πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Yahoo Reaches $117.5M Breach Accord Following Failed Settlement πŸ•΄

An adjusted settlement between Yahoo and the victims of its massive data breach is still awaiting approval.

πŸ“– Read

via "Dark Reading: ".
❌ Shadow App Development: Insider Threat or Opportunity? ❌

The challenge for most enterprises is that the demand for software is so high that traditional development teams often can’t keep up.

πŸ“– Read

via "Threatpost".
❌ Samsung Galaxy S10 Fingerprint Sensor Duped With 3D Print ❌

The Samsung Galaxy S10 fingerprint sensor can be fooled in a hack that takes a mere 13 minutes and involves a 3D printed fingerprint.

πŸ“– Read

via "Threatpost".
πŸ•΄ Craigslist Founder Funds Security Toolkit for Journalists, Elections πŸ•΄

The free tools will be developed by the Global Cybersecurity Alliance to monitor election infrastructure and processes in the runup to the 2020 Presidential election.

πŸ“– Read

via "Dark Reading: ".
❌ Adobe Fixes 24 Critical Flaws in Acrobat Reader, Flash, Shockwave Player ❌

During its regularly scheduled April security update, Adobe overall issued 43 patches, including ones for 24 critical vulnerabilities in eight of its products.

πŸ“– Read

via "Threatpost".
πŸ” Accountability the Next Step in Data Protection πŸ”

The UK’s Information Commissioner stressed in a speech on Monday that nearly one year into GDPR, the regulation is at a critical stage.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2017-17544

A privilege escalation vulnerability in Fortinet FortiOS all versions below 6.2.0 allows admin users to elevate their profile to super_admin via restoring modified configurations.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ A New Approach to Application Security Testing πŸ•΄

If the appsec industry were to develop a better AST solution from scratch, what would it look like?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 8 Steps to More Effective Small Business Security πŸ•΄

Small business face the same security challenges as large enterprises but with much smaller security teams. Here are 8 things to do to get the most from yours.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Meet Baldr: The Inside Scoop on a New Stealer πŸ•΄

Baldr first appeared in January and has since evolved to version 2.2 as attackers aim to build a long-lasting threat.

πŸ“– Read

via "Dark Reading: ".
πŸ” Apple's Face ID: Cheat sheet πŸ”

Face ID has replaced Touch ID on the newest iterations of Apple's flagship products. Here's what you need to know about this form of biometric security.

πŸ“– Read

via "Security on TechRepublic".
❌ Intel Patches High-Severity Flaws in Media SDK, Mini PC ❌

Overall Intel patched four vulnerabilities, including high-severity flaws in its Media SDK and Intel NUC mini PC.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-3139

A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-17023

The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle (MITM) or man-on-the-side (MOTS) attacker to execute arbitrary, malicious software on a target user's computer. This is related to SIC_V11.04-64.exe (Sophos), NCP_EntryCl_Windows_x86_1004_31799.exe (NCP), and ncpmon.exe (both Sophos and NCP). The vulnerability exists because: (1) the VPN client requests update metadata over an insecure HTTP connection; and (2) the client software does not check if the software update is signed before running it.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Patch Tuesday Fixes Windows Bugs Under Attack πŸ•΄

The April release of security updates patches 74 vulnerabilities, two of which are being exploited in the wild.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Verizon Patches Trio of Vulnerabilities in Home Router πŸ•΄

One of the flaws gives attackers way to gain root access to devices, Tenable says.

πŸ“– Read

via "Dark Reading: ".
❌ SAS 2019: Meet β€˜TajMahal,’ A New and Highly Advanced APT Framework ❌

A highly sophisticated APT framework has been found targeting a single Central Asian diplomatic entity for years.

πŸ“– Read

via "Threatpost".
❌ SAS 2019: Gaza Cybergang Blends Sophistication Levels in Highly Effective Spy Effort ❌

The SneakyPastes campaign was highly effective but hardly advanced.

πŸ“– Read

via "Threatpost".
πŸ•΄ 'MuddyWater' APT Spotted Attacking Android πŸ•΄

Cyber espionage attack group adds mobile malware to its toolset.

πŸ“– Read

via "Dark Reading: ".
⚠ Two teens charged with jamming school Wi-Fi to get out of exams ⚠

They're facing charges of computer criminal activity after allegedly disrupting the network at the request of their friends.

πŸ“– Read

via "Naked Security".
⚠ Two robocallers fined $3m for Google listings scam ⚠

The robocall scammers were defrauding small businesses who were scared of seeing their Google search listings drop off.

πŸ“– Read

via "Naked Security".