πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Latest FinSpy Modules Lift Data from Secure Messaging Apps ❌

The espionage tool is capable of eavesdropping on calls and messages sent via Signal, Telegram, WhatsApp and more.

πŸ“– Read

via "Threatpost".
πŸ•΄ Intel Releases Updates for Storage & Diagnostic Tools πŸ•΄

CISA released an alert telling users about the updates to firmware in Intel SSD and Processor Diagnostic products.

πŸ“– Read

via "Dark Reading: ".
❌ Zoom Pushes Emergency Patch for Webcam Hijack Flaw ❌

After media scrutiny, the collaboration service has decided to address the zero-day after initially dismissing its severity.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-7189

main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the address/port were 127.0.0.1:80:443, which is later truncated to 127.0.0.1:80. This behavior has a security risk if the explicitly provided port number (i.e., 443 in this example) is hardcoded into an application as a security policy, but the hostname argument (i.e., 127.0.0.1:80 in this example) is obtained from untrusted input.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6217

paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12652

libpng before 1.6.32 does not properly check the length of chunks against the user limit.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Vulnerability Found in GE Anesthesia Machines πŸ•΄

GE Healthcare has released a statement claiming the bug is not in the machine itself and does not pose direct risk to patients.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why You Need a Global View of IT Assets πŸ•΄

It may seem obvious, but many companies lose sight of the fact that they can't protect what they don't know they even have.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-10531

An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks.

πŸ“– Read

via "National Vulnerability Database".
πŸ” US Coast Guard Issues Cybersecurity Best Practices for Ships πŸ”

In addition to a list of best practices, the Coast Guard confirmed in an alert this week that malware affected the shipboard network of a vessel in February.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ New Ransomware Targets QNAP's Network-Attached Storage Devices πŸ•΄

More than 19,000 systems in the US are potentially at risk from eCh0raix.

πŸ“– Read

via "Dark Reading: ".
❌ Bug in Anesthesia Respirators Allows Cyber-Tampering ❌

GE Healthcare said an attacker could modify gas composition parameters within the devices' respirator function.

πŸ“– Read

via "Threatpost".
πŸ•΄ Financial Firms Face Threats from Employee Mobile Devices πŸ•΄

A new report says that phishing and man-in-the-middle attacks are major risks to financial institutions - via mobile devices in the hands of their employees.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Industry Insight: Checking Up on Healthcare Security πŸ•΄

Modern threats putting healthcare organization at risk, how they're improving their security posture, and where many fall short.

πŸ“– Read

via "Dark Reading: ".
⚠ β€œMozilla aren’t villains after all” – ISPs back down after public outcry ⚠

Mozilla was nominated for an "Internet Villain" award - and The People Of The Internet were not pleased

πŸ“– Read

via "Naked Security".
⚠ GDPR superpowers lead to whopper ICO fines for BA, Marriott ⚠

The ICO isn't pulling its punches: The penalty for BA's data breach is about 367 times higher than the previous record-setting fine.

πŸ“– Read

via "Naked Security".
⚠ Cyberattack lands ship in hot water ⚠

Less than two months after warning of cybersecurity problems on ships, the US Coast Guard has revealed that a large international vessel has suffered a cyberattack.

πŸ“– Read

via "Naked Security".
πŸ” Cybersecurity: Malware lingers in SMBs for an average of 800 days before discovery πŸ”

Small and medium-sized businesses lack the IT staff needed to run comprehensive security detection and response, according to Infocyte.

πŸ“– Read

via "Security on TechRepublic".
❌ Implementing Bug Bounty Programs: The Right and Wrong Approaches ❌

Threatpost catches up with David Baker, the chief security officer at Bugcrowd, about the future of bug bounty programs.

πŸ“– Read

via "Threatpost".