πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ New Attacks Target Recent PHP Framework Vulnerability πŸ•΄

Multiple threat actors are using relatively simple techniques to take advantage of the vulnerability, launching cryptominers, skimmers, and other malware payloads.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-4643 (apple_tv, iphone_os, mac_os)

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Launches New Azure DevOps Bug Bounty Program πŸ•΄

A new program will pay bounties of up to $20,000 for new critical bugs in the company's Azure DevOps systems and services.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Facebook Shuts Hundreds of Russia-Linked Pages, Accounts for Disinformation πŸ•΄

Facebook says the accounts and pages were part of two unrelated disinformation operations aimed at targets outside the US.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Launches Azure DevOps Bug Bounty Program ❌

Microsoft is offering rewards of up to $20,000 for flaws in its Azure DevOps online services and the latest release of the Azure DevOps server.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ 773 Million Email Addresses, 21 Million Passwords For Sale on Hacker Forum πŸ•΄

Data appears to be from multiple breaches over past few years, says researcher who discovered it.

πŸ“– Read

via "Dark Reading: ".
⚠ YouTube bans dangerous and harmful pranks and challenges ⚠

The platform can't keep us from driving while blindfolded, but at least it can remove videos that glorify our more brainless moments.

πŸ“– Read

via "Naked Security".
⚠ Ep. 015 – USB anti-hacking, bypassing 2FA and government insecurity [PODCAST] ⚠

Here's the latest Naked Security podcast - enjoy!

πŸ“– Read

via "Naked Security".
⚠ Did you know you can see the ad boxes Facebook sorts us into? ⚠

...or that they can edit the (often inaccurate) pigeon-holes Facebook likes to put us in, a study found.

πŸ“– Read

via "Naked Security".
⚠ Google cracks down on access to your Android phone and SMS data ⚠

Android apps that want access to your call and SMS data now have to pass muster with Google's team of reviewers.

πŸ“– Read

via "Naked Security".
⚠ Vast data-berg washes up 1.16 billion pwned records ⚠

Have I Been Pwned? (HIBP) has revealed a huge cache of breached email addresses and passwords, which it has named Collection #1.

πŸ“– Read

via "Naked Security".
πŸ” Microsoft launches Azure DevOps bug bounty program, $20,000 rewards on offer πŸ”

The Redmond giant is keenly interested in remote code execution and privilege escalation flaws.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 8 Tips for Monitoring Cloud Security πŸ•΄

Cloud security experts weigh in with the practices and tools they prefer to monitor and measure security metrics in the cloud.

πŸ“– Read

via "Dark Reading: ".
πŸ” 5 blockchain trends to expect in 2019 πŸ”

Blockchain may finally be ready to move from hype to reality, with continued IoT integrations and tokenization, according to KPMG.

πŸ“– Read

via "Security on TechRepublic".
❌ Twitter Android Glitch Exposed Private Tweets for Years ❌

Twitter has fixed the issue, which has been ongoing since 2014.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ The Rx for HIPAA Compliance in the Cloud πŸ•΄

For medical entities, simply following HIPAA cloud service provider guidelines is no longer enough to ensure that your practice is protected from cyber threats, government investigations, and fines.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ PCI Council Releases New Software Framework for DevOps Era πŸ•΄

The PCI Software Security Framework will eventually replace PCI DA-DSS when it expires in 2022.

πŸ“– Read

via "Dark Reading: ".
πŸ” Bug bounty programs: Everything you thought you knew is wrong πŸ”

One common criticism of bug bounty programs is that very few hackers actually make money. Not only is this untrue, but it misses the point.

πŸ“– Read

via "Security on TechRepublic".