πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Dark web marketplace Wall Street Market busted by international police ⚠

It went down in flames, with a rogue admin blackmailing vendors and buyers and leaking login credentials and the IP address.

πŸ“– Read

via "Naked Security".
⚠ Firefox add-ons with obfuscated code will be banned by Mozilla ⚠

The updated Add-on Policy aims to rid Firefox of third-party malicious code that hides what it's really up to.

πŸ“– Read

via "Naked Security".
πŸ•΄ Russian Nation-State Group Employs Custom Backdoor for Microsoft Exchange Server πŸ•΄

Turla hacking team abuses a legitimate feature of the Exchange server in order to hide out and access all of the target organization's messages.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Better Behavior, Better Biometrics? πŸ•΄

Behavioral biometrics is a building block to be used in conjunction with other security measures, but it shows promise.

πŸ“– Read

via "Dark Reading: ".
⚠ MegaCortex ransomware distracts victims with Matrix film references ⚠

One moment, the defenders’ network looked secure but the next, as if out of nowhere, the ransom note pops up.

πŸ“– Read

via "Naked Security".
❌ Ukrainian Charged With Launching 100 Million Malicious Ads ❌

Oleksii Petrovich Ivanov has been extradited in the U.S. after allegedly launching malvertising campaigns that caused victims to view malicious ads on more than 100 million occasions.

πŸ“– Read

via "Threatpost".
πŸ” 90% of data breaches in US occur in New York and California πŸ”

Half a billion records have been exposed in total, with over 86 breaches affecting the two states since January, according to Risk Based Security.

πŸ“– Read

via "Security on TechRepublic".
❌ Chinese Spies Stole NSA Cyberweapons Long Before Shadow Brokers Leak ❌

Forensic analysis shows a Chinese APT using Equation Group hacking tools at least a year before Shadow Brokers dumped its cache in April 2017.

πŸ“– Read

via "Threatpost".
πŸ•΄ The Big E-Crime Pivot πŸ•΄

Criminals have begun to recognize that enterprise ransomware offers tremendous financial advantage over the more traditional tactics of wire fraud and account takeover.

πŸ“– Read

via "Dark Reading: ".
πŸ” Trade Secret Theft Victim Wins $845 Million πŸ”

While very little money will change hands, the sum is believed to be one of the largest judgments for the theft of trade secrets in U.S. history.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ The Dark Web is Smaller Than You Think πŸ•΄

The number of live, accessible .onion sites amounts to less than 0.005% of surface web domains, researchers report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US States with the Worst Consumer Cyber-Hygiene πŸ•΄

Ranking based on consumers' cybersecurity practices - or lack thereof.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How a Chinese Nation-State Group Reversed-Engineered NSA Attack Tools πŸ•΄

New Symantec research shows how the Buckeye group captured an exploit and backdoor used by the National Security Agency and deployed them on other victims.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How a Chinese Nation-State Group Reversed-Engineered NSA Attack Tools πŸ•΄

New Symantec research shows how the Buckeye group captured an exploit and backdoor used by the National Security Agency and deployed them on other victims.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to enable BitLocker on non-TPM Macs πŸ”

It's easy to add Microsoft's drive encrypting BitLocker protection to your non-TPM enabled Mac computers hosting Windows via Boot Camp or third-party VM.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-14485

BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-14478 (coppermine_photo_gallery)

ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13994

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13993

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13992

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13991

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.

πŸ“– Read

via "National Vulnerability Database".