πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 8 Steps to More Effective Small Business Security πŸ•΄

Small business face the same security challenges as large enterprises but with much smaller security teams. Here are 8 things to do to get the most from yours.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Meet Baldr: The Inside Scoop on a New Stealer πŸ•΄

Baldr first appeared in January and has since evolved to version 2.2 as attackers aim to build a long-lasting threat.

πŸ“– Read

via "Dark Reading: ".
πŸ” Apple's Face ID: Cheat sheet πŸ”

Face ID has replaced Touch ID on the newest iterations of Apple's flagship products. Here's what you need to know about this form of biometric security.

πŸ“– Read

via "Security on TechRepublic".
❌ Intel Patches High-Severity Flaws in Media SDK, Mini PC ❌

Overall Intel patched four vulnerabilities, including high-severity flaws in its Media SDK and Intel NUC mini PC.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-3139

A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-17023

The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle (MITM) or man-on-the-side (MOTS) attacker to execute arbitrary, malicious software on a target user's computer. This is related to SIC_V11.04-64.exe (Sophos), NCP_EntryCl_Windows_x86_1004_31799.exe (NCP), and ncpmon.exe (both Sophos and NCP). The vulnerability exists because: (1) the VPN client requests update metadata over an insecure HTTP connection; and (2) the client software does not check if the software update is signed before running it.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Patch Tuesday Fixes Windows Bugs Under Attack πŸ•΄

The April release of security updates patches 74 vulnerabilities, two of which are being exploited in the wild.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Verizon Patches Trio of Vulnerabilities in Home Router πŸ•΄

One of the flaws gives attackers way to gain root access to devices, Tenable says.

πŸ“– Read

via "Dark Reading: ".
❌ SAS 2019: Meet β€˜TajMahal,’ A New and Highly Advanced APT Framework ❌

A highly sophisticated APT framework has been found targeting a single Central Asian diplomatic entity for years.

πŸ“– Read

via "Threatpost".
❌ SAS 2019: Gaza Cybergang Blends Sophistication Levels in Highly Effective Spy Effort ❌

The SneakyPastes campaign was highly effective but hardly advanced.

πŸ“– Read

via "Threatpost".
πŸ•΄ 'MuddyWater' APT Spotted Attacking Android πŸ•΄

Cyber espionage attack group adds mobile malware to its toolset.

πŸ“– Read

via "Dark Reading: ".
⚠ Two teens charged with jamming school Wi-Fi to get out of exams ⚠

They're facing charges of computer criminal activity after allegedly disrupting the network at the request of their friends.

πŸ“– Read

via "Naked Security".
⚠ Two robocallers fined $3m for Google listings scam ⚠

The robocall scammers were defrauding small businesses who were scared of seeing their Google search listings drop off.

πŸ“– Read

via "Naked Security".
⚠ Mar-a-Lago intruder had instant-malware-inflicting thumb drive ⚠

Ms. Zhang's infected USB drive instantly went to work on a Secret Service agent's PC. He shut it down immediately "to halt the corruption."

πŸ“– Read

via "Naked Security".
❌ SAS 2019: Triton ICS Malware Hits A Second Victim ❌

In only the second known attack of the Russia-linked malware, which shut down an oil refinery in 2017, another Mideast target has been hit.

πŸ“– Read

via "Threatpost".
⚠ Update now! Here’s the April Patch Tuesday roundup ⚠

Microsoft and Adobe Patch Tuesday updates are here. Find out more about the most serious bugs and how to patch them.

πŸ“– Read

via "Naked Security".
πŸ” How hotel booking confirmation links can leak personal information to third parties πŸ”

Passing booking information as URL arguments allows third parties to intercept booking information for data collection, according to Symantec.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How Mozilla uses AI to manage Firefox bug reports πŸ”

The company created a homegrown artificial intelligence tool dubbed BugBug to classify and categorize each bug report.

πŸ“– Read

via "Security on TechRepublic".
⚠ Check your Verizon FiOS Quantum Gateway G1100 router now ⚠

Owners of Verizon’s FiOS Quantum Gateway (G1100) routers should check the firmware has been updated after a security company made public three significant security flaws.

πŸ“– Read

via "Naked Security".
⚠ Ep. 027 – Honeypots, GPS rollover and the MySpace data vortex ⚠

Guess how long it takes crooks to find a new device when you plug it in? All this and more in the latest Naked Security podcast- enjoy!

πŸ“– Read

via "Naked Security".
πŸ•΄ Safe Harbor Programs: Ensuring the Bounty Isn't on White Hat Hackers' Heads πŸ•΄

As crowdsourced security-testing surges in popularity, companies need to implement safe harbor provisions to protect good-faith hackers -- and themselves.

πŸ“– Read

via "Dark Reading: ".