🛡 Cybersecurity & Privacy 🛡 - News
26K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
Microsoft lets Windows users off the update leash

Microsoft has announced some big changes that will finally give Windows users more control over updates and releases.

📖 Read

via "Naked Security".
🕴 Ignore the Insider Threat at Your Peril 🕴

Attacks from insiders often go undiscovered for months or years, so the potential impact can be huge. These 11 countermeasures can mitigate the damage.

📖 Read

via "Dark Reading: ".
Bootstrap supply chain attack is another attempt to poison the barrel

Somebody smuggled something bad into the vast third-party, open-source supply chain we all depend upon.

📖 Read

via "Naked Security".
ATENTION New - CVE-2016-10745

In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

📖 Read

via "National Vulnerability Database".
🔐 How to protect your business from tax fraud 🔐

With the April 15th filing deadline around the corner, cybercriminals are counting on a rushed response to questions to infect potential victims.

📖 Read

via "Security on TechRepublic".
Spam Campaigns Spread TrickBot Malware with Tax Lure

Three recent spam campaigns are pretending to be from ADP and Paychex; in reality, the malicious emails are spreading the TrickBot trojan.

📖 Read

via "Threatpost".
ATENTION New - CVE-2017-7912

Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2014-9186

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code execution. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2014-5436

A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information disclosure. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2014-5435

An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

📖 Read

via "National Vulnerability Database".
🕴 Microsoft Products Under EU Investigation About Data Collection 🕴

A new inquiry aims to determine whether contracts between Microsoft and EU organizations violate GDPR.

📖 Read

via "Dark Reading: ".
🕴 8 Steps to More Effective Small Business Security 🕴

Small business face the same security challenges as large enterprises but with much smaller security teams. Here are 8 things to do to get the most from yours.

📖 Read

via "Dark Reading: ".
New Mirai Samples Grow the Number of Processors Targets

Researchers said that they discovered new Mirai samples in February 2019, capable of infecting devices powered by a broadened range of processors.

📖 Read

via "Threatpost".
TP-Link Routers Vulnerable to Zero-Day Buffer Overflow Attack

Consumer router models allowed authenticated users to take unrestricted remote control over TL-WR940N and TL-WR941ND routers.

📖 Read

via "Threatpost".
🕴 Credential-Stuffing Attacks Behind 30 Billion Login Attempts in 2018 🕴

Using e-mail addresses and passwords from compromised sites, attackers most often targeted retail sites, video-streaming services, and entertainment companies, according to Akamai.

📖 Read

via "Dark Reading: ".
🔏 Introducing the New Digital Guardian Support Community 🔏

Digital Guardian upgraded its Support Community over the weekend to provide an improved user experience, better workflows and ticketing process.

📖 Read

via "Subscriber Blog RSS Feed ".
🕴 'Exodus' iOS Surveillance Software Masqueraded as Legit Apps 🕴

Italian firm appears to have developed spyware for lawful intercept purposes, Lookout says.

📖 Read

via "Dark Reading: ".
🕴 20 Million Dollar Investment Round Shows Growth of Risk Assessment Market 🕴

The Series B investment supports a company bringing risk assessment to businesses in business terms.

📖 Read

via "Dark Reading: ".
🕴 20 Million Dollar Investment Round Shows Growth of Risk Assessment Market 🕴

The Series B investment supports a company bringing risk assessment to businesses in business terms.

📖 Read

via "Dark Reading: ".
🕴 Guilty Plea in Senate Data Theft 🕴

A former senate staff member stole personal information about three senators and published it on Wikipedia.

📖 Read

via "Dark Reading: ".
🕴 'Digital Doppelganger' Underground Takes Payment Card Theft to the Next Level 🕴

Massive criminal marketplace discovered packaging and selling stolen credentials along with victims' online behavior footprints.

📖 Read

via "Dark Reading: ".