πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Google Stored G Suite Passwords in Plaintext Since 2005 ❌

Google said it had stored G Suite enterprise users' passwords in plain text since 2005 marking a giant security faux pas.

πŸ“– Read

via "Threatpost".
πŸ•΄ Consumer IoT Devices Are Compromising Enterprise Networks πŸ•΄

While IoT devices continue to multiply, the latest studies show a dangerous lack of visibility into those connected to enterprise networks.

πŸ“– Read

via "Dark Reading: ".
πŸ” Arm suspends cooperation with Huawei, endangering mobile and server business πŸ”

UK-based Arm Holdings has issued a memo to staff indicating it must stop working with Chinese equipment manufacturer Huawei, following a US trade dispute.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The 3 Cybersecurity Rules of Trust πŸ•΄

Every day, keeping anything secure requires being smart about trust. The rules of trust will keep you and your data safer.

πŸ“– Read

via "Dark Reading: ".
πŸ” Tech news roundup: GDPR turns 1, and who makes the best apps? πŸ”

Karen Roby reports on this week's biggest tech news, including Huawei's Android license and the one year anniversary of GDPR. How have businesses been affected by the legislation and what does Microsoft have to say about a potential version of the law in the US?

πŸ“– Read

via "Security on TechRepublic".
❌ Windows Zero-Day Drops on Twitter, Developer Promises 4 More ❌

SandboxEscaper has released her latest local privilege-escalation exploit for Windows.

πŸ“– Read

via "Threatpost".
πŸ” Tech news roundup: GDPR turns 1, and who makes the best apps? πŸ”

Karen Roby reports on this week's biggest tech news, including Huawei's Android license and the one year anniversary of GDPR. How have businesses been affected by the legislation and what does Microsoft have to say about a potential version of the law in the US?

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-1991

IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10750

In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Flaws in Khan Academy Opened Door to Account Takeovers ❌

The two critical cross-site request forgery flaws in the online learning non-profit Khan Academy have been resolved.

πŸ“– Read

via "Threatpost".
πŸ•΄ DDoS Attacks Up in Q1 After Months of Steady Decline πŸ•΄

Sudden surge suggests that new actors have stepped up to the plate to replace the old operators.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Proving the Value of Security Awareness with Metrics that 'Deserve More' πŸ•΄

Without metrics that matter to the business, awareness programs will continue to be the bastard child of security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google Alerts Admins to Unhashed Password Storage πŸ•΄

The company reports it has seen improper access to, or misuse of, affected enterprise G Suite credentials.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Baltimore Email, Other Systems Still Offline from May 7 Ransomware Attack πŸ•΄

The city's mayor says there's no 'exact timeline on when all systems will be restored.'

πŸ“– Read

via "Dark Reading: ".
πŸ” Lithuanian DPA Hopes First GDPR Fine Is A Wake Up Call πŸ”

It took a year but Lithuania's data protection authority issued its first fine, to a fintech company, for breaching three provisions of the GDPR.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ WannaCry-Infested Laptop Starts at $1.13M in Art Auction ❌

The "bestiary" houses six historical threats that combined resulted in at least $95B in damages worldwide.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2018-7202

An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-14729

The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12886

stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-9809

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6514 (wordpress)

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

πŸ“– Read

via "National Vulnerability Database".