πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Massive Dark Web 'Wall Street Market' Shuttered πŸ•΄

Europol-led international law enforcement operation led to takedown of world's second-largest digital underground marketplace.

πŸ“– Read

via "Dark Reading: ".
❌ Researchers Weigh in on Trump’s Cyber Workforce Executive Order ❌

Short on concrete details but long on affirming cybersecurity skills as a critical piece of federal defense, the White House executive order aims to bolster the national cyber workforce.

πŸ“– Read

via "Threatpost".
⚠ Mozilla bug throws Tor Browser users into chaos ⚠

A Mozilla bug has made everyone's Firefox addons 'untrustworthy' - including turning off the important NoScript security feature in Tor.

πŸ“– Read

via "Naked Security".
❌ Amid Bug Bounty Hype, Sometimes Security is Left in the Dust ❌

Amidst the PR glitz and popularity of bug bounty programs, experts worry that actual smart security strategy is being left behind.

πŸ“– Read

via "Threatpost".
❌ Extinguishing the IoT Insecurity Dumpster Fire ❌

Will connected devices be insecure forever? Or will legislation - such as the recent UK mandate announced this week - help boost IoT security?

πŸ“– Read

via "Threatpost".
πŸ•΄ Trust the Stack, Not the People πŸ•΄

A completely trusted stack lets the enterprise be confident that apps and data are treated and protected wherever they are.

πŸ“– Read

via "Dark Reading: ".
❌ Tor Security Add-On Abruptly Killed by Mozilla Bug ❌

A digital signing flaw killed add-ons for Firefox as well as Tor -- and no patch is yet available for Tor users.

πŸ“– Read

via "Threatpost".
❌ High-Severity PrinterLogic Flaws Enable Remote Code Execution ❌

The three flaws enable an unauthenticated attacker to launch remote code execution attacks on printers.

πŸ“– Read

via "Threatpost".
❌ Avengers: Endgame Sites Promise Digital Downloads, Deliver Info-Harvesting ❌

Web scammers are going after Marvel fans as the movie passes the $2.2 billion box-office mark, making it the second-highest grossing film of all time, behind only Avatar.

πŸ“– Read

via "Threatpost".
πŸ” Certificate issue disabling add-ons in Firefox and Tor Browser finally fixed πŸ”

Mozilla forces third party add-ons to be digitally signed, though an expired certificate disabled these, causing confusion among users of Firefox and the Tor Browser over the weekend.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Security Top Concern as Mobile Providers Think 5G πŸ•΄

The deployment of 5G networks will bring new use cases and revenue opportunities, mobile providers say, but security will be essential.

πŸ“– Read

via "Dark Reading: ".
πŸ” Popcorn Recipe Case Highlights Niche Trade Secret Theft Risk πŸ”

This company protected its sensitive data with biometric thumbprint scanner but still managed to suffer trade secret theft after a former director of research allegedly stole gigabytes of data on its recipes.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ High-Severity Bug Leaves Cisco TelePresence Gear Open to Attack ❌

Cisco patches two high-severity bugs that could be exploited by remote attackers.

πŸ“– Read

via "Threatpost".
❌ Oracle WebLogic Exploit-fest Continues with GandCrab Ransomware, XMRig ❌

Snowballing attacks using a recently patched critical bug show no sign of abating.

πŸ“– Read

via "Threatpost".
πŸ” The dark web is smaller, and may be less dangerous, than we think πŸ”

Another Dark Web market has been closed, its leaders arrested. Law enforcement seems to be getting a handle on the Dark Web--is it really as big of a threat as it is made out to be?

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-13990

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13983

ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13990

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13983

ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft Debuts ElectionGuard to Secure Voting Processes πŸ•΄

The new software development kit - free and open source - will be available to election officials and technology suppliers this summer.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 'Matrix'-Themed Ransomware Variant Spreads πŸ•΄

MegaCortex uses a compromised domain controller in its attack.

πŸ“– Read

via "Dark Reading: ".