πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Toyota Customer Information Exposed in Data Breach πŸ•΄

The attackers hit dealer sales systems in Japan, according to the automaker.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ NDSU Offers Nation's First Ph.D. in Cybersecurity Education πŸ•΄

The new program focuses on training university-level educators in cybersecurity.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Bug in Cisco WebEx Browser Extensions Allows Remote Code-Execution ❌

Users of the conferencing platform should update immediately.

πŸ“– Read

via "Threatpost".
❌ Undocumented Intel VISA Tech Can Be Abused, Researchers Allege ❌

Researchers at Black Hat Asia said that Intel VISA, an undocumented testing tool, can be abused using previously-disclosed vulnerabilities.

πŸ“– Read

via "Threatpost".
πŸ” Use a password to secure access to an Excel workbook πŸ”

At the file level, you can password protect an Excel workbook in two ways: You can determine who can get in and who can save changes.

πŸ“– Read

via "Security on TechRepublic".
❌ Medical Weed Dispensary Exposes Health Data for Thousands ❌

As to how the breach happened, the company is so far keeping details tightly rolled up.

πŸ“– Read

via "Threatpost".
πŸ” Blockchain: Top 4 challenges CIOs face πŸ”

With hype around blockchain fading, organizations are starting to seek out use cases for the technology, according to Gartner.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2014-7198

OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 21 stories of the week ⚠

From the Android bloatware selling your data to the hoards of security keys on GitHub, and everything in between. It's the weekly roundup.

πŸ“– Read

via "Naked Security".
⚠ Politicians mistakenly vote the wrong way in controversial internet law ⚠

Members of the European Parliament appear to have materially affected the future of the internet by mistakenly voting the wrong way.

πŸ“– Read

via "Naked Security".
⚠ Top-secret defense document hoarder Harold Martin pleads guilty ⚠

Martin admitted that for more than 20 years, he stole and a vast quantity of highly classified information, stashing it in his home and car.

πŸ“– Read

via "Naked Security".
⚠ Microsoft slaps down 99 APT35/Charming Kitten domains ⚠

Court order in hand, Microsoft seized control of the hacker group's (which it calls Phosphorous) phishing sites.

πŸ“– Read

via "Naked Security".
⚠ Russia accused of massive GPS spoofing campaign ⚠

Russia has been hijacking signals sent by Global Navigation Satellite Systems (GNSS) systems such as GPS, researchers claim.

πŸ“– Read

via "Naked Security".
πŸ” Blockchain: Top 4 challenges CIOs face πŸ”

With hype around blockchain fading, organizations are starting to seek out use cases for the technology, according to Gartner.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ In the Race Toward Mobile Banking, Don't Forget Risk Management πŸ•΄

The rise of mobile banking and payment services has sparked widespread adoption, making a focus on risk essential.

πŸ“– Read

via "Dark Reading: ".
❌ Google Play Boots Italian Spyware Apps That Infected Hundreds ❌

Google Play has removed 25 malicious apps that were downloading spyware, dubbed Exodus, onto victims' phones.

πŸ“– Read

via "Threatpost".
❌ ThreatList: Game of Thrones, a Top Malware Conduit for Cybercriminals ❌

As Game of Thrones' eighth season gets ready to kick off, a new report says the popular TV show accounted for 17 percent of all infected pirated content in the last year.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-16775

Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-16774

Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps ❌

Google said in 2018 it tracked a rise in the number of potentially harmful apps found on Android devices that were either pre-installed or delivered via over-the-air updates.

πŸ“– Read

via "Threatpost".
πŸ” Effectiveness of Identity Theft Services Limited πŸ”

A congressional watchdog is reiterating its findings that identity theft services are rarely efficient at mitigating data breach risks.

πŸ“– Read

via "Subscriber Blog RSS Feed ".