πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Chinese Hackers Behind 2015 Anthem Data Breach Indicted ❌

Two have been indicted in the 2015 massive data breach of health insurer Anthem, which compromised the data of at least 78 million customers.

πŸ“– Read

via "Threatpost".
❌ β€˜Unhackable’ Biometric USB Offers Up Passwords in Plain Text ❌

A simple Wireshark analysis was enough to subvert the gadget, which uses iris identification to protect the drive.

πŸ“– Read

via "Threatpost".
πŸ•΄ Nation-State Breaches Surged in 2018: Verizon DBIR πŸ•΄

The source of breaches has fluctuated significantly over the past nine years, but organized crime has almost always topped nation-state actors each year. The gap narrowed significantly in 2018, according to the annual report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US DoJ Indicts Chinese Man for Anthem Breach πŸ•΄

Fujie Wang allegedly worked as part of a hacking team out of China that stole information on nearly 80 million Americans in the massive healthcare breach.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-1600

The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Data Dump Purportedly Reveals Details on Previously Unknown Iranian Threat Group πŸ•΄

Rana targets airline companies and others in well-planned, well-researched attacks, Israel's ClearSky says.

πŸ“– Read

via "Dark Reading: ".
⚠ Airbnb Superhost’s creepy spycam sniffed out by sleuthing infosec pro ⚠

Why motion sensors in the bedrooms, she wondered? Why the extra light and weird wiring on the router?

πŸ“– Read

via "Naked Security".
⚠ FTC renews call for single federal privacy law ⚠

It also wants to be the country's data-privacy police: commissioners called for more resources and ability to impose penalties.

πŸ“– Read

via "Naked Security".
⚠ 275m personal records swiped from exposed MongoDB database ⚠

Records included not only the individuals’ name and email address but also their employment history, salary, and phone number.

πŸ“– Read

via "Naked Security".
❌ ThreatList: Nigerian Cybercrime Surged 54 Percent in 2018 ❌

Nigerian scam groups launched even more attacks in 2018 - and used more complex types of malware to reach more victims.

πŸ“– Read

via "Threatpost".
πŸ•΄ Bumper Crop of New Briefings Added for Black Hat USA πŸ•΄

Among the 50+ new Briefings confirmed for this August event are a deep dive into the Apple T2 chip and a pile of lessons learned from the Equifax and Home Depot breaches.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Hackers Still Outpace Breach Detection, Containment Efforts πŸ•΄

Research shows time to discovery and containment of breaches slowly shrinking, but attackers don't need a very big window to do a lot of damage.

πŸ“– Read

via "Dark Reading: ".
πŸ” Half of employees think the cloud is actually in the sky, according to a third of IT workers πŸ”

It's not a secret that IT professionals--particularly first-tier tech support--have a low opinion of users, though a new survey paints a rather bleak picture.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Symantec CEO Greg Clark Steps Down πŸ•΄

Exec shake-up comes amid earnings drop in financial report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How We Collectively Can Improve Cyber Resilience πŸ•΄

Three steps you can take, based on Department of Homeland Security priorities.

πŸ“– Read

via "Dark Reading: ".
⚠ Chrome browser pushes SameSite cookie security overhaul ⚠

Slowly but steadily, developers are being given the tools with which to tame the promiscuous and often insecure world of the browser cookie.

πŸ“– Read

via "Naked Security".
πŸ” Friday Five: 5/10 Edition πŸ”

A dark web service takedown, Google gets better about data privacy, and another city hit by ransomware - catch up on the week's news with this roundup!

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Nvidia Warns Windows Gamers on GPU Driver Flaws ❌

Nvidia has patched three vulnerabilities in its Windows GPU display driver that could enable information disclosure, denial of service and privilege escalation.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-12885

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12795

OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12789

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

πŸ“– Read

via "National Vulnerability Database".