πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ’‘ Adobe patch update tackles six critical vulnerabilities in ColdFusion πŸ’‘

The worst vulnerabilities lead to arbitrary code execution.

πŸ“– Read

via "Latest topics for ZDNet in Security".
πŸ’‘ Data management firm Veeam mismanages own data, leaks 445m records πŸ’‘

The server was reportedly available for anyone to access and lacked any form of protection against intrusion.

πŸ“– Read

via "Latest topics for ZDNet in Security".
⚠ Vizio to send class notices through the TVs that spied on viewers ⚠

Millions of smart TVs may soon be forced to admit to viewers that they spied on them, and then sold their data.

πŸ“– Read

via "Naked Security".
πŸ’‘ Apricorn Aegis Secure Key 3NX: The best flash drive for business users πŸ’‘

Business users looking for a USB flash drive that offers built-in encryption and a broad range of storage capacities, all at an affordable price need look no further.

πŸ“– Read

via "Latest topics for ZDNet in Security".
πŸ’‘ OpenSSL 1.1.1 out with TLS 1.3 support and "complete rewrite" of RNG component πŸ’‘

TLS 1.3 brings speed improvements and better cryptography to OpenSSL, the most popular open source cryptography library on the market

πŸ“– Read

via "Latest topics for ZDNet in Security".
πŸ” Why behavioral biometrics are the next hot security technology πŸ”

Biometrics, from fingerprints to iris- and facial-recognition, are advancing, with behavioral biometrics quickly becoming the security access of choice, says BioCatch VP Frances Zelazny.

πŸ“– Read

via "Security on TechRepublic".
⚠ Younger Facebook users 4 times more likely to delete app, study shows ⚠

They also appear to be more privacy-wary, with 64% changing their settings, comparing to just a third of older users.

πŸ“– Read

via "Naked Security".
⚠ Beware: WhatsApp scammers target children with β€˜Olivia’ porn message ⚠

"I can send a picture where all of us are together," says "Olivia," before sending a porn URL. Tell kids not to click!

πŸ“– Read

via "Naked Security".
πŸ” What to expect from cyber-attacks during an election year πŸ”

Jake Dilemani, Senior Vice President Mercury Communication, explains how cyber-attacks targeting communication systems and critical infrastructure can alter the course of history.

πŸ“– Read

via "Security on TechRepublic".
⚠ Microsoft purges 3,000 tech support scams hiding on TechNet ⚠

Microsoft has taken down thousands of ads for tech support scams that infested the company’s TechNet support domain.

πŸ“– Read

via "Naked Security".
πŸ’‘ After Windows 10 upgrade, do these seven things immediately πŸ’‘

You've just upgraded to the most recent version of Windows 10. Before you get back to work, use this checklist to ensure that your privacy and security settings are correct and that you've cut annoyances to a bare minimum.

πŸ“– Read

via "Latest topics for ZDNet in Security".
πŸ’‘ BlackBerry's ambitious target: Protecting everything from smartphones to cities πŸ’‘

BlackBerry Security Summit London: CEO John Chen details how the company wants to harness machine learning and AI.

πŸ“– Read

via "Latest topics for ZDNet in Security".
πŸ’‘ Phishing warning: One in every one hundred emails is now a hacking attempt πŸ’‘

And just one mistake can compromise an entire organisation.

πŸ“– Read

via "Latest topics for ZDNet in Security".
πŸ’‘ Okta partners with Yubico to offer free security keys πŸ’‘

Okta will give away two free Okta-branded YubiKey Experience Packs to every Okta customer organization using Okta MFA and Okta Adaptive MFA.

πŸ“– Read

via "Latest topics for ZDNet in Security".
❔ CVE-2018-8440 – Task Scheduler ALPC Zero-Day Exploit in the Wild ❔

Estimated reading time: 1 minuteThe recent zero-day vulnerability CVE-2018-8440 in Windows Task Scheduler enables attackers to perform a privilege elevation on targeted machines. Microsoft has released a security advisory CVE-2018-8440 on September 11, 2018 to address this issue. According to Microsoft, successful exploitation of this vulnerability could run arbitrary code in the security context of the local system. About the vulnerability CVE-2018-8440 is a local privilege escalation vulnerability in the Windows Task Scheduler’s Advanced Local Procedure Call (ALPC) interface. The ALPC endpoint in Windows task scheduler exports the SchRpcSetSecurity function, which allows us to set an arbitrary DACL without checking permissions. Exploiting the vulnerability ultimately allows a local unprivileged user to change the permissions of any file on the system. The exploit code release was announced on twitter, on 27th August 2018, by a security researcher who goes with the handle β€œSandboxEscaper”.  Within days, PowerPool malware was found using the exploit to infect users. Vulnerable versions Windows 7 Windows 8.1 Windows 10 Windows Server 2008, 2012 and 2016 Quick Heal detection Quick Heal has released the following detection for the vulnerability CVE-2018-8440: Trojan.Win64 Trojan.IGeneric Quick Heal Security Labs is actively looking for new in-the-wild exploits for this vulnerability and ensuring coverage for them. References https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8440 Subject Matter Experts Sameer Patil | Quick Heal Security Labs The post CVE-2018-8440 – Task Scheduler ALPC Zero-Day Exploit in the Wild appeared first on Quick Heal Blog | Latest computer security news, tips, and advice.

πŸ“– Read

via "Quick Heal Blog | Latest computer security news, tips, and advice".
πŸ” Awful military and government LinkedIn passwords highlight need for 2FA, new policies πŸ”

Password inadequacy remains a top threat in internet security, according to a new report from WatchGuard Technologies.

πŸ“– Read

via "Security on TechRepublic".
πŸ” BlackBerry's ambitious target: Protecting everything from smartphones to cities πŸ”

BlackBerry Security Summit London: CEO John Chen details how the company wants to harness machine learning and AI.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 8 Cryptomining Malware Families to Keep on the Radar πŸ•΄

Cryptojacking attacks at the hands of cryptomining malware is on the rise as these variants of Trojans, worms, and exploit kits make their rounds.

πŸ“– Read

via "Dark Reading: ".
❌ Osiris Banking Trojan Displays Modern Malware Innovation ❌

Osiris’ fundamental makeup positions it in the fore of malware trends, despite being based on old source code that’s been knocking around for years.

πŸ“– Read

via "The first stop for security news | Threatpost ".
❌ Apple Yet to Patch Safari Browser Address Bar Spoofing Flaw ❌

A flaw in Safari - that allows an attacker to spoof websites and trick victims into handing over their credentials - has yet to be patched.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ Mobile Attack Rates Up 24% Globally, 44% in US πŸ•΄

One-third of all fraud targets are mobile, a growing source of all digital transactions.

πŸ“– Read

via "Dark Reading: ".