πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Radiflow: New Approach for Classifying OT Attack Flaws πŸ•΄

The firm says risk assessment should begin with understanding attacker taxonomy and continue with vulnerability analysis.

πŸ“– Read

via "Dark Reading: ".
❌ Threatpost Poll: Can We Fix 2FA? ❌

Take our short poll to weigh in on the state of two-factor authentication.

πŸ“– Read

via "Threatpost | The first stop for security news".
⚠ New year, new career? How some Sophos experts got into cybersecurity ⚠

We asked a number of people working in different roles at Sophos how they made their way into cybersecurity. 1. Music making to malware fighting Sales Engineer, Benedict Jones I graduated from university with a first class BSc honours degree in Sound Technology and Digital Music. I have always pertained a profound interest in music […]

πŸ“– Read

via "Naked Security".
❌ Popular Web-Hosting Platform Bluehost Riddled with Flaws, Researcher Claims ❌

He said that similar flaws were also found in the Dreamhost, HostGator, OVH and iPage web hosting platforms.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Cryptomining Continues to Be Top Malware Threat πŸ•΄

Tools for illegally mining Coinhive, Monero, and other cryptocurrency dominate list of most prevalent malware in December 2018.

πŸ“– Read

via "Dark Reading: ".
⚠ Is fake-news sharing driven by age, not politics? ⚠

Researchers say people over 65 are seven times more likely to share fake news than 18 to 29-year-olds.

πŸ“– Read

via "Naked Security".
⚠ Facebook to start fact-checking fake news in the UK ⚠

Facebook's relying on demotion instead of removal, so users will still be able to share content, even if Full Fact rates it inaccurate.

πŸ“– Read

via "Naked Security".
⚠ Blockchain burglar returns some of $1m crypto-swag ⚠

In an interesting move for villainy, a thief who stole over $1 million from the Ethereum Classic blockchain has given some of it back.

πŸ“– Read

via "Naked Security".
⚠ Windows 7 users get fix for latest updating woe ⚠

Microsoft has vexed its Windows 7 users with a misbehaving update that caused licensing and networking errors.

πŸ“– Read

via "Naked Security".
πŸ” Cyberattacks now cost businesses an average of $1.1M πŸ”

Malware and bots, phishing, and DDoS attacks are some of the top threats companies face, according to Radware.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why vendor security practices are causing heartburn for enterprise pros πŸ”

High dependencies on external vendors with unclear security policies is a concern among IT professionals, according to a Deloitte report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Former IBM Security Execs Launch Cloud Data Security Startup πŸ•΄

Sonrai Security, the brainchild of two execs from IBM Security and Q1 Labs, debuts with $18.5 million in Series A funding.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why Cyberattacks Are the No. 1 Risk πŸ•΄

The paradigm shift toward always-on IT requires business leaders to rethink their defense strategy.

πŸ“– Read

via "Dark Reading: ".
πŸ” Police can't force you to unlock your phone by iris, face or finger πŸ”

Police can't force you to unlock your phone by iris, face or finger

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2017-18358

LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18357

Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18356

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10736 (social_pug)

The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ ThreatList: $1.7M is the Average Cost of a Cyber-Attack ❌

Brand damage, loss of productivity, falling stock prices and more contribute to significant business impacts in the wake of a breach.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ 7 Privacy Mistakes To Keep Security Pros on Their Toes πŸ•΄

When it comes to privacy, it's the little things that can lead to big mishaps.

πŸ“– Read

via "Dark Reading: ".
❌ Judge: Law Enforcement Can’t Force Suspects to Unlock iPhones with FaceID ❌

A ruling found that coercing suspects to open their phones using biometrics violates the fourth and fifth amendments.

πŸ“– Read

via "Threatpost | The first stop for security news".