πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-10055

Invalid memory access and/or a heap buffer overflow in the TensorFlow XLA compiler in Google TensorFlow before 1.7.1 could cause a crash or read from other parts of process memory via a crafted configuration file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 5 Security Challenges to API Protection πŸ•΄

Today's application programming interfaces are no longer simple or front-facing, creating new risks for both security and DevOps.

πŸ“– Read

via "Dark Reading: ".
❌ Facebook May Face $5 Billion FTC Fine for Data Misuse ❌

Facebook may be fined as much as $5 million by the FTC for data issues related to the Cambridge Analytica incident.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-18367

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ TA505 Abusing Legit Remote Admin Tool in String of Attacks πŸ•΄

Russian-speaking threat group has been targeting retailers and financial institutions in the US and abroad via a spear-phishing campaign.

πŸ“– Read

via "Dark Reading: ".
⚠ Teen sues Apple for $1 billion over Apple stores’ facial recognition ⚠

He claims that Apple allegedly uses the technology to spot shoplifters and that it falsely linked him to a series of Apple store thefts.

πŸ“– Read

via "Naked Security".
⚠ Atlanta Hawks fall prey to Magecart credit card skimming group ⚠

The Atlanta Hawks basketball team is recovering after a sophisticated cybercrime group hacked its ecommerce site and planted credit card skimming code on it.

πŸ“– Read

via "Naked Security".
πŸ” Microsoft wants to kill Windows password expiration policy πŸ”

The proposal means that users at organizations with Group Policy would no longer be required to change their Windows passwords on a regular basis.

πŸ“– Read

via "Security on TechRepublic".
⚠ Blochainbandit stole $54 million of Ethereum by guessing weak keys ⚠

Someone has been quietly pilfering Ethereum (ETH) cryptocurrency worth millions of dollars without anyone noticing or, apparently, caring.

πŸ“– Read

via "Naked Security".
πŸ” Businesses hit with 235% more cyberthreats this year πŸ”

Trojans and ransomware top the list of threats with corporate targets in Q1 2019, according to a Malwarebytes report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” The 10 highest-paying cybersecurity jobs πŸ”

Demand for cybersecurity roles jumped over 7% in the last year, leading to increasing salaries, according to Indeed.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 50 InfoSec Networking Groups to Join πŸ”

Looking to stay ahead of the curve on all things infosec? We've gathered a list of 50 valuable associations, LinkedIn networking groups, and meetups for security professionals.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Indeed.com: Slight Dip in Clicks on US Cybersecurity Job Listings πŸ•΄

Meanwhile, most of the highest-paying positions pay more than $100K, according to new analysis from the job posting site.

πŸ“– Read

via "Dark Reading: ".
πŸ” Most SMBs would pay a hacker a ransom to get their stolen data back πŸ”

Social media apps and websites are the biggest potential threat vectors to businesses, according to an AppRiver report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How automated Dark Web marketplaces make credential stuffing attacks more profitable πŸ”

Validated stolen credentials cost less than a cup of coffee, but economies of scale have made selling user accounts more lucrative than ever, according to Recorded Future.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Ramblings of a Recovering Academic on the So-Called Lack of Security Talent πŸ•΄

Hiring for security is difficult, as many surveys show. But what the research doesn't explain is the "why" - and a lack of talent may not be the sole reason.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Regulations, Insider Threat Handicap Healthcare IT Security πŸ•΄

Healthcare IoT is expanding opportunities for hackers as the sector struggles to keep up security-wise.

πŸ“– Read

via "Dark Reading: ".
⚠ ExtraPulsar backdoor based on leaked NSA code – what you need to know ⚠

A US security researcher has come up with an open-source Windows backdoor loosely based on NSA attack code that leaked back in 2017.

πŸ“– Read

via "Naked Security".
❌ Qualcomm Critical Flaw Exposes Private Keys For Android Devices ❌

A side-channel attack in Qualcomm technology, which is used by most modern Android devices, could allow an attacker to snatch private keys.

πŸ“– Read

via "Threatpost".
πŸ” Enterprise cryptojacking attacks continue, despite overall decline in popularity among hackers πŸ”

A newly-discovered cryptojacking campaign uses familiar exploits to target enterprises and traverse network shares, infecting any connected computer.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Sensitive Data Lingers on Used Storage Drives Sold Online πŸ•΄

Four in 10 used hard drives sold on eBay found to contain sensitive information.

πŸ“– Read

via "Dark Reading: ".