🛡 Cybersecurity & Privacy 🛡 - News
26.1K subscribers
89.3K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🔐 3 basic things to know about your data, according to Xerox's CISO 🔐

Dan Patterson interviews Xerox CISO Alissa Abdullah about protecting sensitive data from adversaries. They also discuss the recent Marriott hack, privacy, ransomware, machine learning, and IoT.

📖 Read

via "Security on TechRepublic".
Old tweets reveal hidden secrets

Old Twitter posts could reveal more about you than you think, according to researchers, even if you didn’t explicitly mention it.

📖 Read

via "Naked Security".
🔐 69% of enterprises moving business-critical applications to the cloud 🔐

Security concerns top the list of challenges to cloud migration, according to a Cloud Security Alliance report.

📖 Read

via "Security on TechRepublic".
🕴 Kudos to the Unsung Rock Stars of Security 🕴

It is great to have heroes, but the real security heroes are the men and women who keep the bad guys out while fighting their own organizations at the same time.

📖 Read

via "Dark Reading: ".
Yet Another Bypass: Is 2FA Broken? Authentication Experts Weigh In

A penetration testing tool called Modlishka can defeat two-factor authentication in the latest 2FA security issue. We asked a roundtable of experts what it all means.

📖 Read

via "Threatpost | The first stop for security news".
U.S. Government Shutdown Leaves Dozens of .Gov Websites Vulnerable

As the shutdown continues into its 21st day, dozens of .gov websites haven't renewed their TLS certificates.

📖 Read

via "Threatpost | The first stop for security news".
🕴 Who Takes Responsibility for Cyberattacks in the Cloud? 🕴

A new CSA report addresses the issue of breach responsibility as more organizations move ERP application data the cloud.

📖 Read

via "Dark Reading: ".
TA505 Crime Gang Debuts Brand-New ServHelper Backdoor

The latest malware from TA505 has been seen targeting banks, retailers and restaurants with two different versions.

📖 Read

via "Threatpost | The first stop for security news".
🕴 6 Serverless and Containerization Trends CISOs Should Track 🕴

Security leaders must stay on top of a fast-moving world of cloud deployment options.

📖 Read

via "Dark Reading: ".
🕴 NotPetya Victim Mondelez Sues Zurich Insurance for $100 Million 🕴

Mondelez files lawsuit after Zurich rejects claim for damages from massive ransomware attack.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2017-13891

In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-13889

In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-13888

In iOS before 11.2, a type confusion issue was addressed with improved memory handling.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-13887

In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-13886

In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was addressed with additional restrictions.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-7576

In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-4644

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-4643

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-4642

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.

📖 Read

via "National Vulnerability Database".
🕴 SCOTUS Says Suit Over Fiat-Chrysler Hack Can Move Forward 🕴

A class-action suit over a 2015 attack demonstration against a Jeep Cherokee can move forward, US Supreme Court rules.

📖 Read

via "Dark Reading: ".
🕴 How Enterprises Are Attacking the Cybersecurity Problem 🕴

Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.

📖 Read

via "Dark Reading: ".