πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Ubiquitous Bug Allows HIPAA-Protected Malware to Hide Behind Medical Images ❌

The ubiquitous nature of the flaw opens the door for rapidly spreading, crippling cyberattacks.

πŸ“– Read

via "Threatpost".
πŸ•΄ Tips for the Aftermath of a Cyberattack πŸ•΄

Incident response demands technical expertise, but you can't fully recover without non-IT experts.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ VPN Vulnerabilities Point Out Need for Comprehensive Remote Security πŸ•΄

VPNs are the primary tool for securing remote access, but recently disclosed vulnerabilities point out the weakness of relying on them as the only tool.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Nation-State Hacker Group Hijacking DNS to Redirect Email, Web Traffic πŸ•΄

'Sea Turtle' group has compromised at least 40 national security organizations in 13 countries so far, Cisco Talos says.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-0382

A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not properly clear previously assigned session identifiers for a user session when a user authenticates to the web-based interface. An attacker could exploit this vulnerability by using an existing session identifier to connect to the software through the web-based interface. Successful exploitation could allow the attacker to hijack an authenticated user's browser session on the system. Versions 8.1 and 8.5 are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-0248

A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service (DoS) condition on an affected device. The attacker would need to have valid administrator credentials on the device. This vulnerability is due to incomplete input validation for unexpected configuration options that the attacker could submit while accessing the GUI configuration menus. An attacker could exploit these vulnerabilities by authenticating to the device and submitting crafted user input when using the administrative GUI configuration feature. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Software versions prior to 8.3.150.0, 8.5.140.0, 8.8.111.0 are affected by this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
⚠ Oracle issues nearly 300 patches in quarterly update ⚠

Oracle's latest security update covers 297 vulnerabilities, many of which come with a "patch now" warning.

πŸ“– Read

via "Naked Security".
⚠ Chrome flaw on iOS leads to 500 million unwanted pop-up ads ⚠

If you own an iOS device and use the Chrome browser, you may have encountered some strange-looking pop-up ads in the past week.

πŸ“– Read

via "Naked Security".
⚠ Google plays Whack-A-Mole with naughty Android developers ⚠

Android developers without a track record are going to be submitted to more checks in order to stamp out those of β€œbad faith.”

πŸ“– Read

via "Naked Security".
⚠ Facebook user data used as bargaining chip, according to leaked docs ⚠

Leaked internal docs used to claim "privacy was an afterthought" at Facebook

πŸ“– Read

via "Naked Security".
⚠ Serious Security: Ransomware you’ll never find – and how to stop it ⚠

What if you got hit by ransomware - but the malware program itself was on the other side of the world where you'd never find it?

πŸ“– Read

via "Naked Security".
❌ Cisco Patches Critical Flaw In ASR 9000 Routers ❌

The flaw could enable an unauthenticated, remote attacker to access the devices, Cisco said.

πŸ“– Read

via "Threatpost".
πŸ” BlackBerry opens BBM Enterprise for personal use after Emtek discontinues BBM Consumer πŸ”

Attempts to make BBM more consumer-focused with social media functions saw limited success, leading to the discontinuation of the BBM Consumer app.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to secure a blockchain: 3 things business leaders need to know πŸ”

With companies across industries adopting blockchain technologies, security concerns remain, according to the World Economic Forum.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Facebook Accidentally Imported 1.5M Users' Email Data Sans Consent πŸ•΄

The social media giant says it did not access the imported data and is notifying affected users.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ GoT Guide to Cybersecurity: Preparing for Battle During a Staffing Shortage πŸ•΄

Faced with an overwhelming adversary, Game of Thrones heroes Daenerys Targaryen and Jon Snow have a lot in common with today's beleaguered CISOs.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to install the OPNsense Firewall/Router Linux distribution πŸ”

Need a dedicated firewall appliance? OPNsense is a free, open-source solution, ready to protect your network from intrusion.

πŸ“– Read

via "Security on TechRepublic".
❌ Easter Attack Affects Half a Billion Apple iOS Users via Chrome Bug ❌

The U.S-focused eGobbler malvertising attacks are exploiting an unpatched Google Chrome bug.

πŸ“– Read

via "Threatpost".
πŸ•΄ Former Student Admits to USB Killer Attack πŸ•΄

An Indian national used device to attack computers and peripherals at a New York college.

πŸ“– Read

via "Dark Reading: ".
πŸ” Breaking Down the Best Practices & Tools for Data-Centric Audit and Protection (DCAP) πŸ”

Data classification, discovery, and encryption: We reached out to 18 security experts for insight on implementing a data-centric audit and protection program in an organization.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Poll: Facebook Harvests Email Contacts for 1.5M Users – Is Enough, Enough? ❌

Take our short poll on how far Facebook can push its luck.

πŸ“– Read

via "Threatpost".