πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Google Spots New Technique to Sneak Malware Past Detection Tools πŸ•΄

The operator behind OpenSUpdater is using a new way to sneak adware and other malware past security tools.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Password Reuse Problems Persist Despite Known Risks πŸ•΄

The vast majority of users worry about compromised passwords, but two-thirds continue to use the same password or a variation, a survey finds.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Who Is BlackMatter? πŸ•΄

Researchers piece together the origins of the group that made headlines this week as the perpetrator behind a ransomware attack on New Cooperative.

πŸ“– Read

via "Dark Reading".
πŸ•΄ What Are the Different Types of Cyber Insurance? πŸ•΄

Even with the best cybersecurity defenses in place, organizations can fall victim to a cyberattack.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Bitcoin.org hack nets giveaway scammers $17,000 overnight πŸ—“οΈ

Open source project back online after fraudsters dangled double-your-money lure

πŸ“– Read

via "The Daily Swig".
❌ Critical Cisco Bugs Allow Code Execution on Wireless, SD-WAN ❌

Unauthenticated cyberattackers can also wreak havoc on networking device configurations.

πŸ“– Read

via "Threat Post".
πŸ•΄ Our Eye Is on the SPARROW πŸ•΄

How unauthorized users can exploit wireless infrastructures for covert communication.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Contrast Application Security Platform Scales to Support OWASP Risks πŸ•΄

Contrast's platform detects and prevents against OWASP Top Ten risks from development to production with out-of-the-box policy rules and automated compliance reporting.

πŸ“– Read

via "Dark Reading".
🦿 10,000 employees at Stanley Black & Decker go passwordless 🦿

Here's how TruU's Passwordless Protection could make hybrid work easier and beef up security in the enterprise.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Meet TruffleHog – a browser extension for finding secret keys in JavaScript code πŸ—“οΈ

API keys are accidentally being leaked by websites. Here’s how to find them

πŸ“– Read

via "The Daily Swig".
⚠ S3 Ep51: OMIGOD a gaping hole, waybill scams, and Face ID hacked [Podcast] ⚠

Latest episode - listen now!

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Developers fix multitude of vulnerabilities in Apache HTTP Server πŸ—“οΈ

High-impact SSRF and request smuggling bugs among flaws addressed in bumper patch cycle

πŸ“– Read

via "The Daily Swig".
❌ TangleBot Malware Reaches Deep into Android Device Functions ❌

The mobile baddie grants itself access to almost everything, enabling spying, data-harvesting, stalking and fraud attacks, among others.

πŸ“– Read

via "Threat Post".
🦿 iOS 15: How to enable Mail Privacy Protection 🦿

Learn how to use the new iOS 15 security feature called Mail Privacy Protection, which can hide your IP address and other tracking data often sent to marketers without your knowledge.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2021-41587 β€Ό

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40099 β€Ό

An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41586 β€Ό

In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40102 β€Ό

An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-40100 β€Ό

An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41588 β€Ό

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ TangleBot Campaign Underscores SMS Threat πŸ•΄

The attack targets Android devices and starts with a malicious SMS message that aims to bring malware onto compromised devices.

πŸ“– Read

via "Dark Reading".
πŸ‘1