πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Nation-State Breaches Surged in 2018: Verizon DBIR πŸ•΄

The source of breaches has fluctuated significantly over the past nine years, but organized crime has almost always topped nation-state actors each year. The gap narrowed significantly in 2018, according to the annual report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US DoJ Indicts Chinese Man for Anthem Breach πŸ•΄

Fujie Wang allegedly worked as part of a hacking team out of China that stole information on nearly 80 million Americans in the massive healthcare breach.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-1600

The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Data Dump Purportedly Reveals Details on Previously Unknown Iranian Threat Group πŸ•΄

Rana targets airline companies and others in well-planned, well-researched attacks, Israel's ClearSky says.

πŸ“– Read

via "Dark Reading: ".
⚠ Airbnb Superhost’s creepy spycam sniffed out by sleuthing infosec pro ⚠

Why motion sensors in the bedrooms, she wondered? Why the extra light and weird wiring on the router?

πŸ“– Read

via "Naked Security".
⚠ FTC renews call for single federal privacy law ⚠

It also wants to be the country's data-privacy police: commissioners called for more resources and ability to impose penalties.

πŸ“– Read

via "Naked Security".
⚠ 275m personal records swiped from exposed MongoDB database ⚠

Records included not only the individuals’ name and email address but also their employment history, salary, and phone number.

πŸ“– Read

via "Naked Security".
❌ ThreatList: Nigerian Cybercrime Surged 54 Percent in 2018 ❌

Nigerian scam groups launched even more attacks in 2018 - and used more complex types of malware to reach more victims.

πŸ“– Read

via "Threatpost".
πŸ•΄ Bumper Crop of New Briefings Added for Black Hat USA πŸ•΄

Among the 50+ new Briefings confirmed for this August event are a deep dive into the Apple T2 chip and a pile of lessons learned from the Equifax and Home Depot breaches.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Hackers Still Outpace Breach Detection, Containment Efforts πŸ•΄

Research shows time to discovery and containment of breaches slowly shrinking, but attackers don't need a very big window to do a lot of damage.

πŸ“– Read

via "Dark Reading: ".
πŸ” Half of employees think the cloud is actually in the sky, according to a third of IT workers πŸ”

It's not a secret that IT professionals--particularly first-tier tech support--have a low opinion of users, though a new survey paints a rather bleak picture.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Symantec CEO Greg Clark Steps Down πŸ•΄

Exec shake-up comes amid earnings drop in financial report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How We Collectively Can Improve Cyber Resilience πŸ•΄

Three steps you can take, based on Department of Homeland Security priorities.

πŸ“– Read

via "Dark Reading: ".
⚠ Chrome browser pushes SameSite cookie security overhaul ⚠

Slowly but steadily, developers are being given the tools with which to tame the promiscuous and often insecure world of the browser cookie.

πŸ“– Read

via "Naked Security".
πŸ” Friday Five: 5/10 Edition πŸ”

A dark web service takedown, Google gets better about data privacy, and another city hit by ransomware - catch up on the week's news with this roundup!

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Nvidia Warns Windows Gamers on GPU Driver Flaws ❌

Nvidia has patched three vulnerabilities in its Windows GPU display driver that could enable information disclosure, denial of service and privilege escalation.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-12885

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12795

OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12789

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1006

A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were installed by PAC Project installer, versions prior to R9.4006, is susceptible to a heap-based buffer overflow condition that may allow remote code execution on the target system. Opto 22 suggests upgrading to the new product version as soon as possible.

πŸ“– Read

via "National Vulnerability Database".
❌ The WannaCry Security Legacy and What’s to Come ❌

The WannaCry attack proved pivotal, changing the way organizations go about securing their environments.

πŸ“– Read

via "Threatpost".