πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ ASUS 'ShadowHammer' Attack Underscores Trusted Third-Party Risks πŸ•΄

Taiwanese computer maker says it has fixed issue that allowed attackers to distribute malware via company's automatic software update mechanism.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Russia Regularly Spoofs Regional GPS πŸ•΄

The nation is a pioneer in spoofing and blocking satellite navigation signals, causing more than 9,800 incidents in the past three years, according to an analysis of navigational data.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-10744

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

πŸ“– Read

via "National Vulnerability Database".
⚠ DragonEx exchange hacked, smoking ashes being raked over ⚠

β€œPart” of its assets have been retrieved, and they've got an address for a suddenly much plumper Bittrex wallet.

πŸ“– Read

via "Naked Security".
⚠ Preinstalled Android apps are harvesting and sharing your data ⚠

New research reveals that the bloatware preinstalled on many new Android phones could do far more than simply chew up your storage.

πŸ“– Read

via "Naked Security".
❌ Ransomware Behind Norsk Hydro Attack Takes On Wiper-Like Capabilities ❌

Researchers are still looking for answers when it comes to LockerGoga's initial infection method - and what the attackers behind the ransomware really want.

πŸ“– Read

via "Threatpost".
πŸ” 6 things keeping IoT pros up at night πŸ”

Implementation and security are the top concerns among professionals involved in the Internet of Things, according to a survey from the organizers of IoT World 2019.

πŸ“– Read

via "Security on TechRepublic".
πŸ” 3 security threats businesses need to prepare for by 2021 πŸ”

IoT and digital transformation efforts will leave more businesses vulnerable to cyberattack, according to Information Security Forum.

πŸ“– Read

via "Security on TechRepublic".
⚠ Facebook’s Whitehat Settings lets bug-hunters dial back app security ⚠

The "Whitehat" settings will help researchers to analyze network traffic from its mobile apps by dialling back security settings.

πŸ“– Read

via "Naked Security".
πŸ•΄ The 'Twitterverse' Is Not the Security Community πŸ•΄

The drama on social media belies the incredible role models, job, training, and networking opportunities found in the real world of traditional cybersecurity.

πŸ“– Read

via "Dark Reading: ".
⚠ Ep. 025 – Business Email Compromise and IoT surprises [PODCAST] ⚠

Here's our latest podcast - listen now!

πŸ“– Read

via "Naked Security".
❌ Cybercriminals Have a Heyday with WinRAR Bug in Fresh Campaigns ❌

With new attacks on the Israeli military and social-work educators, exploitation of the 19-year-old flaw shows no signs of slowing down.

πŸ“– Read

via "Threatpost".
❌ Gamers Beware: Nvidia Fixes High-Severity GeForce Experience Bug ❌

Versions of GeForce Experience for Windows before 3.18 are open to a bug that can allow denial of service and remote code execution.

πŸ“– Read

via "Threatpost".
πŸ•΄ GAO Finds Deficiencies in Systems for Handling National Debt πŸ•΄

IT systems at the Bureau of the Fiscal Service and the Federal Reserve Bank show vulnerabilities that could lead them open to exploitation and breach.

πŸ“– Read

via "Dark Reading: ".
❌ Grindr Poses National Security Risk, U.S. Gov Says ❌

According to a report, Grindr's Chinese owners are selling the platform after concerns were raised about user data handling.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-2752

A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19. HP has no access to customer data as a result of this issue.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-2748

A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app. HP has no access to customer data as a result of this issue.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18364

phpFK lite has XSS via the faq.php, members.php, or search.php query string or the user.php user parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Threat Hunting 101: Not Mission Impossible for the Resource-Challenged πŸ•΄

How small and medium-sized businesses can leverage native features of the operating system and freely available, high-quality hunting resources to overcome financial limitations.

πŸ“– Read

via "Dark Reading: ".
πŸ” Breaking Down Singapore's New Data Protection Trustmark Certification πŸ”

A new certification, launched by a division of the country's government this week, is designed to help organizations demonstrate "accountable and responsible data protection practices."

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ 87% of Cloud Pros Say Visibility Masks Security πŸ•΄

The majority of cloud IT professionals find a direct link between network visibility and business value, new data shows.

πŸ“– Read

via "Dark Reading: ".