πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” The 5 most hacked passwords πŸ”

More than 23 million people were breached after using the password 123456, according to the UK's National Cyber Security Centre.

πŸ“– Read

via "Security on TechRepublic".
❌ Millions of Medical Documents for Addiction and Recovery Patients Leaked ❌

The information includes data on all rehab treatments and procedures, linked with patients' names and other info.

πŸ“– Read

via "Threatpost".
⚠ Can you get hit by someone else’s ransomware? [VIDEO] ⚠

How to protect yourself from being *affected* by malware, even if you're not yourself *infected*.

πŸ“– Read

via "Naked Security".
πŸ•΄ 4 Tips to Protect Your Business Against Social Media Mistakes πŸ•΄

Don't let social media become the go-to platform for cybercriminals looking to steal sensitive corporate information or cause huge reputational damage.

πŸ“– Read

via "Dark Reading: ".
❌ WannaCry Hero Pleads Guilty to Kronos Malware Charges ❌

The malware researcher has pleaded guilty to two out of 10 charges; one with creating the Kronos malware and the other with conspiracy.

πŸ“– Read

via "Threatpost".
πŸ” How to update the Nmap database πŸ”

Your nmap service probe database is probably way out of date. Jack Wallen shows you how to update that special file to the latest version.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to update the nmap database πŸ”

Your nmap service probe database is probably out of date. It's easy to update that special file to the latest version.

πŸ“– Read

via "Security on TechRepublic".
❌ France’s β€˜Secure’ Telegram Replacement Hacked in an Hour ❌

The messaging app that will replace the government's use of WhatsApp and Telegram was released last week, with security vulnerability included.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2018-20818

A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possibly have unspecified other impact.

πŸ“– Read

via "National Vulnerability Database".
❌ Evil TeamViewer Attacks Under the Guise of the U.S. State Department ❌

The attack is targeting financial regulators and embassy staff-- but probably isn't the work of an APT.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2016-1587

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-1586

A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-1585

In all versions of AppArmor mount rules are accidentally widened when compiled.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-1584

In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-1579

UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run arbitrary commands in an unconfined environment as the phablet user.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-1573

Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1343

All versions of unity-scope-gdrive logs search terms to syslog.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1341

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Appoprt before 2.19.2 function _python_module_path.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1340

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1327

Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1326

python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.

πŸ“– Read

via "National Vulnerability Database".