πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 The new Ring Always Home Camera is a security disaster in the making 🦿

Jack Wallen offers his take on the upcoming release of the Ring Always Home Cam.

πŸ“– Read

via "Tech Republic".
🦿 Could Microsoft be en route to dumping Windows in favor of Linux? 🦿

Microsoft Linux is the next evolution of the Microsoft desktop operating system, argues Jack Wallen. He explains why this would be a win-win for Microsoft, IT pros, users, and the Linux community.

πŸ“– Read

via "Tech Republic".
❌ Sophisticated Android Ransomware Executes with the Home Button ❌

The malware also has a unique machine-learning module.

πŸ“– Read

via "Threat Post".
πŸ•΄ CISOs Planning on Bigger Budgets: Report πŸ•΄

Budgets are on the rise, even in a time of revenue worries across the industry.

πŸ“– Read

via "Dark Reading".
🦿 How to secure your open source supply chain 🦿

Commentary: Open source has never been more popular, which means it's time to figure out how to effectively secure the open source you use. Two experts weigh in.

πŸ“– Read

via "Tech Republic".
🦿 How the enterprise can shut down cyber criminals and protect a remote staff 🦿

Hackers accidentally allowed into company software by security noncompliant employees cost businesses millions annually; we asked experts to weigh in on best safety practices.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Critical Zerologon Flaw Exploited in TA505 Attacks πŸ•΄

Microsoft reports a new campaign leveraging the critical Zerologon vulnerability just days after nation-state group Mercury was seen using the flaw.

πŸ“– Read

via "Dark Reading".
πŸ” 10/9 Friday Five πŸ”

Antitrust reforms, biometic data collection, and DHS malware warnings - catch up on all the week's news with the Friday Five!

πŸ“– Read

via "Digital Guardian".
❌ Fitbit Spyware Steals Personal Data via Watch Face ❌

Immersive Labs Researcher takes advantage of lax Fitbit privacy controls to build a malicious spyware watch face.

πŸ“– Read

via "Threat Post".
πŸ•΄ Apple Pays Bug Bounty to Enterprise Network Researchers πŸ•΄

So far, the company has doled out $288,000 to five researchers who, in three months, found 55 vulnerabilities in its corporate infrastructure.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Latest Version of MalLocker Android Ransomware Packs New Tricks πŸ•΄

Like most such mobile malware, the new one doesn't encrypt data but attempts to make an infected system impossible to use, Microsoft says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-26935 β€Ό

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26947 β€Ό

monero-wallet-gui in Monero GUI 0.17.0.1 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26948 β€Ό

Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14184 β€Ό

Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5141 β€Ό

A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep1: Ransomware – is it really OK to pay? – Naked Security Podcast ⚠

Our podcast is back for Series 3 - here's Episode 1!

πŸ“– Read

via "Naked Security".
⚠ Naked Security Live – Cybersecurity tips for your own network ⚠

Here's the latest Naked Security Live video - enjoy (and please share with your friends)!

πŸ“– Read

via "Naked Security".
❌ Ransomware Attackers Buy Network Access in Cyberattack Shortcut ❌

Network access to various industries is being offered in underground forums at as little as $300 a pop - and researchers warn that ransomware groups like Maze and NetWalker could be buying in.

πŸ“– Read

via "Threat Post".
πŸ•΄ How to Pinpoint Rogue IoT Devices on Your Network πŸ•΄

Researchers explain how security practitioners can recognize when a seemingly benign device could be malicious.

πŸ“– Read

via "Dark Reading".