πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2017-16558

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 55% of SMBs Would Pay Up Post-Ransomware Attack πŸ•΄

The number gets even higher among larger SMBs.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ UVA Wins Second Consecutive National Collegiate Cyber Defense Championship πŸ•΄

The Wahoos came out on top among 235 colleges and universities that took part in the 15-year-old competition.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-1360

A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12244

SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.

πŸ“– Read

via "National Vulnerability Database".
❌ Android-Based Sony Smart-TVs Open to Image Pilfering ❌

A pair of bugs would allow attackers to compromise the WiFi password of a TV and the multimedia stored inside it.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cyberattackers Focus on More Subtle Techniques πŸ•΄

Spam has given way to spear phishing, cryptojacking remains popular, and credential spraying is on the rise.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New EternalBlue Family Member Takes Aim at Asian Web Servers πŸ•΄

Beapy is a new malware variant that's storming across China, leaving cryptominers in its wake.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Security Vulns in Microsoft Products Continue to Increase πŸ•΄

The good news: Removing admin privileges can mitigate most of them, a new study by BeyondTrust shows.

πŸ“– Read

via "Dark Reading: ".
⚠ Cops can try suspect’s fingers on locked iPhones found at crime scene ⚠

A Massachusetts federal district judge gave cops a warrant to force-unlock iPhones with the suspect's fingers.

πŸ“– Read

via "Naked Security".
⚠ Microsoft drops password expiration from Windows 10 security ⚠

Microsoft has recognised that users don't actually change their passwords when prompted, they just tweak them. And that doesn't help anyone.

πŸ“– Read

via "Naked Security".
⚠ Fingerprint glitch in passports swapped left and right hands ⚠

And just who, exactly, is going to pay for new passports if it's necessary? Danish police are chatting with Kube Data about that.

πŸ“– Read

via "Naked Security".
⚠ NSA asks to end mass phone surveillance ⚠

The NSA has asked the White House to end its mass phone surveillance program because the work involved outweighs its intelligence value.

πŸ“– Read

via "Naked Security".
❌ Facial Recognition β€˜Consent’ Doesn’t Exist, Threatpost Poll Finds ❌

Half of Threatpost readers surveyed in a recent poll don't believe that consent realistically exists when it comes to facial recognition.

πŸ“– Read

via "Threatpost".
πŸ•΄ Go Medieval to Keep OT Safe πŸ•΄

When it comes to operational technology and industrial control systems, make sure you're the lord of all you survey.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Flaws in Sierra Wireless 5G Gateway Allow RCE, Command Injection ❌

A 5G wireless gateway tailored for industrial internet of things (IoT), retail point-of-sale and enterprise redundancy applications is riddled with vulnerabilities, include two critical bugs that allow remote code-execution (RCE) and arbitrary command-injection. The Sierra Wireless AirLink ES450 LTE gateway (version 4.9.3) has 11 different bugs, which could be exploited for RCE, uncovering user credentials […]

πŸ“– Read

via "Threatpost".
πŸ” Friday Five: 4/26 Edition πŸ”

A new phishing scam asking for selfies,embedding malware in video games, and the latest IoT vulnerability are all covered in this week's Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2015-9284

The request phase of the OmniAuth Ruby gem is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Widespread scam campaigns targeting millions uncovered by GoDaddy and Palo Alto Networks πŸ”

A research team found that thousands of websites were tricking users into entering credit card information by spoofing trustworthy sites.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to manage user passwords with Group Policy πŸ”

You can enforce various policies to make sure your users meet certain requirements with their Windows passwords. Learn about some of the password-related settings in Group Policy.

πŸ“– Read

via "Security on TechRepublic".
❌ GoDaddy Shutters 14,000 Subdomains Tied to β€˜Snake Oil’ Scams ❌

GoDaddy worked with researchers to shut down 15,000 domain-shadowing websites tied to bogus affiliate marketing offers promoted via spam campaigns.

πŸ“– Read

via "Threatpost".