πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 'Lone Wolf' Scammer Built a Multifaceted BEC Cybercrime Operation πŸ•΄

A one-man 419 scam evolved into a lucrative social-engineering syndicate over the past decade that conducts a combination of business email compromise, romance, and financial fraud.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to integrate Spamassassin with Postfix Mail Server πŸ”

The task of preventing the never-ending flow of spam gets a bit simpler with Spamassassin and Postfix.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Want less spam? Learn how to integrate Spamassassin with Postfix Mail Server πŸ”

The task of preventing the never-ending flow of spam gets a bit simpler with Spamassassin and Postfix.

πŸ“– Read

via "Security on TechRepublic".
❌ Microsoft Warns of Email Attacks Executing Code Using an Old Bug ❌

The flaw affected all versions of Microsoft Office, Microsoft Windows and architecture types dating back to 2000, and was patched in November 2017.

πŸ“– Read

via "Threatpost".
❌ How to Model Risk in an Apex Predator Cyber-World ❌

Large-scale existential threats exist everywhere and can annihilate us with only trivial effort. Should we all throw everything we can at them?

πŸ“– Read

via "Threatpost".
πŸ” Stop ignoring hybrid cloud security risks πŸ”

Karen Roby talks with a security expert about safeguarding the enterprise in a hybrid IT world.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Breaking Down LGPD, Brazil’s New Data Protection Law πŸ”

Brazil's GDPR-like data protection law, LGPD, owes a lot to the EU regulation but has several key differences that organizations that do business in the country should be familiar with.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ GoldBrute Botnet Brute-Forcing 1.5M RDP Servers πŸ•΄

Botnets are scanning the Internet for servers exposing RDP and using weak, reused passwords to obtain access.

πŸ“– Read

via "Dark Reading: ".
πŸ” Photos: Cisco Live 2019 keynote and highlights πŸ”

TechRepublic's Teena Maddox attended Cisco's premier education and training event for IT professionals in San Diego, CA.

πŸ“– Read

via "Security on TechRepublic".
❌ WordPress Sites Worldwide Hit with β€˜Call-Girl’ Search-Engine Pollution ❌

A web spam campaign targeting Koreans is affecting non-hacked websites worldwide.

πŸ“– Read

via "Threatpost".
❌ Mozilla Confirms Premium Firefox Browser With Security Features ❌

A future premium Firefox browser could come with security features like VPN and secure cloud solutions.

πŸ“– Read

via "Threatpost".
πŸ” Stop ignoring hybrid cloud security risks πŸ”

Karen Roby talks with Ping Identity security expert about safeguarding the enterprise in a hybrid IT world.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Voting Machine Vendor Shifts Gears & Pushes for Backup Paper Ballots πŸ•΄

Election Systems & Software will 'no longer sell paperless voting machines,' CEO said.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cognitive Bias Can Help Shape Security Decisions πŸ•΄

A new report sheds light on how human cognitive biases affect cybersecurity decisions and business outcomes.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Huawei Represents Massive Supply Chain Risk: Report πŸ•΄

The Chinese technology giant's enormous product and service footprint gives it access to more data than almost any other single organization, Recorded Future says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Federal Photos Filched in Contractor Breach πŸ•΄

Data should never have been on subcontractor's servers, says Customs and Border Protection.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cognitive Bias Can Hamper Security Decisions πŸ•΄

A new report sheds light on how human cognitive biases affect cybersecurity decisions and business outcomes.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-13718

The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings and PIN, as well as port forward and expose any internal device's port to the Internet. It was identified that the device uses custom Python code called "rodman" that allows the mobile appication to interact with the device. The APIs that are a part of this rodman Python file allow the mobile application to interact with the device using a secret, which is a uuid4 based session identifier generated by the device the first time it is set up. However, in some cases, these APIs can also use a security code. This security code is nothing but the PIN number set by the user to interact with the device when using the touch interface on the router. This allows an attacker on the Internet to interact with the router's HTTP interface when a user navigates to the attacker's website, and brute force the credentials. Also, since the device's server sets the Access-Control-Allow-Origin header to "*", an attacker can easily interact with the JSON payload returned by the device and steal sensitive information about the device.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-13717

Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute force the credentials and pull any information that is stored on the device. In this case, a user's Wi-Fi credentials are stored in clear text on the device and can be pulled easily.

πŸ“– Read

via "National Vulnerability Database".
⚠ Researchers crack digital safe using HSM flaw ⚠

French researchers have found a bug in a hardware security module (HSM) that could enable an attacker to steal highly prized secrets.

πŸ“– Read

via "Naked Security".