πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 2018's Most Common Vulnerabilities Include Issues New and Old πŸ•΄

The most common vulnerabilities seen last year run the gamut from cross-site scripting to issues with CMS platforms.

πŸ“– Read

via "Dark Reading: ".
⚠ Serious Security: What 2000 years of cryptography can teach us ⚠

Here's a fascinating history of cryptography that has plenty to teach you - and you don't need a degree in mathematics to follow along!

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2017-18332

Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18331

Improper access control on secure display buffers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, SDA660

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18160

AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, SD 850

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 23 stories of the week ⚠

From WhatsApps that aren't meant for you to the highly promising USB-C authentication, and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Monday review – the hot 23 stories of the week ⚠

From WhatsApps that aren't meant for you to the highly promising USB-C authentication, and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Monday review – the hot 23 stories of the week ⚠

From WhatsApps that aren't meant for you to the highly promising USB-C authentication, and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Tim Cook demands a way for users to delete their personal data ⚠

The Apple CEO wants the FTC to set up a data-broker clearinghouse so people can see the data that companies have collected on them.

πŸ“– Read

via "Naked Security".
⚠ State agency exposes 3TB of data, including FBI info and remote logins ⚠

Oklahoma’s Department of Securities (ODS) exposed 3TB of files in plain text containing sensitive data on the public internet this month.

πŸ“– Read

via "Naked Security".
⚠ Attackers used a LinkedIn job ad and Skype call to breach bank’s defences ⚠

A Chilean Senator has taken to Twitter with alarming news – the company running the country’s ATM network suffered a serious cyberattack.

πŸ“– Read

via "Naked Security".
⚠ Twitter bug exposed some Android private tweets to public view ⚠

The latest privacy glitch, which went unnoticed for over four years, may trigger yet another EU privacy probe.

πŸ“– Read

via "Naked Security".
⚠ Is the Ten Year Challenge a Facebook scam??? ⚠

Get a grip.

πŸ“– Read

via "Naked Security".
πŸ•΄ Shadow IT, IaaS & the Security Imperative πŸ•΄

Organizations must strengthen their security posture in cloud environments. That means considering five critical elements about their infrastructure, especially when it operates as an IaaS.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-10739

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.

πŸ“– Read

via "National Vulnerability Database".
⚠ WhatsApp fights the spread of deadly fake news with recipient limit ⚠

WhatsApp has capped the number of people you can forward messages to, after India was seized by rumour-inspired mob lynchings.

πŸ“– Read

via "Naked Security".
⚠ DNC targeted by Russian hackers beyond 2018 midterms, it claims ⚠

The Democratic National Committee has filed a civil complaint accusing Russia of trying to hack its computers as recently as November 2018.

πŸ“– Read

via "Naked Security".
⚠ Bicycle-riding hitman convicted with Garmin GPS watch location data ⚠

Location data extracted from the athletic hitman's Garmin GPS watch and TomTom sat nav led to his conviction in two gangland murders.

πŸ“– Read

via "Naked Security".
⚠ Rogue websites can turn vulnerable browser extensions into back doors ⚠

A researcher has found that websites can use some extensions to bypass security policies, execute code, and even install other extensions.

πŸ“– Read

via "Naked Security".
πŸ” Rushing to patch? Here's how to prioritize your security efforts πŸ”

When addressing security vulnerabilities, enterprises should focus on those with publicly available exploit code, according to a Kenna Security report.

πŸ“– Read

via "Security on TechRepublic".
❌ Adobe Issues Unscheduled Updates for Experience Manager Platform ❌

The patches are part of Adobe's second unscheduled update this month.

πŸ“– Read

via "Threatpost | The first stop for security news".