πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Tim Cook demands a way for users to delete their personal data ⚠

The Apple CEO wants the FTC to set up a data-broker clearinghouse so people can see the data that companies have collected on them.

πŸ“– Read

via "Naked Security".
⚠ State agency exposes 3TB of data, including FBI info and remote logins ⚠

Oklahoma’s Department of Securities (ODS) exposed 3TB of files in plain text containing sensitive data on the public internet this month.

πŸ“– Read

via "Naked Security".
⚠ Attackers used a LinkedIn job ad and Skype call to breach bank’s defences ⚠

A Chilean Senator has taken to Twitter with alarming news – the company running the country’s ATM network suffered a serious cyberattack.

πŸ“– Read

via "Naked Security".
⚠ Twitter bug exposed some Android private tweets to public view ⚠

The latest privacy glitch, which went unnoticed for over four years, may trigger yet another EU privacy probe.

πŸ“– Read

via "Naked Security".
⚠ Is the Ten Year Challenge a Facebook scam??? ⚠

Get a grip.

πŸ“– Read

via "Naked Security".
πŸ•΄ Shadow IT, IaaS & the Security Imperative πŸ•΄

Organizations must strengthen their security posture in cloud environments. That means considering five critical elements about their infrastructure, especially when it operates as an IaaS.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-10739

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.

πŸ“– Read

via "National Vulnerability Database".
⚠ WhatsApp fights the spread of deadly fake news with recipient limit ⚠

WhatsApp has capped the number of people you can forward messages to, after India was seized by rumour-inspired mob lynchings.

πŸ“– Read

via "Naked Security".
⚠ DNC targeted by Russian hackers beyond 2018 midterms, it claims ⚠

The Democratic National Committee has filed a civil complaint accusing Russia of trying to hack its computers as recently as November 2018.

πŸ“– Read

via "Naked Security".
⚠ Bicycle-riding hitman convicted with Garmin GPS watch location data ⚠

Location data extracted from the athletic hitman's Garmin GPS watch and TomTom sat nav led to his conviction in two gangland murders.

πŸ“– Read

via "Naked Security".
⚠ Rogue websites can turn vulnerable browser extensions into back doors ⚠

A researcher has found that websites can use some extensions to bypass security policies, execute code, and even install other extensions.

πŸ“– Read

via "Naked Security".
πŸ” Rushing to patch? Here's how to prioritize your security efforts πŸ”

When addressing security vulnerabilities, enterprises should focus on those with publicly available exploit code, according to a Kenna Security report.

πŸ“– Read

via "Security on TechRepublic".
❌ Adobe Issues Unscheduled Updates for Experience Manager Platform ❌

The patches are part of Adobe's second unscheduled update this month.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ How Cybercriminals Clean Their Dirty Money πŸ•΄

By using a combination of new cryptocurrencies and peer-to-peer marketplaces, cybercriminals are laundering up to an estimated $200 billion in ill-gotten gains a year. And that's just the beginning.

πŸ“– Read

via "Dark Reading: ".
πŸ” Hackers turn to data theft and resale on the Dark Web for higher payouts πŸ”

Selling personal information and compromised accounts of popular Instragram users has become more lucrative than ransomware and cryptojacking campaigns.

πŸ“– Read

via "Security on TechRepublic".
❌ Google Fined $57M in Largest GDPR Slap Yet ❌

The French Data Protection Authority (DPA) found a lack of transparency when it comes to how Google harvests and uses personal data for ad-targeting purposes.

πŸ“– Read

via "Threatpost | The first stop for security news".
ATENTIONβ€Ό New - CVE-2017-6923

In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is mitigated if you have access restrictions on the view. It is best practice to always include some form of access restrictions on all views, even if you are using another module to display them.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6922

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Google Hit With $57 Million GDPR Fine in France πŸ•΄

The fine represents the first major penalty for a US technology company under the new European regulations.

πŸ“– Read

via "Dark Reading: ".
❌ How Web Apps Can Turn Browser Extensions Into Backdoors ❌

Researchers show how rogue web applications can be used to attack vulnerable browser extensions in a hack that gives adversaries access to private user data.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Real-World Threats That Trump Spectre & Meltdown πŸ•΄

New side-channel attacks are getting lots of attention, but other more serious threats should top your list of threats.

πŸ“– Read

via "Dark Reading: ".