πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 12 AppSec Activities Enterprises Can't Afford to Skip πŸ•΄

The latest Building Security in Maturity Model (BSIMM9) report offers a statistically backed, bare-minimum benchmark for software security initiatives.

πŸ“– Read

via "Dark Reading: ".
❌ Threatpost New Wrap Podcast For Oct. 5 ❌

Threatpost editors discuss the highlights and biggest breaking news from this past week.

πŸ“– Read

via "The first stop for security news | Threatpost ".
❌ D-Link Patches RCE Bugs in Wireless Access Point Gear ❌

 D-Link has released the beta version of the controller which addresses the reported vulnerabilities.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ Successful Scammers Call After Lunch πŸ•΄

Analysis of 20,000 voice phishing, or vishing, calls reveals patterns in how hackers operate.

πŸ“– Read

via "Dark Reading: ".
❌ Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat ❌

A spyware attack on a Saudi dissident living in Canada made headlines this week, but Citizen Lab warns that simpler attacks are the real epidemic.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ Most Home Routers Are Full of Vulnerabilities πŸ•΄

More than 80% of surveyed routers had, on average, 172 security vulnerabilities, new research shows.

πŸ“– Read

via "Dark Reading: ".
❌ Sony Smart TV Bug Allows Remote Access, Root Privileges ❌

Software patching becomes a new reality for smart TV owners.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ Mandia: Tipping Point Now Here for Rules of Cyber Engagement πŸ•΄

FireEye CEO and nation-state hacking expert Kevin Mandia says Russia began changing the game in 2015.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybersecurity investments: Why ROI calculations may not tell the whole story πŸ”

Cybersecurity spends are about loss prevention not earnings, suggests security expert Bruce Schneier. Thankfully, there are better options to ensure cybersecurity investments are maximized.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2015-9273

The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-6710

ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.

πŸ“– Read

via "National Vulnerability Database".
❌ PoC Attack Escalates MikroTik Router Bug to β€˜As Bad As It Gets’ ❌

Researchers say a medium severity bug should now be rated critical because of a new hack technique that allows for remote code execution on MikroTik edge and consumer routers.

πŸ“– Read

via "The first stop for security news | Threatpost ".
⚠ Monday review – the hot 19 stories of the week ⚠

From the iOS lockscreen bypass to Facebook using your 2FA phone number to target market you, and everything we wrote in between. Catch up with the news from the last seven days - it's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Seven Russian cyberspies indicted for hacking, wire fraud, ID theft ⚠

"Bungling" Russian GRU operatives picked up by Dutch police, linked to OPCW and World Anti-Doping Agency hacks.

πŸ“– Read

via "Naked Security".
⚠ Fitbit data leads to arrest of 90-year-old in stepdaughter’s murder ⚠

Her device recorded her heart rate slowing rapidly, then stopping about five minutes before her stepfather left the house.

πŸ“– Read

via "Naked Security".
⚠ Attackers use voicemail hack to steal WhatsApp accounts ⚠

The Israeli National Cybersecurity Authority issued an alert warning that WhatsApp users could lose control of their accounts.

πŸ“– Read

via "Naked Security".
⚠ Phantom Secure CEO sold encrypted phones to drug cartels ⚠

The CEO of β€œuncrackable” phone seller, Phantom Secure, has pleaded guilty to helping drug sellers keep their business locked away from the eyes of law enforcement.

πŸ“– Read

via "Naked Security".
πŸ•΄ Teach Your AI Well: A Potential New Bottleneck for Cybersecurity πŸ•΄

Artificial intelligence (AI) holds the promise of easing the skills shortage in cybersecurity, but implementing AI may result in a talent gap of its own for the industry.

πŸ“– Read

via "Dark Reading: ".
πŸ” 5 tips to secure your supply chain from cyberattacks πŸ”

It's nearly impossible to secure supply chains from attacks like the alleged Chinese chip hack that was reported last week. But here are some tips to protect your company.

πŸ“– Read

via "Security on TechRepublic".
⚠ Unpatched routers bad, doubly unpatched routers worse – much, much worse! ⚠

Two bugs can be four times the trouble! If you missed the last Microtik router patch, you're at risk, but if you're *two* patches behind ...

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2016-7475

Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic Management Microkernel (TMM) may not properly clean-up pool member network connections when using SPDY or HTTP/2 virtual server profiles.

πŸ“– Read

via "National Vulnerability Database".