πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Zero-Day No More: Windows Bug Gets a Fix ❌

0patch has released an interim micropatch for the dangerous LPE bug while we wait for Microsoft's official patch.

πŸ“– Read

via "Threatpost".
πŸ•΄ 7 Container Components That Increase a Network's Security πŸ•΄

A proof of concept at Interop19 showed just how simple a container deployment can be.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Robbinhood: Inside the Ransomware That Slammed Baltimore πŸ•΄

Attackers appear to have used a ransomware-as-a-service platform to wage the attack.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 2.8 Billion US Consumer Records Lost in 2018 πŸ•΄

Healthcare breaches grew 400%, study shows.

πŸ“– Read

via "Dark Reading: ".
❌ Is β€˜Sign in with Apple’ Marketing Spin or Privacy Magic? Experts Weigh In ❌

The login scheme promises it won't share data -- and will be required for all developers using third-party sign-ins.

πŸ“– Read

via "Threatpost".
πŸ•΄ Carbanak Attack: Two Hours to Total Compromise πŸ•΄

Investigation of the cybercrime group's attack on an East European bank shows how some attackers require very little time to broaden their access and establish persistence on a network.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-13384

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13382

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13381

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13380

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13379

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Adware Hidden in Android Apps Downloaded More Than 440 Million Times πŸ•΄

The heavily obfuscated adware was found in 238 different apps on Google Play.

πŸ“– Read

via "Dark Reading: ".
⚠ Apple battles Facebook and Google with rival sign in service ⚠

Apple's WWDC was full of surprises including a new feature designed to make signing up for websites more private: Sign In with Apple.

πŸ“– Read

via "Naked Security".
⚠ ATM skimming crook behind bars after draining bank accounts for 2 years ⚠

A multi-state ATM card-skimming spree netted his gang over $800k from 531 people's bank accounts.

πŸ“– Read

via "Naked Security".
⚠ Apple bans ads, third-party tracking in apps meant for kids ⚠

The new policy: Ditch third-party trackers in apps designed for youngsters, lest the app get booted out of the App Store.

πŸ“– Read

via "Naked Security".
⚠ Patch Android! June 2019 update fixes eight critical flaws ⚠

It's that time again. June's patches for Android are here.

πŸ“– Read

via "Naked Security".
❌ Newly-Identified BEC Cybergang Targets U.S. Enterprise Victims ❌

At Infosecurity Europe, researchers detailed a cybergang that grew from a one-man shop launching Craigslist scams to a full-on enterprise BEC group.

πŸ“– Read

via "Threatpost".
❌ Podcast: Behind-the-Scenes Look at Scattered Canary BEC Cybergang ❌

At Infosecurity Europe, Threatpost gets a behind-the-scenes look at the discovery of BEC cybergang Scattered Canary.

πŸ“– Read

via "Threatpost".
πŸ” iOS developers still failing to build end-to-end encryption into apps πŸ”

Despite a mandate from Apple, 68% of developers disable ATS globally on their apps, according to a Wandera report.

πŸ“– Read

via "Security on TechRepublic".
❌ Why Election Trust is Dwindling in a Post-Cambridge Analytica World ❌

As more data is collected, shared and sold, people are growing increasingly distrustful of technology, an expert said at Infosecurity Europe Wednesday.

πŸ“– Read

via "Threatpost".
❌ BlueKeep β€˜Mega-Worm’ Looms as Fresh PoC Shows Full System Takeover ❌

A working exploit for the critical remote code-execution flaw shows how an unauthenticated attacker can achieve full run of a victim machine in about 22 seconds.

πŸ“– Read

via "Threatpost".