πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” How to install CA certificates in Ubuntu server πŸ”

Having trouble getting CA certificates installed and recognized in Ubuntu Server? Find out how it's done with a few quick commands.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Majority of C-Level Executives Expect a Cyber Breach πŸ•΄

Survey of executives in the US and UK shows that worries abound -- about cyberattacks and the lack of resources to defend against them.

πŸ“– Read

via "Dark Reading: ".
❌ WWDC 2019: Apple Takes Aim at Facebook on Privacy ❌

The iPhone-maker announced the 'Sign in with Apple' API, and restrictions on location-tracking.

πŸ“– Read

via "Threatpost".
❌ Tap β€˜n Ghost Attack Creatively Targets Android Devices ❌

Researchers use malicious NFC tags and booby-trapped physical surfaces to connect Android devices to malicious wireless networks.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-14853

The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attacker is able to run shell commands and receive valid output from the device.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14852

An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14851

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14850

All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14728

An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Baltimore Ransomware Attacker Was Behind Now-Suspended Twitter Account πŸ•΄

Researchers at Armor were able to confirm the person or persons behind a Twitter account that appeared to be leaking confidential files was the actual ransomware attacker that hit the city.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Urges Businesses to Patch 'BlueKeep' Flaw πŸ•΄

Fearing another worm of WannaCry severity, Microsoft warns vulnerable users to apply the software update for CVE-2019-0708.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-14854

A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions prior to 2017-09-25.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Zebrocy APT Group Expands Malware Arsenal with New Backdoor Family πŸ•΄

Group's constant experimentation and malware changes are complicating efforts for defenders, Kaspersky Lab says.

πŸ“– Read

via "Dark Reading: ".
⚠ Apple sunsets iTunes ⚠

RIP iTunes, hello to the standalone Music, Podcasts and TV apps that are taking its place.

πŸ“– Read

via "Naked Security".
❌ Infosecurity Europe: Cryptojacking is Making a Comeback ❌

At Infosecurity Europe, a security expert from Guardicore discusses a new cryptomining malware campaign called Nanshou and why the cryptojacking threat is set to get worse.

πŸ“– Read

via "Threatpost".
⚠ US visa applicants required to hand over social media info ⚠

As of Friday, it's no longer optional - the US is been asking for five years of social media information.

πŸ“– Read

via "Naked Security".
⚠ GandCrab ransomware service shuts up shop ⚠

The authors of the GandCrab ransomware strain are shutting their ransomware-as-a-service portal, allegedly walking away with a cool $150m.

πŸ“– Read

via "Naked Security".
⚠ Synthetic clicks and the macOS flaw Apple can’t seem to fix ⚠

A researcher has found a way to abuse synthetic clicks in macOS "Catalina", and it hasn’t even shipped yet.

πŸ“– Read

via "Naked Security".
πŸ” Employees are almost as dangerous to business security as hackers and cybercriminals πŸ”

Non-malicious insiders are among the top three threat actors, according to an ISACA report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to protect your customers' personal identifiable information πŸ”

Personal identifiable information (PII) was the leading type of data breach in 2018, accounting for 97% of all breaches, according to a ForgeRock report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ What Cyber Skills Shortage? πŸ•΄

Employers can solve the skills gap by first recognizing that there isn't an archetypal "cybersecurity job" in the same way that there isn't an archetypal "automotive job." Here's how.

πŸ“– Read

via "Dark Reading: ".