πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Have tech companies taken two-factor authentication too far? πŸ”

Apple is facing a lawsuit from a user claiming that two-factor authentication is a "waste of their personal time." Here's why businesses shouldn't ignore the security measure.

πŸ“– Read

via "Security on TechRepublic".
❌ Xiaomi M365 Electric Scooter Hacked and Remotely Controlled ❌

Hackers up to 100 meters away could take over Xiaomi M365 scooters to brake or accelerate them.

πŸ“– Read

via "Threatpost | The first stop for security news".
❌ Major Container Security Flaw Threatens Cascading Attacks ❌

A fundamental component of container technologies like Docker, cri-o, containerd and Kubernetes contains an important vulnerability that could cause cascading attacks.

πŸ“– Read

via "Threatpost | The first stop for security news".
❌ Attackers Completely Destroy VFEmail’s Secure Mail Infrastructure ❌

"Every file server is lost, every backup server is lost.”

πŸ“– Read

via "Threatpost | The first stop for security news".
❌ Critical WordPress Plugin Flaw Allows Complete Website Takeover ❌

Users of the popular plugin, Simple Social Buttons, are encouraged to update to version 2.0.22.

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Devastating Cyberattack on Email Provider Destroys 18 Years of Data πŸ•΄

All data belonging to US users-including backup copies-have been deleted in catastrophe, VMEmail says.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Patches Zero-Day Browser Bug Under Active Attack ❌

In its February Patch Tuesday bulletin Microsoft patches four public bugs and one that under active attack.

πŸ“– Read

via "Threatpost | The first stop for security news".
❌ Double-Stuffed: Dunkin’ Hit by Another Credential-Stuffing Attack ❌

Dunkin’ Donuts may have just launched its first double-filled doughnut, but another doubling up is not quite as tasty. The chain has suffered its second credential-stuffing attack in three months. Like the first incident, the attack targeted pastry aficionados that have DD Perks accounts, which is Dunkin’s loyalty program. Names, email addresses, 16-digit DD Perks […]

πŸ“– Read

via "Threatpost | The first stop for security news".
πŸ•΄ Microsoft, Adobe Both Close More Than 70 Security Issues πŸ•΄

With their regularly scheduled Patch Tuesday updates, both companies issued fixes for scores of vulnerabilities in their widely used software.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Up to 100,000 Reported Affected in Landmark White Data Breach πŸ•΄

Australian property valuation firm Landmark White exposed files containing personal data and property valuation details.

πŸ“– Read

via "Dark Reading: ".
❌ Siemens Warns of Critical Remote-Code Execution ICS Flaw ❌

The affected SICAM 230 process control system is used as an integrated energy system for utility companies, and as a monitoring system for smart-grid applications.

πŸ“– Read

via "Threatpost | The first stop for security news".
ATENTIONβ€Ό New - CVE-2017-0938

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.

πŸ“– Read

via "National Vulnerability Database".
⚠ Security firm beats Adobe by patching reader flaw first ⚠

Adobe has patched a flaw that enabled attackers to slurp a user’s network authentication details - but not before someone else patched it first.

πŸ“– Read

via "Naked Security".
⚠ 620 million records from 16 websites listed for sale on the Dark Web ⚠

Some of the breaches are new, while some were reported last year. The sites include MyFitnessPal, MyHeritage, Whitepages and more.

πŸ“– Read

via "Sophos".
πŸ” 4 ways your company can avoid a data breach πŸ”

Only one in three organizations say they are confident they can prevent data breaches, according to Balbix.

πŸ“– Read

via "Security on TechRepublic".
⚠ Ep. 019 – Android holes, iOS screengrabbing and USB poo [PODCAST] ⚠

Here's the latest Naked Security podcast - enjoy!

πŸ“– Read

via "Naked Security".
πŸ” More developers are abusing Apple Developer Enterprise Program to distribute illicit apps πŸ”

Apple has less of an iron grip over iOS than first thought, as organizations are using the Developer Enterprise Program for apps that would not be allowed in the App Store.

πŸ“– Read

via "Security on TechRepublic".
❌ Unpatched Apple macOS Hole Exposes Safari Browsing History ❌

There are no permission dialogues for apps in certain folders for macOS Mojave, which allows a malicious app to spy on browsing histories..

πŸ“– Read

via "Threatpost | The first stop for security news".
❌ β€˜Dirty Sock’ Flaw in snapd Allows Root Access to Linux Servers ❌

The issue affects default installations of Ubuntu Server and Desktop and is likely included in many Ubuntu-like Linux distributions.

πŸ“– Read

via "Threatpost | The first stop for security news".
⚠ Evil USB O.MG Cable opens up Wi-Fi to remote attacks ⚠

... and enables de-authenticaton attacks that could knock targeted systems off the Wi-Fi and onto one of these nefarious cables.

πŸ“– Read

via "Naked Security".