πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Hackers Break into System That Houses College Application Data πŸ•΄

More than 900 colleges and universities use Slate, owned by Technolutions, to collect and manage information on applicants.

πŸ“– Read

via "Dark Reading: ".
πŸ” Why you need the Myki Android Password Manager πŸ”

If you're searching for an easy-to-use password manager that doesn't save your data to a third-party server, give Myki a try.

πŸ“– Read

via "Security on TechRepublic".
❌ Google Patches Critical Bluetooth RCE Bug ❌

In all, Google reported 45 bugs in its March update with 11 ranked critical and 33 rated high.

πŸ“– Read

via "Threatpost".
❌ Researcher Claims Iranian APT Behind 6TB Data Heist at Citrix ❌

IRIDIUM is an APT that uses proprietary techniques to bypass two-factor authentication for critical applications, according to security firm Resecurity.

πŸ“– Read

via "Threatpost".
πŸ•΄ 3 Places Security Teams Are Wasting Time πŸ•΄

Dark Reading caught up with RSA Security president Rohit Ghai at the RSA Conference to discuss critical areas where CISOs and their teams are spinning their wheels.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ NSA, DHS Call for Info Sharing Across Public and Private Sectors πŸ•΄

Industry leaders debate how government and businesses can work together on key cybersecurity issues.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cryptominers Remain Top Threat but Coinhive's Exit Could Change That πŸ•΄

Coinhive has remained on top of Check Point Software's global threat index for 15 straight months.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 763M Email Addresses Exposed in Latest Database Misconfiguration Episode πŸ•΄

MongoDB once again used by database admin who opens unencrypted database to the whole world.

πŸ“– Read

via "Dark Reading: ".
πŸ” How SMBs can bolster cybersecurity efforts πŸ”

Learn what experts at a Wall Street Journal forum suggest businesses should do to improve their cybersecurity stance.

πŸ“– Read

via "Security on TechRepublic".
⚠ John Oliver bombards the FCC with anti-robocall robocall campaign ⚠

The Last Week Tonight host launched an anti-robocalling robocalling campaign to force the FCC to put a stop to the pervasive, irritating calls.

πŸ“– Read

via "Naked Security".
⚠ Email list-cleaning site may have leaked up to 2 billion records ⚠

The number of records exposed online by Verification.io email list-cleaning service may be far higher than originally anticipated.

πŸ“– Read

via "Naked Security".
⚠ Citrix admits attackers breached its network – what we know ⚠

On Friday, software giant Citrix issued a short statement admitting that hackers recently managed to get inside its internal network. According to a statement by chief information security officer Stan Black, the company was told of the attack by the FBI on 6 March, since when it had established that attackers had taken β€œbusiness documents” […]

πŸ“– Read

via "Naked Security".
⚠ Study throws security shade on freelance and student programmers ⚠

A recent study shows that if you aren't prepared to ask or pay for security, you probably won't get it.

πŸ“– Read

via "Naked Security".
πŸ” Business PC users are most at risk in these 10 countries πŸ”

Some 11% of US business computers are at risk of malware infection, compared to 20% of home PCs, according to an Avast report.

πŸ“– Read

via "Security on TechRepublic".
⚠ Facebook sues developers over data-scraping quizzes ⚠

Downloaded by 63K users, the quizzes promised answers to questions such as "What kind of dog are you according to your zodiac sign?"

πŸ“– Read

via "Naked Security".
πŸ” 25% of software vulnerabilities remain unpatched for more than a year πŸ”

Smaller organizations are more agile at patching vulnerabilities, and vendor support goes a long way in easing patching, according to a report from Kenna Security and the Cyentia Institute.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The 12 Worst Serverless Security Risks πŸ•΄

A new guide from the Cloud Security Alliance offers mitigations, best practices, and a comparison between traditional applications and their serverless counterparts.

πŸ“– Read

via "Dark Reading: ".
❌ Adobe Patches Critical Photoshop, Digital Edition Flaws ❌

Adobe fixed two arbitrary code execution flaws in its Photoshop and Digital Edition products.

πŸ“– Read

via "Threatpost".
❌ Unpatched Windows Bug Allows Attackers to Spoof Security Dialog Boxes ❌

Microsoft won't be patching the bug, but a proof of concept shows the potential for successful malware implantation.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cybercriminals Think Small to Earn Big πŸ•΄

As the number of breaches increased 424% in 2018, the average breach size shrunk 4.7 times as attackers aimed for smaller, more vulnerable targets.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-17944

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.

πŸ“– Read

via "National Vulnerability Database".