πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Dutch Data Protection Authority Issues First GDPR Fine πŸ”

The fine, against a large hospital, stems from its apparent lack of internal patient record security.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Security Training That Keeps Up with Modern Development πŸ•΄

Black Hat USA speakers to discuss what it will take to 'shift knowledge left' to build up a corps of security-savvy software engineers.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-13897

Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 855, SDA660, SDM630, SDM660

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Johannesburg Ransomware Attack Leaves Residents in the Dark πŸ•΄

The virus affected the network, applications, and databases at City Power, which delivers electricity to the South African financial hub.

πŸ“– Read

via "Dark Reading: ".
❌ New Loader Variant Behind Widespread Malware Attacks ❌

Malware infection technique called TxHollower gets updated with stealthy features.

πŸ“– Read

via "Threatpost".
❌ Streamlining Patch Management: Expert Advice ❌

Webinar examines challenges in patch management and offers solutions to streamline the process.

πŸ“– Read

via "Threatpost".
πŸ•΄ Louisiana Declares Cybersecurity State of Emergency πŸ•΄

A series of attacks on school district systems leads the governor to declare the state's first cybersecurity state of emergency.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Russian Threat Group May Have Devised a 'Man-on-the-Side' Attack πŸ•΄

Data from an intrusion last year suggests Iron Liberty group may have a new trick up its sleeve, Secureworks says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Android Spyware Has Ties to Election Interference πŸ•΄

Recently revealed surveillance-ware comes from a consultant with close ties to Russia's GRU who was sanctioned by the US for election-tampering.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Senate Report: US Election Security 'Sorely Lacking' in 2016 πŸ•΄

Senate Intelligence Committee report released today cites weaknesses, but finds no evidence of vote-tampering.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-0202

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11779

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.

πŸ“– Read

via "National Vulnerability Database".
⚠ S2 Ep1: FaceApp, logic bombs and stranger danger – Naked Security Podcast ⚠

We’re finally back with Series 2 of the Naked Security Podcast. While you’ve been missing us, we’ve been working out how to improve the show and kitting out a dedicated studio. You’ll now find longer episodes with more opportunities to get involved. Send us your general cybersecurity questions and join the discussion via social media […]

πŸ“– Read

via "Naked Security".
⚠ Browser plug-ins peddled personal data from over 4m browsers ⚠

Nacho Analytics gathered data like passwords, tax and prescription data from browser add-ons - and those who bought it can keep it.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2018-20856

An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-20855

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-20854

An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error with a resultant ctrl->phys out-of-bounds read.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ What Every Security Team Should Know About Internet Threats πŸ•΄

Of particular interest for cybercriminals is the Domain Name System, which plays a central role in orchestrating all Internet and application traffic.

πŸ“– Read

via "Dark Reading: ".
⚠ BlueKeep guides make imminent public exploit more likely ⚠

A public exploit for Microsoft's BlueKeep vulnerability is just days away. In fact, for those with deep pockets, it's already here.

πŸ“– Read

via "Naked Security".
πŸ•΄ Black Hat Q&A: Inside the Black Hat NOC πŸ•΄

Cybersecurity expert Bart Stump explains what it's like to reliably deliver a useful, high-security network for one of the toughest audiences in the world.

πŸ“– Read

via "Dark Reading: ".