πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2017-15720

In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.

πŸ“– Read

via "National Vulnerability Database".
❌ Malware in Ad-Based Images Targets Mac Users ❌

Researchers detected 191,970 bad ads and estimates that around 1 million users were impacted.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ” Phishing and spearphishing: A cheat sheet for business professionals πŸ”

When criminals use technology to propagate social engineering attacks, securing your organization can become complicated. Here's what you need to know about phishing and spearphishing.

πŸ“– Read

via "Security on TechRepublic".
❌ Redaman Spams Russian Banking Customers with Rotating Tactics ❌

The banking trojan hides its misdeeds with a rotating set of tactics.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ” How to reset local user passwords from the macOS recovery partition πŸ”

Mac admins or users savvy around Terminal can easily reset a password and have the affected account back to work within minutes.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Aging PCs Running Out-of-Date Software Bring Security Worries πŸ•΄

Age is an issue with application languages and frameworks, too.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 'Anatova' Emerges as Potentially Major New Ransomware Threat πŸ•΄

Modular design, ability to infect network shares make the malware dangerous, McAfee says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ DHS Issues Emergency Directive on DNS Security πŸ•΄

All government domain owners are instructed to take immediate steps to strengthen the security of their DNS servers following a successful hacking campaign.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-0187

A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improper handling of confidential information. An attacker could exploit this vulnerability by logging into the web interface on a vulnerable system. An exploit could allow an attacker to obtain confidential information for privileged accounts. This information could then be used to impersonate or negatively impact the privileged account on the affected system.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Hackers impersonate these 10 brands the most in phishing attacks πŸ”

Phishers often spoof major tech brands in their efforts to gain payments from individuals and businesses, according to a Vade Secure report.

πŸ“– Read

via "Security on TechRepublic".
⚠ β€œProceed with caution”: Microsoft browser says Mail Online is untrustworthy ⚠

Hanging up on the fact-checkers probably isn't the best way for a news outlet to assure them that it's trustworthy.

πŸ“– Read

via "Naked Security".
⚠ Update now! Apple releases first 2019 iOS and macOS patches ⚠

Apple has issued its January security updates fixing a list of mostly shared CVE flaws affecting iOS and macOS with a smattering for Safari, watchOS, tvOS, and iCloud for Windows.

πŸ“– Read

via "Naked Security".
πŸ” 3 enterprise cybersecurity trends CISOs must pay attention to πŸ”

With the CISO at the table, organizations must focus on products, processes, and people to stay secure, according to the executive director of the National Cyber Security Alliance.

πŸ“– Read

via "Security on TechRepublic".
⚠ How to stop a hacker home invasion! [VIDEO] ⚠

Did you see the story about the US family whose Nest camera "warned" them of an impending nuclear attack? Here's how to keep hackers out...

πŸ“– Read

via "Naked Security".
⚠ Supreme Court won’t consider case against defamatory reviews on Yelp ⚠

The decision means Yelp, and other platforms, are still protected from liability for user-submitted content under the CDA's Section 230.

πŸ“– Read

via "Naked Security".
⚠ Bomb threat spam may stem from GoDaddy DNS weakness ⚠

A bomb threat spam campaign that hit North America last month may have been engineered using a flaw in GoDaddy’s domain management process, it was revealed this week.

πŸ“– Read

via "Naked Security".
πŸ•΄ Black Hat Asia Offers New IoT Security Tools & Tricks πŸ•΄

Come to Black Hat Asia in March for an expert look at what's happening in the world of Internet of Things, and what you can do to secure it.

πŸ“– Read

via "Dark Reading: ".
πŸ” Photos: The top 10 computer security applications of 2019 πŸ”

These apps will help keep your enterprise safe from malware and other cybersecurity threats.

πŸ“– Read

via "Security on TechRepublic".