πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Thousands of API and cryptographic keys leaking on GitHub every day ⚠

Researchers have found that one of the most popular source code repositories in the world is still housing thousands of publicly accessible user credentials.

πŸ“– Read

via "Naked Security".
πŸ” Hacking Cars For Fun and Profit at Pwn2Own πŸ”

Web browsers, virtualization software, even cars  – nothing was off guards last week at Pwn2Own, the annual hacking competition held each year alongside CanSecWest in Vancouver.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Why site reliability engineers face more security incidents and higher stress levels πŸ”

Half of SREs have worked on outages lasting longer than a day, according to a Catchpoint report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why 61% of CIOs believe employees maliciously leak data πŸ”

One in five employees surveyed believes data belongs to them, not the company, according to an Opinion Matters / Egress report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to stop remote workers from causing a security incident: 3 tips πŸ”

Some 36% of organizations said they experience security breaches due to remote work, according to an OpenVPN report. Here's how to help.

πŸ“– Read

via "Security on TechRepublic".
❌ FEMA Exposes PII for Millions of Hurricane, Wildfire Survivors ❌

The contractor with whom it shared the data has a vulnerable, unpatched network.

πŸ“– Read

via "Threatpost".
πŸ•΄ A Glass Ceiling? Not in Privacy πŸ•΄

According to a new study, female professionals in the US privacy profession outnumber males 53% to 47%.

πŸ“– Read

via "Dark Reading: ".
πŸ” Top 5 business concerns about public cloud applications πŸ”

Some 99% of companies receive direct business value from cloud visibility, according to a Keysight Technologies report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Dark Reading's Kelly Jackson Higgins Honored as Top Cybersecurity Journalist πŸ•΄

In voting conducted by the SANS Institute, Jackson Higgins is named by peers as one of the top 10 journalists in the industry.

πŸ“– Read

via "Dark Reading: ".
❌ Some ASUS Updates Drop Backdoors on PCs in β€˜Operation ShadowHammer’ ❌

The attack appears to be associated with a China-backed APT actor.

πŸ“– Read

via "Threatpost".
πŸ” How to install OpenSSH on Windows 10 to encrypt network communications πŸ”

Learn how to use SSH natively within Windows 10 to secure communications between network devices.

πŸ“– Read

via "Security on TechRepublic".
❌ Bugs in Grandstream Gear Lay Open SMBs to Range of Attacks ❌

Attackers can remotely compromise multiple network devices (IP PBX, conferencing gear and IP phones), installing malware and eavesdropping via video and audio functions.

πŸ“– Read

via "Threatpost".
πŸ•΄ IT Leaders, Employees Divided on Data Security πŸ•΄

Execs and employees have dramatically different ideas of how much information is being lost and why - a gap that puts enterprise data in grave danger.

πŸ“– Read

via "Dark Reading: ".
⚠ Medtronic cardiac implants can be hacked, FDA issues alert ⚠

Two serious flaws in the telemetry protocol could allow a hacker to control vulnerable Implantable Cardioverter Defibrillators (ICDs).

πŸ“– Read

via "Naked Security".
❌ Malware Payloads Hide in Images: Steganography Gets a Reboot ❌

Low-key but effective, steganography is an old-school trick of hiding code within a normal-looking image, where many cybersecurity pros may not think to look.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-9376

ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-9362

ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-3954

Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could issue commands to the pump. Hospira recommends that customers close Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-3953

Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-3952

Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-7510

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

πŸ“– Read

via "National Vulnerability Database".