πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Reddit Alerts Users to Possible Account Breaches πŸ•΄

User lockouts, combined with requirements for new passwords, indicate an attack on accounts at the popular social media platform.

πŸ“– Read

via "Dark Reading: ".
❌ At CES, Focus is On β€˜Cool Factor’ Not IoT Security ❌

When it comes to IoT, the priority at CES is the "wow factor" - but not so much a focus on security.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ DNS Hijacking Campaign Targets Organizations Globally πŸ•΄

A group believed to be operating out of Iran has manipulated DNS records belonging to dozens of firms in an apparent cyber espionage campaign, FireEye says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New Software Side-Channel Attack Raises Risk for Captured Crypto πŸ•΄

The new attack hits operating systems, not chips, and may give criminals the keys to a company's cryptography.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-1002157

modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-1002152

Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

πŸ“– Read

via "National Vulnerability Database".
⚠ El Chapo was brought down by a sysadmin ⚠

Christian Rodriguez says he set up secure VoIP communications for the cartel: a system whose encryption keys he wound up giving to the FBI.

πŸ“– Read

via "Naked Security".
⚠ Trading site DX.Exchange spills gobs of user data ⚠

A trader believes he could easily have obtained admin access to the site and potentially have stolen the funds of its 600,000 users.

πŸ“– Read

via "Naked Security".
⚠ 2FA codes can be phished by new pentest tool ⚠

A researcher has published a tool called Modlishka, capable of phishing 2FA codes sent by SMS or authentication apps.

πŸ“– Read

via "Naked Security".
πŸ” 3 basic things to know about your data, according to Xerox's CISO πŸ”

Dan Patterson interviews Xerox CISO Alissa Abdullah about protecting sensitive data from adversaries. They also discuss the recent Marriott hack, privacy, ransomware, machine learning, and IoT.

πŸ“– Read

via "Security on TechRepublic".
⚠ Old tweets reveal hidden secrets ⚠

Old Twitter posts could reveal more about you than you think, according to researchers, even if you didn’t explicitly mention it.

πŸ“– Read

via "Naked Security".
πŸ” 69% of enterprises moving business-critical applications to the cloud πŸ”

Security concerns top the list of challenges to cloud migration, according to a Cloud Security Alliance report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Kudos to the Unsung Rock Stars of Security πŸ•΄

It is great to have heroes, but the real security heroes are the men and women who keep the bad guys out while fighting their own organizations at the same time.

πŸ“– Read

via "Dark Reading: ".
❌ Yet Another Bypass: Is 2FA Broken? Authentication Experts Weigh In ❌

A penetration testing tool called Modlishka can defeat two-factor authentication in the latest 2FA security issue. We asked a roundtable of experts what it all means.

πŸ“– Read

via "Threatpost | The first stop for security news".
❌ U.S. Government Shutdown Leaves Dozens of .Gov Websites Vulnerable ❌

As the shutdown continues into its 21st day, dozens of .gov websites haven't renewed their TLS certificates.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Who Takes Responsibility for Cyberattacks in the Cloud? πŸ•΄

A new CSA report addresses the issue of breach responsibility as more organizations move ERP application data the cloud.

πŸ“– Read

via "Dark Reading: ".
❌ TA505 Crime Gang Debuts Brand-New ServHelper Backdoor ❌

The latest malware from TA505 has been seen targeting banks, retailers and restaurants with two different versions.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ 6 Serverless and Containerization Trends CISOs Should Track πŸ•΄

Security leaders must stay on top of a fast-moving world of cloud deployment options.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ NotPetya Victim Mondelez Sues Zurich Insurance for $100 Million πŸ•΄

Mondelez files lawsuit after Zurich rejects claim for damages from massive ransomware attack.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-13891

In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-13889

In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.

πŸ“– Read

via "National Vulnerability Database".