πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2017-14395

Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-14394

OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Inside the FBI's Fight Against Cybercrime πŸ•΄

Heavily outnumbered and outpaced by their targets, small FBI cybersquads have been quietly notching up major wins against online criminals operating out of home and abroad.

πŸ“– Read

via "Dark Reading: ".
⚠ β€œDeeply personal medical” records exposed online ⚠

The Facebook ad agency xSocialMedia exposed 150K medical histories, along with identifying information for the people involved.

πŸ“– Read

via "Naked Security".
⚠ Facebook’s Libra cryptocurrency is big news but will it be secure? ⚠

Unless you’ve been under a rock, you’ll know that earlier this week Facebook announced plans for a new global cryptocurrency for absolutely everyone called Libra.

πŸ“– Read

via "Naked Security".
πŸ•΄ The Hunt for Vulnerabilities πŸ•΄

A road map for improving the update process will help reduce the risks from vulnerabilities.

πŸ“– Read

via "Dark Reading: ".
πŸ” Why tech was key to the KGB being good at espionage πŸ”

The KGB Espionage Museum's Agne Urbaityte explains various technologies and methods of eavesdropping used by the intelligence service, including Deadly Kiss and cameras in rings.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Cybersecurity Accountability Spread Thin in the C-Suite πŸ•΄

While cybersecurity discussions have permeated board meetings, the democratization of accountability has a long way to go.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to respond to phishing emails: 6 steps for G Suite admins πŸ”

Here are steps G Suite administrators should take when a phishing email gets through to an account.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How KGB agents were invisible spies πŸ”

Dan Patterson interviews the KGB Espionage Museum's Agne Urbaityte about how agents in the field would blend in with their environment in order to spy.

πŸ“– Read

via "Security on TechRepublic".
⚠ Google launches new Chrome protection from bad URLs ⚠

The "Suspicious Site Reporter" extension lets users easily report dubious sites, while a new warning flags potential typosquatting pages.

πŸ“– Read

via "Naked Security".
⚠ Update Firefox now! Zero-day found in the wild ⚠

Mozilla has fixed a critical zero-day bug in the latest point releases of the Firefox web browser.

πŸ“– Read

via "Naked Security".
πŸ” KGB agents' wearables: Watches, cufflinks, shoes, and more πŸ”

The KGB Espionage Museum's curator Agne Urbaityte describes how agents concealed spying devices in what they wore when working in the field.

πŸ“– Read

via "Security on TechRepublic".
❌ Cisco DNA Center Critical Flaw Opens Access to Internal Servers ❌

Cisco has patched a slew of critical and high-severity flaws in its DNA Center and SD-WAN.

πŸ“– Read

via "Threatpost".
πŸ” The KGB's eavesdropping and spying devices in everyday items πŸ”

The KGB Espionage Museum's curator Agne Urbaityte explains why and how plates and ashtrays were used as eavesdropping and spying devices.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why tech was key to the KGB being good at espionage πŸ”

The KGB Espionage Museum's Agne Urbaityte explains various technologies and methods of eavesdropping used by the intelligence service, including Deadly Kiss and cameras in rings.

πŸ“– Read

via "Security on TechRepublic".
❌ Tor Browser Issues Update for Critical System Takeover Flaw ❌

The update patches critical flaw (CVE-2019-11707), a type confusion vulnerability in the Mozilla Firefox code that Tor uses.

πŸ“– Read

via "Threatpost".
πŸ•΄ 7 2019 Security Venture Fund Deals You Should Know πŸ•΄

2019 has, so far, been a busy year for venture capitalists in the security industry. Here are 7 funding rounds important because of the technologies or market trends they represent.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Machine Learning Boosts Defenses, But Security Pros Worry Over Attack Potential πŸ•΄

As defenders increasingly use machine learning to remove spam, catch fraud, and block malware, concerns persist that attackers will find ways to use AI technology to their advantage.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-17944

The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Small Businesses May Not Be Security's Weak Link πŸ•΄

Organizations with 250 or fewer employees often employ a higher percentage of security pros than their larger counterparts.

πŸ“– Read

via "Dark Reading: ".