πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-43618 β€Ό

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43620 β€Ό

An issue was discovered in the fruity crate through 0.2.0 for Rust. Security-relevant validation of filename extensions is plausibly affected. Methods of NSString for conversion to a string may return a partial result. Because they call CStr::from_ptr on a pointer to the string buffer, the string is terminated at the first '\0' byte, which might not be the end of the string.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Removing need to unlock mobile wallets for contactless payments has eroded security protections, researchers warn πŸ—“οΈ

Mind the gap

πŸ“– Read

via "The Daily Swig".
πŸ•΄ How Visibility Became the Lifeblood of SecOps and Business Success πŸ•΄

The best way to succeed in the long-term cybersecurity is to invest in visibility because you can't protect or defend against what you can't see.

πŸ“– Read

via "Dark Reading".
🦿 Facebook and Google "listening" is more pervasive than you think 🦿

Yet another consumer is disturbed by the sketchy algorithms deployed by Facebook. Here's how the app knows what you're talking about and what to do about it.

πŸ“– Read

via "Tech Republic".
🦿 Malicious shopping websites surge in number in advance of Black Friday 🦿

More than 5,300 malicious websites have popped up each week, the highest since the start of 2021, says Check Point Research.

πŸ“– Read

via "Tech Republic".
πŸ—“οΈ Vulnerability in FBI email infrastructure allowed malicious actor to send false cyber-attack warnings to thousands πŸ—“οΈ

Security issue saw fake emails sent from legitimate agency accounts

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Microsoft fixes reflected XSS in Exchange Server πŸ—“οΈ

Researchers’ bid to reproduce ProxyShell yields something entirely new

πŸ“– Read

via "The Daily Swig".
❌ FBI Says Its System Was Exploited to Email Fake Cyberattack Alert ❌

The alert was mumbo jumbo, but it was indeed sent from the bureau's email system, from the agency’s own internet address.

πŸ“– Read

via "Threat Post".
πŸ•΄ JupiterOne and Cisco Announce Launch of Secure Cloud Insights πŸ•΄

The partnership is designed to provide businesses with a range of cybersecurity services.

πŸ“– Read

via "Dark Reading".
🦿 Don't fall for LinkedIn phishing: How to watch for this credential-stealing attack 🦿

Cybercriminals are now using LinkedIn to find a way into your files. Learn how to detect phishing on LinkedIn and protect yourself from it.

πŸ“– Read

via "Tech Republic".
πŸ•΄ How to Negotiate With Ransomware Attackers πŸ•΄

Security researchers investigate the ransom negotiation process to create strategies businesses can use if they face an attack.

πŸ“– Read

via "Dark Reading".
🦿 How organizations are beefing up their cybersecurity to combat ransomware 🦿

Most organizations surveyed by Hitachi ID are moving partly to software-as-a-service. Less than half have adopted a Zero Trust strategy.

πŸ“– Read

via "Tech Republic".
❌ Cybercriminals Target Alibaba Cloud for Cryptomining, Malware ❌

Cybercriminals are targeting Alibaba Elastic Computing Service (ECS) instances, disabling certain security features to further their cryptomining goals. Alibaba offers a few unique options that make it a highly attractive target for attackers, researchers noted. According to research from Trend Micro, the Chinese giant’s cloud (also known as Aliyun) has a preinstalled security agent. While […]

πŸ“– Read

via "Threat Post".
πŸ” FTC Updates Safeguards Rule for Consumer Financial Information πŸ”

The FTC recently made changes to the Gramm-Leach-Bliley Act’s Safeguards Rule that should pose further privacy obligations to covered financial institutions.

πŸ“– Read

via "".
❌ High-Severity Intel Processor Bug Exposes Encryption Keys ❌

CVE-2021-0146, arising from a debugging functionality with excessive privileges, allows attackers to read encrypted files.

πŸ“– Read

via "Threat Post".
πŸ•΄ Name That Toon: Cubicle for Four πŸ•΄

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
❌ The Best Ransomware Response, According to the Data  ❌

An analysis of ransomware attack negotiation-data offers best practices.

πŸ“– Read

via "Threat Post".
πŸ•΄ FBI Attributes Abuse of Its Email Account to Software 'Misconfiguration' πŸ•΄

A wave of phony emails from an FBI mail server originated from an issue with the agency's Law Enforcement Enterprise Portal.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Norton Special Report Reveals Nearly 1 in 2 Gamers Have Experienced a Cyberattack πŸ•΄

Three in four say they were impacted financially as a result, losing more than $700 on average.

πŸ“– Read

via "Dark Reading".
🦿 Cybersecurity is a growing field that can benefit from hiring veterans 🦿

There is a real need for "boots-on-the-ground" cybersecurity professionals, so why not tap into a pool of trained and motivated veterans?

πŸ“– Read

via "Tech Republic".