๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด How Should I Securely Destroy/Discard My Devices? ๐Ÿ•ด

While it is possible to do data destruction in-house, doing it correctly and at scale can be tedious.

๐Ÿ“– Read

via "Dark Reading: ".
โŒ Meetup Critical Flaws Allow โ€˜Groupโ€™ Takeover, Payment Theft โŒ

Researchers disclosed critical flaws in the popular Meetup service at Black Hat USA 2020 this week, which could allow takeover of Meetup "Groups."

๐Ÿ“– Read

via "Threatpost".
๐Ÿ•ด A Patriotic Solution to the Cybersecurity Skills Shortage ๐Ÿ•ด

Why now is the right time for the security industry to invest in the human capital that will make technology better, smarter, and safer.

๐Ÿ“– Read

via "Dark Reading: ".
ATENTIONโ€ผ New - CVE-2019-4589

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-4366

IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ” BlackBerry launches free tool for reverse engineering to fight cybersecurity attacks ๐Ÿ”

One of the first announcements at BlackHat USA 2020 is an open-source tool to fight malware that BlackBerry first used internally and is now making available to everyone.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ” How to better protect your organization against mobile threats ๐Ÿ”

The increased use of personal phones for work and the growth of mobile malware create a risk to organizations, says Gigamon.

๐Ÿ“– Read

via "Security on TechRepublic".
โŒ Black Hat USA 2020: Critical Meetup.com Flaws Reveal Common AppSec Holes โŒ

With Black Hat USA 2020 kicking off this week, Erez Yalon with Checkmarx talks about newly disclosed, critical vulnerabilities in Meetup.com - and why they are the "holy grail" for attackers.

๐Ÿ“– Read

via "Threatpost".
๐Ÿ•ด Travel Management Firm CWT Pays $4.5M to Ransomware Attackers ๐Ÿ•ด

Attackers claimed to steal two terabytes of files including financial reports, security files, and employees' personal data.

๐Ÿ“– Read

via "Dark Reading: ".
ATENTIONโ€ผ New - CVE-2019-19455

Wowza Streaming Engine through 2019-11-28 has Insecure Permissions.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-19453

Wowza Streaming Engine through 2019-11-28 allows XSS (issue 1 of 2).

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ Garmin Pays Up to Evil Corp After Ransomware Attack โ€” Reports โŒ

The ransom for the decryptor key in the WastedLocker attack could have topped $10 million, sources said.

๐Ÿ“– Read

via "Threatpost".
๐Ÿ” Survey: Barriers prevent data privacy initiatives ๐Ÿ”

Corporate culture, lack of privacy teams hurt privacy initiatives.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ›  Samhain File Integrity Checker 4.4.2 ๐Ÿ› 

Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.

๐Ÿ“– Go!

via "Security Tool Files โ‰ˆ Packet Storm".
๐Ÿ›  Sifter 9.1 ๐Ÿ› 

Sifter is a osint, recon, and vulnerability scanner. It combines a plethora of tools within different module sets in order to quickly perform recon tasks, check network firewalling, enumerate remote and local hosts, and scan for the blue vulnerabilities within Microsoft systems and if unpatched, exploits them.

๐Ÿ“– Go!

via "Security Tool Files โ‰ˆ Packet Storm".
๐Ÿ” The Linux Foundation announces collective to enhance open source software security ๐Ÿ”

The newly formed Open Source Security Foundation includes titans in technology such as Google, Intel, Microsoft, IBM, and more.

๐Ÿ“– Read

via "Security on TechRepublic".
ATENTIONโ€ผ New - CVE-2015-9549

A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ Netgear Wonโ€™t Patch 45 Router Models Vulnerable to Serious Flaw โŒ

Almost two months after a high-severity flaw was disclosed - and seven months after it was first reported - Netgear has yet to issue fixes for 45 of its router models.

๐Ÿ“– Read

via "Threatpost".
๐Ÿ” New Bill Would Bar IP Theft Offenders From US ๐Ÿ”

Yet another bill designed to crackdown on IP theft, the Stop Theft of Intellectual Property Act of 2020, was introduced in the Senate last week

๐Ÿ“– Read

via "Subscriber Blog RSS Feed ".
โŒ Google Updates Ad Policies to Counter Influence Campaigns, Extortion โŒ

Starting Sept. 1, Google will crack down on misinformation, a lack of transparency and the ability to amplify or circulate politically influential content.

๐Ÿ“– Read

via "Threatpost".