΄

After Senate Judiciary Committee pushes EARN IT Act a step closer to ratification, raising further concerns for privacy advocates, here's what to know.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ BG-IP Vulnerabilities Could be Big Trouble for Customers πŸ•΄

Left unpatched, pair of vulnerabilities could give attackers wide access to a victim's application delivery network.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Building Security Strategies in Sub-Saharan Africa: Trends and Concerns πŸ•΄

Security experts discuss the rise in cybercrime affecting sub-Saharan Africa and the necessary changes to improve security.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-20419

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20418

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.

πŸ“– Read

via "National Vulnerability Database".
⚠ Google buys AR smart-glasses company North ⚠

They're not surveillance spectacles, says Google, just a piece in the jigsaw of "ambient computing", where helpfulness is all around you.

πŸ“– Read

via "Naked Security".
πŸ•΄ Cybersecurity's Lament: There are No Cooks in Space πŸ•΄

Cybersecurity staff are on edge for the same reason that there are no cooks on the ISS: Organizations are carefully watching expenses for jobs that don't require dedicated team members.

πŸ“– Read

via "Dark Reading: ".
❌ Ring Doorbell’s Police Partnerships Questioned Over Racial Bias ❌

Amazon has placed a moratorium on police use of its facial recognition platform - but a congressman asked if that extends to its Ring smart doorbell in a new inquiry.

πŸ“– Read

via "Threatpost".
πŸ•΄ Introducing 'Secure Access Service Edge' πŸ•΄

The industry's latest buzzword is largely a repackaging exercise that bundles a collection of capabilities together and offers them as a cloud-delivered service.

πŸ“– Read

via "Dark Reading: ".
πŸ” Android 11 security features and improvements you need to know πŸ”

If the Android 11 beta is an indication, Jack Wallen predicts it will be the most secure and best performing release. Developers and pro users, read about security and privacy features in Android 11.

πŸ“– Read

via "Security on TechRepublic".
⚠ Facebook hoaxes back in the spotlight – what to tell your friends ⚠

At the risk of giving you a feeling of dΓ©jΓ  vu all over again, it's time to talk about Facebook hoaxes once more.

πŸ“– Read

via "Naked Security".
❌ E.U. Authorities Crack Encryption of Massive Criminal and Murder Network ❌

Four-year investigation shuts down EncroChat and busts 746 alleged criminals for planning murders, selling drugs and laundering money.

πŸ“– Read

via "Threatpost".
πŸ” What are IT pros concerned about in the new normal? Security and flexibility πŸ”

There are a number of paramount concerns afoot among IT professionals. Learn some of the priorities from industry insiders and experts.

πŸ“– Read

via "Security on TechRepublic".