πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Qualcomm Critical Flaw Exposes Private Keys For Android Devices ❌

A side-channel attack in Qualcomm technology, which is used by most modern Android devices, could allow an attacker to snatch private keys.

πŸ“– Read

via "Threatpost".
πŸ” Enterprise cryptojacking attacks continue, despite overall decline in popularity among hackers πŸ”

A newly-discovered cryptojacking campaign uses familiar exploits to target enterprises and traverse network shares, infecting any connected computer.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Sensitive Data Lingers on Used Storage Drives Sold Online πŸ•΄

Four in 10 used hard drives sold on eBay found to contain sensitive information.

πŸ“– Read

via "Dark Reading: ".
πŸ” The 4 most important files for SSH connections πŸ”

You are better armed to make use of the SSH tool with an understanding of four key SSH files.

πŸ“– Read

via "Security on TechRepublic".
❌ Amazon Employees Given β€˜Broad Access’ to Personal Alexa Info ❌

An auditing program for the voice assistant technology exposes geolocation data that can be personally identified, sources said.

πŸ“– Read

via "Threatpost".
πŸ•΄ Enterprise Trojan Detections Spike 200% in Q1 2019 πŸ•΄

Cybercriminals see greater ROI targeting businesses, which have been slammed with ransomware attacks and Trojans.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How a Nigerian ISP Accidentally Hijacked the Internet πŸ•΄

For 74 minutes, traffic destined for Google and Cloudflare services was routed through Russia and into the largest system of censorship in the world, China's Great Firewall.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-16558

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 55% of SMBs Would Pay Up Post-Ransomware Attack πŸ•΄

The number gets even higher among larger SMBs.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ UVA Wins Second Consecutive National Collegiate Cyber Defense Championship πŸ•΄

The Wahoos came out on top among 235 colleges and universities that took part in the 15-year-old competition.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-1360

A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12244

SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.

πŸ“– Read

via "National Vulnerability Database".
❌ Android-Based Sony Smart-TVs Open to Image Pilfering ❌

A pair of bugs would allow attackers to compromise the WiFi password of a TV and the multimedia stored inside it.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cyberattackers Focus on More Subtle Techniques πŸ•΄

Spam has given way to spear phishing, cryptojacking remains popular, and credential spraying is on the rise.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New EternalBlue Family Member Takes Aim at Asian Web Servers πŸ•΄

Beapy is a new malware variant that's storming across China, leaving cryptominers in its wake.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Security Vulns in Microsoft Products Continue to Increase πŸ•΄

The good news: Removing admin privileges can mitigate most of them, a new study by BeyondTrust shows.

πŸ“– Read

via "Dark Reading: ".
⚠ Cops can try suspect’s fingers on locked iPhones found at crime scene ⚠

A Massachusetts federal district judge gave cops a warrant to force-unlock iPhones with the suspect's fingers.

πŸ“– Read

via "Naked Security".
⚠ Microsoft drops password expiration from Windows 10 security ⚠

Microsoft has recognised that users don't actually change their passwords when prompted, they just tweak them. And that doesn't help anyone.

πŸ“– Read

via "Naked Security".
⚠ Fingerprint glitch in passports swapped left and right hands ⚠

And just who, exactly, is going to pay for new passports if it's necessary? Danish police are chatting with Kube Data about that.

πŸ“– Read

via "Naked Security".
⚠ NSA asks to end mass phone surveillance ⚠

The NSA has asked the White House to end its mass phone surveillance program because the work involved outweighs its intelligence value.

πŸ“– Read

via "Naked Security".
❌ Facial Recognition β€˜Consent’ Doesn’t Exist, Threatpost Poll Finds ❌

Half of Threatpost readers surveyed in a recent poll don't believe that consent realistically exists when it comes to facial recognition.

πŸ“– Read

via "Threatpost".