πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Facebook won’t ask for your email password any more ⚠

What's that you say - Facebook was asking for the password to your email account? Yes, sometimes it was.

πŸ“– Read

via "Naked Security".
⚠ Android banking and finance apps’ security found wanting ⚠

A new report claims that mobile finance apps are littered with security bugs.

πŸ“– Read

via "Naked Security".
⚠ Facebook apps expose millions of users’ Facebook data ⚠

Once more unto the breach, dear Facebook Friends of Friends...

πŸ“– Read

via "Naked Security".
πŸ” How to change the default SSH Port on your data center Linux servers πŸ”

Don't let those data center Linux servers use the default SSH port. Gain a bit of a security edge by configuring the daemon to use a non-standard port. Jack Wallen shows you how.

πŸ“– Read

via "Security on TechRepublic".
❌ BEC Scam Gang London Blue Evolves Tactics, Targets ❌

Business email compromise group London Blue is back with evolved email domain spoofing tactics and a newfound interest in targets in Asia.

πŸ“– Read

via "Threatpost".
⚠ Why β€˜PWNED!’ is appearing on some GPS smartwatches ⚠

Over 20 models of smartwatches, some bought for kids, allow for creeps to eavesdrop and track users, in spite of a ban.

πŸ“– Read

via "Naked Security".
❌ Free Cynet Threat Assessment for Mid-sized and Large Organizations ❌

Have your business try Cynet's Free Threat Assessment that checks for malware, C&C connections, data exfiltration, phishing link access, user credential thefts attempts, etc.

πŸ“– Read

via "Threatpost".
πŸ” Businesses beware: Spearphishing attacks aim to change payroll direct deposits πŸ”

Malicious actors are politely asking potential victims to directly deposit money in their accounts, according to a new Vade Security report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ How iOS App Permissions Open Holes for Hackers πŸ•΄

The permissions iOS apps request from users can turn the devices into spy tools and provide a toehold into the enterprise network, according to new research.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to use SSH as a VPN with sshuttle πŸ”

You don't need a VPN server running on a remote host to create a VPN tunnel. With the help of a simple tool, you can create that tunnel with ease.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ True Cybersecurity Means a Proactive Response πŸ•΄

Successful, secure organizations must take an aggressive, pre-emptive posture if they want true data security.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to change the default SSH port on your data center Linux servers πŸ”

Don't let those data center Linux servers use the default SSH port. Gain a bit of a security edge by configuring the daemon to use a non-standard port.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2014-3603

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

πŸ“– Read

via "National Vulnerability Database".
❌ Facebook and Amazon are Locked in a Blame Game Over Leaked Data: Who’s Really To Blame? ❌

After two databases were discovered leaking Facebook data, Facebook and Amazon are both pointing fingers - but researchers say the onus lies on all parties involved as data collection continues to grow.

πŸ“– Read

via "Threatpost".
❌ This Preinstalled Mobile Security App Delivered Vulnerabilities, Not Protection ❌

No. 4 global phone maker, Xiaomi, preinstalled a security app called β€˜Guard Provider’ that had a major flaw.

πŸ“– Read

via "Threatpost".
πŸ•΄ 3 Lessons Security Leaders Can Learn from Theranos πŸ•΄

Theranos flamed out in spectacular fashion, but you can still learn from the company's "worst practices."

πŸ“– Read

via "Dark Reading: ".
πŸ” Collaboration, Actionable Governance Needed to Secure Healthcare Sector πŸ”

Organizations recently responded to a senator who's hoping to develop a strategy for reducing cybersecurity vulnerabilities in the healthcare sector.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Patched Apache Vulnerability Could Still Cause Problems πŸ•΄

More than 2 million Apache HTTP servers remain at risk for a critical privilege escalation vulnerability.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New, Improved BEC Campaigns Target HR and Finance πŸ•΄

Spearphishing campaigns from new and established business email compromise (BEC) gangs are stealing from companies using multiple tactics.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Third Parties in Spotlight as More Facebook Data Leaks πŸ•΄

Two third-party services left Facebook user data exposed online -- in one case, 540 million records of user comments -- highlighting the ease with which third-party developers can access data and the risk of lax security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Threat Group Employs Amazon-Style Fulfillment Model to Distribute Malware πŸ•΄

The operators of the Necurs botnet are using a collection of US-based servers to send out banking Trojans, ransomware, and other malware on behalf of other cybercriminals.

πŸ“– Read

via "Dark Reading: ".