πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Once again, it’s 123456: the password that says β€˜I give up’ ⚠

A new survey says 46% of users find security confusing, which helps explain how that old clunker keeps popping to the top of breach lists.

πŸ“– Read

via "Naked Security".
⚠ Hotspot finder app blabs 2 million Wi-Fi network passwords ⚠

If you used WiFi Finder, your passwords to both public and private networks have been left online in an unprotected database.

πŸ“– Read

via "Naked Security".
πŸ” Weaponization of vulnerabilities in Adobe products more than doubled in 2018 πŸ”

Using free Adobe software like Flash Player and Adobe Reader can pose a security risk in your organization.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Will the US Adopt a National Privacy Law? πŸ•΄

Probably not before the 2020 election. But keep an eye on this Congress as legislators debate how to define personal data and what limits to place on how companies use it.

πŸ“– Read

via "Dark Reading: ".
⚠ Phone fingerprint scanner fooled by chewing gum packet ⚠

A video has surfaced claiming to show someone unlocking a Nokia 9 by tapping a gum packet against the fingerprint scanner.

πŸ“– Read

via "Naked Security".
❌ FBI: BEC Scam Losses Almost Double To Reach $1.2 Billion ❌

Overall, in 2018 the FBI received more than 351k reported scams with losses exceeding $2.7 billion.

πŸ“– Read

via "Threatpost".
πŸ” How businesses plan to protect themselves against cyberattacks πŸ”

Many organizations will spend more to shore up their defenses against cyberattacks this year, says business insurance provider Hiscox.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-1317

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12619

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".

πŸ“– Read

via "National Vulnerability Database".
❌ Exploits for Social Warfare WordPress Plugin Reach Critical Mass ❌

More and more attacks taking advantage of a XSS and RCE bug in the popular plugin have cropped up in the wild.

πŸ“– Read

via "Threatpost".
πŸ•΄ When Every Attack Is a Zero Day πŸ•΄

Stopping malware the first time is an ideal that has remained tantalizingly out of reach. But automation, artificial intelligence, and deep learning are poised to change that.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Exploits for Adobe Vulnerabilities Spiked in 2018 πŸ•΄

With Flash Player on way out, attackers are renewing their focus on Acrobat Reader, RiskSense found.

πŸ“– Read

via "Dark Reading: ".
πŸ” Breaking Down the Nigeria Data Protection Regulation πŸ”

The regulation, issued in January, could pace Nigeria as a leader in data protection in Africa.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ App Exposes Wi-Fi Credentials for Thousands of Private Networks πŸ•΄

A database used by WiFi Finder was left open and unprotected on the Internet.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ City of Stuart Still Recovering from Ryuk Ransomware Attack πŸ•΄

Officials are investigating an April 13 ransomware attack that targeted Stuart's city servers and forced it offline.

πŸ“– Read

via "Dark Reading: ".
❌ Carbanak Source Code Unveils a Startlingly Complex Malware ❌

The malware is behind billions in banking and credit-card losses.

πŸ“– Read

via "Threatpost".
πŸ•΄ Demonstration Showcase Brings DevOps to Interop19 πŸ•΄

Attendees will learn how orchestration and automation can be a part of network operations and security, even at smaller companies.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google File Cabinet Plays Host to Malware Payloads πŸ•΄

Researchers detect a new drive-by download attack in which Google Sites' file cabinet template is a delivery vehicle for malware.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Stuxnet Family Tree Grows πŸ•΄

What a newly discovered missing link to Stuxnet and the now-revived Flame cyber espionage malware add to the narrative of the epic cyber-physical attack.

πŸ“– Read

via "Dark Reading: ".
πŸ” Small business owners: Don't rush into using AI πŸ”

An artificial intelligence strategist advises small business owners to focus on revenue and growth and not AI in of itself--at least for now--because the ROI is not there.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Vendor risk management: What to consider when shopping for a VRM solution πŸ”

A vendor risk management program could curtail Third-Party Vendor-initiated data breaches. Here's what to look for in a VRM solution.

πŸ“– Read

via "Security on TechRepublic".