πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Critical Vulnerability Found in Cisco Video Surveillance Manager ❌

Cisco has patched vulnerability in its video surveillance manager software that could give an unauthenticated, remote attacker the ability to execute arbitrary commands on targeted systems.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ” ProTip: Automate setting a firmware password on Apple computers πŸ”

Securing Mac computers means more than just protecting the data. Limiting the ways a user can gain access to a device--including bypassing the existing OS or resetting account passwords is easily enabled with a simple command.

πŸ“– Read

via "Security on TechRepublic".
❌ Podcast: Two Billion IoT Devices Still Vulnerable to BlueBorne Bug ❌

Up to two billion devices are still vulnerable to the BlueBorne IoT attack - and may not ever get a patch.

πŸ“– Read

via "The first stop for security news | Threatpost ".
⚠ Monday review – the hot 19 stories of the week ⚠

From iOS security updates to Netflix phishing attacks, catch up with everything we've written in the last seven days - it's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ iTunes is assigning you a β€˜trust score’ based on emails and phone calls ⚠

It's just a number to detect fraud, not a Black Mirror-esque score that's going to rate us all as social misfits unworthy of wedding invitations.

πŸ“– Read

via "Naked Security".
⚠ Police accidentally tweet bookmarks that reveal surveilled groups ⚠

The Massachusetts State Police (MSP) accidentally spilled some of its opsec onto Twitter last week, uploading a screenshot that revealed browser bookmarks.

πŸ“– Read

via "Naked Security".
⚠ App developers are STILL allowed to read your Gmails ⚠

Google is still allowing third-party developers access to access its users’ Gmail data, it said in a letter to Senators last week.

πŸ“– Read

via "Naked Security".
⚠ Facebook faces sanctions if it drags its feet on data transparency ⚠

The EU justice commissioner said she's out of patience. Also, she quit Facebook because it's a "channel of dirt."

πŸ“– Read

via "Naked Security".
⚠ Bankrupt NCIX customer data resold on Craigslist ⚠

What happens to sensitive customer data when a large company that has collected it over many years suddenly goes bust?

πŸ“– Read

via "Naked Security".
πŸ” Will Microsoft finally kill the password with its Authenticator upgrade? πŸ”

Microsoft has extended its support for passwordless login using the app to the hundreds of thousands of Azure Active Directory-connected apps used by business, one of a series of security improvements announced at Ignite.

πŸ“– Read

via "Security on TechRepublic".
❌ Tricky DoS Attack Crashes Mozilla Firefox ❌

There are currently no mitigations for the Firefox attack, a researcher told Threatpost.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ” Cisco: We've killed another critical hard-coded root password bug, patch urgently πŸ”

This time a 9.8/10-severity hardcoded password has been found in Cisco's video surveillance software.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Hacking Back: Simply a Bad Idea πŸ•΄

While the concept may sound appealing, it's rife with drawbacks and dangers.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 'Scan4Yyou' Operator Gets 14-Year Sentence πŸ•΄

A citizen of the former USSR is sentenced to 168 months for running Scan4you, an online counter antivirus service.

πŸ“– Read

via "Dark Reading: ".
❌ Assessing the Human Element in Cyber Risk Analysis ❌

The human factor doesn't have to be an intangible when assessing cyber risks within a company.

πŸ“– Read

via "The first stop for security news | Threatpost ".
❌ Google’s Forced Sign-in to Chrome Raises Privacy Red Flags ❌

Chrome users are now automatically signed into the browser if they're signed into any other Google service, such as Gmail.

πŸ“– Read

via "The first stop for security news | Threatpost ".
❌ Adwind RAT Scurries By AV Software With New DDE Variant ❌

The spam campaign mostly targets victims in Turkey and Germany.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ 6 Dark Web Pricing Trends πŸ•΄

For cybercriminals, the Dark Web grows more profitable every day.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Deletes Passwords for Azure Active Directory Applications πŸ•΄

At Ignite 2018, security took center stage as Microsoft rolled out new security services and promised an end to passwords for online apps.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-8298

Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.

πŸ“– Read

via "National Vulnerability Database".
❌ Cybercriminals Target Kodi Media Player for Malware Distribution ❌

A recent cryptomining campaign shows criminal ingenuity.

πŸ“– Read

via "The first stop for security news | Threatpost ".