πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Monday review – the hot 17 stories of the week ⚠

From DNS over HTTPS to Microsoft's expiration policy - and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Piracy streaming apps are stuffed with malware ⚠

Researchers have found that hackers are exploiting vulnerable piracy streaming devices to steal credit card data or rope them into botnets.

πŸ“– Read

via "Naked Security".
⚠ Cops need warrant for both location history and phone pinging, says judge ⚠

It's one of the first location data privacy cases to grapple with the warrant and surveillance implications of the Carpenter decision.

πŸ“– Read

via "Naked Security".
⚠ Cryptocurrency giants in $850m fraud allegations ⚠

The New York Attorney General has accused major cryptocurrency exchange Bitfinex and cryptocurrency Tether of an $850m fraud.

πŸ“– Read

via "Naked Security".
⚠ NIST tool boosts chances of finding dangerous software flaws ⚠

NIST thinks it has reached an important milestone in complex software testing with something called Combinatorial Coverage Measurement (CCM).

πŸ“– Read

via "Naked Security".
πŸ•΄ Learn to Defend Against HTTP Desync Attacks at Black Hat USA πŸ•΄

Save the Date: Black Hat USA returns to the Mandalay Bay in Las Vegas August 3-8.

πŸ“– Read

via "Dark Reading: ".
πŸ” Risk management tips from the SBA and NIST every small-business owner should read πŸ”

Shifting cybersecurity from a defensive posture to one of managing risk is becoming more important for small-business owners. Here's must-read risk-management guidance.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Half of companies have 1,000+ sensitive files accessible to every employee πŸ”

Post-GDPR, businesses are still failing to adequately protect sensitive data, according to a Varonis report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” 75% of people are stressed about remembering passwords πŸ”

Two-thirds of consumers say having their bank accounts compromised would be more stressful than losing their job, according to a Kaspersky report.

πŸ“– Read

via "Security on TechRepublic".
❌ 2 Million IoT Devices Vulnerable to Complete Takeover ❌

Millions of security cameras, baby monitors and "smart" doorbells are open to hijack - and no solution is currently available.

πŸ“– Read

via "Threatpost".
πŸ” BEC Scams Responsible for $1.2B in Losses in 2018 πŸ”

It sounds like business email compromise attacks, attacks that rely on tricking recipients, usually executives, into conducting wire transfers, aren't going away anytime soon.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Docker Hub Hack Affects 190K Accounts ❌

Github and Bitbucket tokens for Docker autobuilds are also impacted.

πŸ“– Read

via "Threatpost".
πŸ•΄ A Rear-View Look at GDPR: Compliance Has No Brakes πŸ•΄

With a year of Europe's General Data Protection Regulation under our belt, what have we learned?

πŸ“– Read

via "Dark Reading: ".
πŸ” Why marketing teams are critical to successful cybersecurity efforts πŸ”

Marketers often focus on cybersecurity best practices after there is an incident, though experts say that needs to change to improve a company's chances of surviving a cyberattack.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Can password managers protect you from hackers? πŸ”

Microsoft Identity Division's corporate vice president of program management Alex Simons sat down with Dan Patterson to discuss the different threats facing the enterprise today.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Can password managers protect you from hackers? πŸ”

Microsoft Identity Division's corporate vice president of program management Alex Simons sat down with Dan Patterson to discuss the different threats facing the enterprise today.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-12384

When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10749

parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9285

esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1343 (ubuntu_linux)

All versions of unity-scope-gdrive logs search terms to syslog.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1341 (apport, ubuntu_linux)

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Appoprt before 2.19.2 function _python_module_path.

πŸ“– Read

via "National Vulnerability Database".