πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Silence Group Quietly Emerges as New Threat to Banks πŸ•΄

Though only two members strong, hackers pose a credible threat to banks in Russia and multiple countries.

πŸ“– Read

via "Dark Reading".
❌ OilRig Sends an OopsIE to Mideast Government Targets ❌

The Iran-linked group is using a variant of the data-exfiltration OopsIE trojan to attack a Mideast government entity.

πŸ“– Read

via "The first stop for security news | Threatpost".
πŸ•΄ PowerPool Malware Uses Windows Zero-Day Posted on Twitter πŸ•΄

Researchers detected the vulnerability in an attack campaign two days after it was posted on social media.

πŸ“– Read

via "Dark Reading ".
ATENTIONβ€Ό New - CVE-2015-9266

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 7 Ways Blockchain is Being Used for Security πŸ•΄

Blockchain is being used as a security tool. If you haven't thought about adopting it, you might want to reconsider your take.

πŸ“– Read

via "Dark Reading: ".
⚠ Ungagged Google warns users about FBI accessing their accounts ⚠

Some of those who received the letters conjecture that it may be because they purchased the LuminosityLink RAT.

πŸ“– Read

via "Naked Security".
⚠ Thousands of unsecured 3D printers discovered online ⚠

With access control disabled, other people could download previous print files, or even maliciously damage the printer.

πŸ“– Read

via "Naked Security".
❌ High-Severity Flaws in Cisco Secure Internet Gateway Service Patched ❌

The two bugs were disclosed Wednesday in Cisco Umbrella, the tech giant's cloud-based security service.

πŸ“– Read

via "The first stop for security news | Threatpost ".
⚠ Social Security numbers exposed on US government transparency site ⚠

The US government exposed dozens of people's’ personal details, including social security numbers, due to an online mishap on a public transparency portal.

πŸ“– Read

via "Naked Security".
⚠ Mobile spyware maker mSpy leaks millions of records – AGAIN ⚠

The irony: Parents put it on kids' phones to protect them, but this breach exposed sensitive data including Whatsapp and Facebook messages.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2017-1000600

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

πŸ“– Read

via "National Vulnerability Database".
❌ Mozilla’s Release of Firefox 62 Packs Nine Fixes ❌

The slew of fixes address a critical vulnerability that could enable memory corruption.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ Understanding & Solving the Information-Sharing Challenge πŸ•΄

Why cybersecurity threat feeds from intel-sharing groups diminish in value and become just another source of noise. (And what to do about it.)

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US to Charge North Korea for Sony Breach, WannaCry πŸ•΄

The DoJ plans to charge North Korean threat actors for their involvement in two major cyberattacks, US officials report.

πŸ“– Read

via "Dark Reading: ".
❌ Active Spy Campaign Exploits Unpatched Windows Zero-Day ❌

The PowerPool gang launched its attack just two days after the zero-day in the Windows Task Scheduler was disclosed.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ The SOC Gets a Makeover πŸ•΄

Today's security operations center is all about reducing the number of alerts with emerging technologies - and enhancing old-school human collaboration. Here's how some real-world SOCs are evolving.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why a Healthy Data Diet Is the Secret to Healthy Security πŸ•΄

In the same way that food is fuel to our bodies, data is the fuel on which our security programs run. Here are 10 action items to put on your cybersecurity menu.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Report: Data Breaches Hit Share Prices, Too πŸ•΄

A data breach has a measurable impact on stock price, according to a report looking at incidents from the past six years

πŸ“– Read

via "Dark Reading: ".