πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Data Dump Purportedly Reveals Details on Previously Unknown Iranian Threat Group πŸ•΄

Rana targets airline companies and others in well-planned, well-researched attacks, Israel's ClearSky says.

πŸ“– Read

via "Dark Reading: ".
⚠ Airbnb Superhost’s creepy spycam sniffed out by sleuthing infosec pro ⚠

Why motion sensors in the bedrooms, she wondered? Why the extra light and weird wiring on the router?

πŸ“– Read

via "Naked Security".
⚠ FTC renews call for single federal privacy law ⚠

It also wants to be the country's data-privacy police: commissioners called for more resources and ability to impose penalties.

πŸ“– Read

via "Naked Security".
⚠ 275m personal records swiped from exposed MongoDB database ⚠

Records included not only the individuals’ name and email address but also their employment history, salary, and phone number.

πŸ“– Read

via "Naked Security".
❌ ThreatList: Nigerian Cybercrime Surged 54 Percent in 2018 ❌

Nigerian scam groups launched even more attacks in 2018 - and used more complex types of malware to reach more victims.

πŸ“– Read

via "Threatpost".
πŸ•΄ Bumper Crop of New Briefings Added for Black Hat USA πŸ•΄

Among the 50+ new Briefings confirmed for this August event are a deep dive into the Apple T2 chip and a pile of lessons learned from the Equifax and Home Depot breaches.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Hackers Still Outpace Breach Detection, Containment Efforts πŸ•΄

Research shows time to discovery and containment of breaches slowly shrinking, but attackers don't need a very big window to do a lot of damage.

πŸ“– Read

via "Dark Reading: ".
πŸ” Half of employees think the cloud is actually in the sky, according to a third of IT workers πŸ”

It's not a secret that IT professionals--particularly first-tier tech support--have a low opinion of users, though a new survey paints a rather bleak picture.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Symantec CEO Greg Clark Steps Down πŸ•΄

Exec shake-up comes amid earnings drop in financial report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How We Collectively Can Improve Cyber Resilience πŸ•΄

Three steps you can take, based on Department of Homeland Security priorities.

πŸ“– Read

via "Dark Reading: ".
⚠ Chrome browser pushes SameSite cookie security overhaul ⚠

Slowly but steadily, developers are being given the tools with which to tame the promiscuous and often insecure world of the browser cookie.

πŸ“– Read

via "Naked Security".
πŸ” Friday Five: 5/10 Edition πŸ”

A dark web service takedown, Google gets better about data privacy, and another city hit by ransomware - catch up on the week's news with this roundup!

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Nvidia Warns Windows Gamers on GPU Driver Flaws ❌

Nvidia has patched three vulnerabilities in its Windows GPU display driver that could enable information disclosure, denial of service and privilege escalation.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-12885

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12795

OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12789

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1006

A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were installed by PAC Project installer, versions prior to R9.4006, is susceptible to a heap-based buffer overflow condition that may allow remote code execution on the target system. Opto 22 suggests upgrading to the new product version as soon as possible.

πŸ“– Read

via "National Vulnerability Database".
❌ The WannaCry Security Legacy and What’s to Come ❌

The WannaCry attack proved pivotal, changing the way organizations go about securing their environments.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft SharePoint Bug Exploited in the Wild πŸ•΄

A number of reports show CVE-2019-0604 is under active attack, Alien Labs researchers say.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-12884

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.

πŸ“– Read

via "National Vulnerability Database".
❌ News Wrap: Facebook Regulation, Verizon DBIR, Hidden Airbnb Cameras ❌

From a creepy Airbnb incident to Verizon's Data Breach Investigations Report, Threatpost editors break down the top privacy and security stories for the week ended May 10.

πŸ“– Read

via "Threatpost".