🛡 Cybersecurity & Privacy 🛡 - News
26.1K subscribers
89.3K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
Hack Allows Escape of Play-with-Docker Containers

Researchers created a proof-of-concept escape of Docker test environment.

📖 Read

via "Threatpost | The first stop for security news".
🕴 Radiflow: New Approach for Classifying OT Attack Flaws 🕴

The firm says risk assessment should begin with understanding attacker taxonomy and continue with vulnerability analysis.

📖 Read

via "Dark Reading: ".
Threatpost Poll: Can We Fix 2FA?

Take our short poll to weigh in on the state of two-factor authentication.

📖 Read

via "Threatpost | The first stop for security news".
New year, new career? How some Sophos experts got into cybersecurity

We asked a number of people working in different roles at Sophos how they made their way into cybersecurity. 1. Music making to malware fighting Sales Engineer, Benedict Jones I graduated from university with a first class BSc honours degree in Sound Technology and Digital Music. I have always pertained a profound interest in music […]

📖 Read

via "Naked Security".
Popular Web-Hosting Platform Bluehost Riddled with Flaws, Researcher Claims

He said that similar flaws were also found in the Dreamhost, HostGator, OVH and iPage web hosting platforms.

📖 Read

via "Threatpost | The first stop for security news".
🕴 Cryptomining Continues to Be Top Malware Threat 🕴

Tools for illegally mining Coinhive, Monero, and other cryptocurrency dominate list of most prevalent malware in December 2018.

📖 Read

via "Dark Reading: ".
Is fake-news sharing driven by age, not politics?

Researchers say people over 65 are seven times more likely to share fake news than 18 to 29-year-olds.

📖 Read

via "Naked Security".
Facebook to start fact-checking fake news in the UK

Facebook's relying on demotion instead of removal, so users will still be able to share content, even if Full Fact rates it inaccurate.

📖 Read

via "Naked Security".
Blockchain burglar returns some of $1m crypto-swag

In an interesting move for villainy, a thief who stole over $1 million from the Ethereum Classic blockchain has given some of it back.

📖 Read

via "Naked Security".
Windows 7 users get fix for latest updating woe

Microsoft has vexed its Windows 7 users with a misbehaving update that caused licensing and networking errors.

📖 Read

via "Naked Security".
🔐 Cyberattacks now cost businesses an average of $1.1M 🔐

Malware and bots, phishing, and DDoS attacks are some of the top threats companies face, according to Radware.

📖 Read

via "Security on TechRepublic".
🔐 Why vendor security practices are causing heartburn for enterprise pros 🔐

High dependencies on external vendors with unclear security policies is a concern among IT professionals, according to a Deloitte report.

📖 Read

via "Security on TechRepublic".
🕴 Former IBM Security Execs Launch Cloud Data Security Startup 🕴

Sonrai Security, the brainchild of two execs from IBM Security and Q1 Labs, debuts with $18.5 million in Series A funding.

📖 Read

via "Dark Reading: ".
🕴 Why Cyberattacks Are the No. 1 Risk 🕴

The paradigm shift toward always-on IT requires business leaders to rethink their defense strategy.

📖 Read

via "Dark Reading: ".
🔐 Police can't force you to unlock your phone by iris, face or finger 🔐

Police can't force you to unlock your phone by iris, face or finger

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2017-18358

LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-18357

Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-18356

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10736 (social_pug)

The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.

📖 Read

via "National Vulnerability Database".
ThreatList: $1.7M is the Average Cost of a Cyber-Attack

Brand damage, loss of productivity, falling stock prices and more contribute to significant business impacts in the wake of a breach.

📖 Read

via "Threatpost | The first stop for security news".
🕴 7 Privacy Mistakes To Keep Security Pros on Their Toes 🕴

When it comes to privacy, it's the little things that can lead to big mishaps.

📖 Read

via "Dark Reading: ".