πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ Internet Bug Bounty: High severity vulnerability in Apache HTTP Server could lead to RCE πŸ—“οΈ

Buffer overflow flaw should be patched immediately

πŸ“– Read

via "The Daily Swig".
πŸ•΄ 7 Predictions for Global Energy Cybersecurity in 2022 πŸ•΄

Increased digitization makes strong cybersecurity more important than ever.

πŸ“– Read

via "Dark Reading".
❌ Log4J-Related RCE Flaw in H2 Database Earns Critical Rating ❌

Critical flaw in the H2 open-source Java SQL database are similar to the Log4J vulnerability, but do not pose a widespread threat.

πŸ“– Read

via "Threat Post".
πŸ—“οΈ Latest WordPress security release fixes XSS, SQL injection bugs πŸ—“οΈ

Quartet of software flaws addressed ahead of next major release of popular CMS

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Researchers discover Log4j-like flaw in H2 database console πŸ—“οΈ

Impact of JNDI bug mitigated by vulnerable behavior being disabled by default

πŸ“– Read

via "The Daily Swig".
❌ QNAP: Get NAS Devices Off the Internet Now ❌

There are active ransomware and brute-force attacks being launched against internet-exposed, network-attached storage devices, the device maker warned.

πŸ“– Read

via "Threat Post".
⚠ S3 Ep64: Log4Shell again, scammers keeping busy, and Apple Home bug [Podcast + Transcript] ⚠

We're back for 2022 - listen now!

πŸ“– Read

via "Naked Security".
⚠ Log4Shell-like security hole found in popular Java SQL database engine H2 ⚠

"It's Log4Shell, Jim, but not as we know it." How to find and fix a JNDI-based vuln in the H2 Database Engine.

πŸ“– Read

via "Naked Security".
🦿 Norton 360 wants to pay you a pittance to mine Ethereum cryptocurrency 🦿

The new opt-in feature turns your idle PC into a cryptominer, with Norton skimming 15% off the top, plus market fees.

πŸ“– Read

via "Tech Republic".
πŸ•΄ How to Proactively Limit Damage From BlackMatter Ransomware πŸ•΄

Logic flaw exists in malware that can be used to prevent it from encrypting remote shares, security vendor says.

πŸ“– Read

via "Dark Reading".
πŸ” FTC Settles with Financial Firm Following Mortgage File Breach πŸ”

A recently finalized settlement will require the company maintain proper data security safeguards and undergo periodic audits.

πŸ“– Read

via "".
❌ 3.7M FlexBooker Records Dumped on Hacker Forum ❌

Attackers are trading millions of records from a trio of pre-holiday breaches on an online forum.

πŸ“– Read

via "Threat Post".
πŸ” Friday Five 1/7 πŸ”

A scientist pleads guilty to stealing trade secret data, a new proof-of-concept iPhone Trojan, and more - catch up on the infosec news of the week with the Friday Five!

πŸ“– Read

via "".
πŸ“’ The scariest security horror stories of 2021 πŸ“’

A crisis at Microsoft, the ransomware resurgence, and endless zero-days dominated headlines

πŸ“– Read

via "ITPro".
πŸ“’ FTC threatens legal action against companies failing to patch Log4Shell πŸ“’

The agency appears to be cracking down on the widespread security flaw as attack attempts remained high over the holiday period

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft issues out-of-band patch for Windows Server sign-in bug πŸ“’

The flaw, which causes a slow down in the user verification process, needs to be installed manually by IT admins

πŸ“– Read

via "ITPro".
πŸ“’ Morgan Stanley agrees $60 million settlement in data breach lawsuit πŸ“’

The two separate data incidents occurred in 2016 and 2019 and concerned the investment bank's handling of legacy IT equipment

πŸ“– Read

via "ITPro".
πŸ“’ How to fix the Blue Screen of Death (BSOD) error in Windows 11 πŸ“’

Encountering Windows' dreaded BSOD error is never fun, but it's possible to diagnose the problem with a few simple steps

πŸ“– Read

via "ITPro".
πŸ“’ Majority of Americans say ransomware attacks should be considered terrorism πŸ“’

Most also believe it should be made illegal to pay ransoms to hackers

πŸ“– Read

via "ITPro".
πŸ“’ Google Cloud acquires Israeli security startup Siemplify πŸ“’

The SOAR specialist has been described as "the missing piece" for Google's Chronicle platform

πŸ“– Read

via "ITPro".
πŸ“’ Researchers warn of spear-phishing exploit in Google Docs πŸ“’

Hackers have found a way to use Google's comment function to dupe victims into clicking on malicious links

πŸ“– Read

via "ITPro".