πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ BlueKeep guides make imminent public exploit more likely ⚠

A public exploit for Microsoft's BlueKeep vulnerability is just days away. In fact, for those with deep pockets, it's already here.

πŸ“– Read

via "Naked Security".
πŸ•΄ Black Hat Q&A: Inside the Black Hat NOC πŸ•΄

Cybersecurity expert Bart Stump explains what it's like to reliably deliver a useful, high-security network for one of the toughest audiences in the world.

πŸ“– Read

via "Dark Reading: ".
⚠ Happy SysAdminDay 2019! ⚠

Hey sysadmin, nice tee.

πŸ“– Read

via "Naked Security".
πŸ•΄ 3 Takeaways from the First American Financial Breach πŸ•΄

Data leaks from business logic flaws are not well understood and difficult to identify before they reach production environments. Here's how to find and prevent them.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-20857

Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Black Hat Q&A: Inside the Black Hat NOC πŸ•΄

Cybersecurity expert Bart Stump explains what it's like to reliably deliver a useful, high-security network for one of the toughest audiences in the world.

πŸ“– Read

via "Dark Reading: ".
πŸ” 66% of SMBs don't believe they are vulnerable to cyberattacks πŸ”

SMBs aren't prioritizing cybersecurity prevention strategies, even though they are at risk of attack, according to a Keeper Security report.

πŸ“– Read

via "Security on TechRepublic".
⚠ Sysadmins need to know – how DO you pronounce β€œsudo”? ⚠

We take on one of #SysAdminDay's thorny issues.

πŸ“– Read

via "Naked Security".
πŸ•΄ FormGet Storage Bucket Leaks Passport Scans, Bank Details πŸ•΄

Exposed files include mortgage and loan information, passport and driver's license scans, internal corporate files, and shipping labels.

πŸ“– Read

via "Dark Reading: ".
πŸ” Friday Five: 7/26 Edition πŸ”

News about a new phishing campaign targeting Office 365 admins, the FTC's big Facebook fine, and the latest data breach statistics are all covered in this week's Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2018-17210 (central_print_services)

An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks (that would otherwise logout a low-privileged user) by calling the core print job components directly via crafted HTTP GET and POST requests.

πŸ“– Read

via "National Vulnerability Database".
❌ β€˜Google’ Sites Are the Latest Ploy by Card-Skimming Thieves ❌

A credit-card skimmer on Magento sites was found loading JavaScript from a legitimate-seeming Google Analytics domain.

πŸ“– Read

via "Threatpost".
πŸ•΄ Companies' 'Anonymized' Data May Violate GDPR, Privacy Regs πŸ•΄

New study found that any database containing 15 pieces of demographic data could be used to identify individuals.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Complete Personal Fraud Kits Sell for Less Than $40 on Dark Web πŸ•΄

The low cost of records reflects the huge supply of PII after many breaches at hospitals, government agencies, and credit bureaus.

πŸ“– Read

via "Dark Reading: ".
❌ Gamers Are Easy Prey for Credential Thieves ❌

Gamers are easy pickings for credential crooks, thanks to lax security hygiene and poor gaming company practices.

πŸ“– Read

via "Threatpost".
❌ Rare Steganography Hack Can Compromise Fully Patched Websites ❌

Attackers are hiding PHP scripts in EXIF headers of JPEG images to hack websites, just by uploading an image.

πŸ“– Read

via "Threatpost".
πŸ•΄ Malware Researcher Hutchins Sentenced to Supervised Release πŸ•΄

Marcus Hutchins, the researcher known for stopping WannaCry, avoids jail time over charges of creating and distributing Kronos malware.

πŸ“– Read

via "Dark Reading: ".
❌ Louisiana Gov Declares Emergency After Cyberattacks Plague Schools ❌

Attacks on at least three school districts and likely others have prompted the state's first emergency due to cyberattack.

πŸ“– Read

via "Threatpost".
⚠ WannaCry hero gets off lightly, avoids prison – was justice done? ⚠

Wrote malware for money, went straight, got busted, didn't go to prison. Has US cybercrime enforcement gone soft?

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2017-18379

In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.

πŸ“– Read

via "National Vulnerability Database".