πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2014-7198

OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 21 stories of the week ⚠

From the Android bloatware selling your data to the hoards of security keys on GitHub, and everything in between. It's the weekly roundup.

πŸ“– Read

via "Naked Security".
⚠ Politicians mistakenly vote the wrong way in controversial internet law ⚠

Members of the European Parliament appear to have materially affected the future of the internet by mistakenly voting the wrong way.

πŸ“– Read

via "Naked Security".
⚠ Top-secret defense document hoarder Harold Martin pleads guilty ⚠

Martin admitted that for more than 20 years, he stole and a vast quantity of highly classified information, stashing it in his home and car.

πŸ“– Read

via "Naked Security".
⚠ Microsoft slaps down 99 APT35/Charming Kitten domains ⚠

Court order in hand, Microsoft seized control of the hacker group's (which it calls Phosphorous) phishing sites.

πŸ“– Read

via "Naked Security".
⚠ Russia accused of massive GPS spoofing campaign ⚠

Russia has been hijacking signals sent by Global Navigation Satellite Systems (GNSS) systems such as GPS, researchers claim.

πŸ“– Read

via "Naked Security".
πŸ” Blockchain: Top 4 challenges CIOs face πŸ”

With hype around blockchain fading, organizations are starting to seek out use cases for the technology, according to Gartner.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ In the Race Toward Mobile Banking, Don't Forget Risk Management πŸ•΄

The rise of mobile banking and payment services has sparked widespread adoption, making a focus on risk essential.

πŸ“– Read

via "Dark Reading: ".
❌ Google Play Boots Italian Spyware Apps That Infected Hundreds ❌

Google Play has removed 25 malicious apps that were downloading spyware, dubbed Exodus, onto victims' phones.

πŸ“– Read

via "Threatpost".
❌ ThreatList: Game of Thrones, a Top Malware Conduit for Cybercriminals ❌

As Game of Thrones' eighth season gets ready to kick off, a new report says the popular TV show accounted for 17 percent of all infected pirated content in the last year.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-16775

Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-16774

Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps ❌

Google said in 2018 it tracked a rise in the number of potentially harmful apps found on Android devices that were either pre-installed or delivered via over-the-air updates.

πŸ“– Read

via "Threatpost".
πŸ” Effectiveness of Identity Theft Services Limited πŸ”

A congressional watchdog is reiterating its findings that identity theft services are rarely efficient at mitigating data breach risks.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ ShadowHammer Shows Supply Chain Risks πŸ•΄

Trusted relationships can become critical risks when suppliers' systems are breached.

πŸ“– Read

via "Dark Reading: ".
❌ March Madness Scams Give Attackers Fast Break ❌

Researchers have seen March Madness-related phishing scams, fake domains and adware spike as cybercriminals take a pass at tournament viewers.

πŸ“– Read

via "Threatpost".
πŸ•΄ ShadowHammer Shows Supply Chain Risks πŸ•΄

Trusted relationships can become critical risks when suppliers' systems are breached.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to install and use Firefox Lockbox πŸ”

Firefox Lockbox allows you to easily view your saved Firefox passwords and is a viable tool for certain users.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Restaurant Chains Hit in PoS Attack πŸ•΄

Buca di Beppo, Earl of Sandwich, and Planet Hollywood were among the chains hit in a nearly year-long breach of their point-of-sale systems.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-8023

EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated remote attacker could send arbitrary commands via RPC service to be executed on the host system with the privileges of the nsrexecd service, which runs with administrative privileges.

πŸ“– Read

via "National Vulnerability Database".