πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Change your password! VoIP provider leaves huge database exposed online ⚠

A researcher has discovered an exposed database containing gigabytes of call logs, SMS data, and internal system credentials belonging to US Voice-over-IP (VoIP) service provider VOIPo.com.

πŸ“– Read

via "Naked Security".
⚠ Microsoft font gives away forgery in bankruptcy case ⚠

In a case that could be straight out of a legal TV drama, a computing font has cost a couple two houses in a Canadian bankruptcy case.

πŸ“– Read

via "Naked Security".
❌ Cryptomining Malware Uninstalls Cloud Security Products ❌

New samples of cryptomining malware performs a never-before-seen function: uninstalling cloud security products.

πŸ“– Read

via "Threatpost | The first stop for security news".
⚠ Email crooks swindle woman out of $150K from home sale ⚠

She sent her bank account details three times, she said. Unfortunately, they wound up in crooks' hands, and her money wound up in their pockets.

πŸ“– Read

via "Naked Security".
πŸ•΄ Simulating Lateral Attacks Through Email πŸ•΄

A skilled attacker can get inside your company by abusing common email applications. Here are three strategies to block them.

πŸ“– Read

via "Dark Reading: ".
❌ Cyber-Jackpot: 773M Credentials Dumped on the Dark Web ❌

Thousands of individual breaches make up the database, one of the largest troves of stolen credentials ever seen.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ” Malware can now evade cloud security tools, as cybercriminals target public cloud users πŸ”

Refined malware payloads from Chinese threat actor Rocke Group are sidestepping security tools to install cryptocurrency miners on cloud systems.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2017-2411 (iphone_os)

In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-13889 (mac_os_x)

In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-13888 (iphone_os)

In iOS before 11.2, a type confusion issue was addressed with improved memory handling.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-7576 (iphone_os)

In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 'We Want IoT Security Regulation,' Say 95% of IT Decision-Makers πŸ•΄

New global survey shows businesses are valuing IoT security more highly, but they are still challenged by IoT data visibility and privacy.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-13891 (iphone_os)

In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-4642 (apple_tv, iphone_os, mac_os)

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.

πŸ“– Read

via "National Vulnerability Database".
πŸ” ​4 ways to prepare for GDPR and similar privacy regulations πŸ”

Data privacy is no longer a nice-to-have security commodity, but a must-have commodity.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to connect to VNC using SSH πŸ”

If your network doesn't allow connections into the default VNC port 5901, you can tunnel it through SSH.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2016-4644 (apple_tv, iphone_os, mac_os)

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Over 87GB of email addresses and passwords exposed in Collection 1 dump πŸ”

An 87GB dump of email addresses and passwords containing almost 773 million unique addresses and just under 22 million unique passwords has been found.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The Security Perimeter Is Dead; Long Live the New Endpoint Perimeter πŸ•΄

The network no longer provides an air gap against external threats, but access devices can take up the slack.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Go Hands-On with New Security Tricks at Black Hat Asia πŸ•΄

Get up close and personal with the latest tools and techniques for testing (and breaking) everything from HTTPS to deep neural networks to Microsoft Office!

πŸ“– Read

via "Dark Reading: ".
❌ Apple CEO Demands Federal Data Privacy Legislation ❌

Apple CEO Tim Cook has called on the government to double down on data privacy regulation in 2019.

πŸ“– Read

via "Threatpost | The first stop for security news".