πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Nation-State Actors Go All-In on Mobile Malware ❌

Even though mobile data security is less mature than its desktop equivalent, the quality of the information on offer is top-tier.

πŸ“– Read

via "Threatpost".
πŸ” How to protect your corporate bank account after the Capital One breach: 10 tips πŸ”

A Capital One data breach put the data of 106 million people at risk, including social security numbers and banking information.

πŸ“– Read

via "Security on TechRepublic".
⚠ Capital One breach – 100 million users’ data stolen ⚠

Global financial services company Capital One has just announced a massive data breach.

πŸ“– Read

via "Naked Security".
πŸ•΄ BlueKeep Exploits Appear as Security Firms Continue to Worry About Cyberattack πŸ•΄

The lack of an attack has puzzled some security experts, but the general advice remains that companies should patch their vulnerable systems more quickly.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ DHS Warns About Security Flaws in Small Airplanes πŸ•΄

Rapid7 researchers found holes in CAN bus networks that an attacker could exploit to sabotage its operation.

πŸ“– Read

via "Dark Reading: ".
❌ Android Ransomware Spreads Via β€˜Sex Simulation Game’ Links on Reddit, SMS ❌

A new strain of ransomware is being distributed to Android users via online forums and SMS messages.

πŸ“– Read

via "Threatpost".
πŸ•΄ Transforming 'Tangible Security' into a Competitive Advantage πŸ•΄

Today's consumers want to see and touch security. Meeting this demand will be a win-win for everyone, from users to vendors to security teams.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Capital One Breach Affects 100M US Citizens, 6M Canadians πŸ•΄

The breach exposed credit card application data, Social Security numbers, and linked bank accounts, among other information.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-16871

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Insecure Real-Time Video Protocols Allow Hollywood-Style Hacking πŸ•΄

Lack of security in the default settings of Internet-enabled video cameras make co-opting video feeds not just a movie-hacker technique, but a reality for millions of cameras.

πŸ“– Read

via "Dark Reading: ".
πŸ” New York Updates Data Breach Notification Law πŸ”

The law, which updates data breach notification requirements in the state, was one of two forms of legislation signed last week to better protect New York residents against security breaches.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Suffering SOC Saga Continues πŸ•΄

New study exposes low confidence among security professionals in their security operations centers.

πŸ“– Read

via "Dark Reading: ".
❌ Apple iMessage Allows Remote Attackers to Read iPhone Messages, Images ❌

Remote exploitation can be achieved with no user interaction.

πŸ“– Read

via "Threatpost".
πŸ•΄ Apple iOS Flaw Could Give Attacker Access via iMessage πŸ•΄

Google Project Zero researchers found an iOS vulnerability that could let an attacker snoop on a victim's phone remotely.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-18381

The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

πŸ“– Read

via "National Vulnerability Database".
❌ DHS Warning: Small Aircraft are Ripe for Hacking ❌

Hackers with physical access to small aircraft can easily hack the plane's CAN bus system and take control of key navigation systems.

πŸ“– Read

via "Threatpost".
πŸ•΄ Container Security Is Falling Behind Container Deployments πŸ•΄

Organizations are increasingly turning to containers even though they are not as confident in the security of those containers, according to a new survey.

πŸ“– Read

via "Dark Reading: ".
⚠ Cyberattacks on connected cars could gridlock entire cities ⚠

It would require taking over and stranding 20% of a city's cars to freeze traffic, and only 10% to impede ambulances, physicists calculate.

πŸ“– Read

via "Naked Security".
πŸ•΄ Keep Your Eye on Digital Certificates πŸ•΄

X.509 certificates help secure the identity, privacy, and communication between two endpoints, but these digital certificates also have built-in expirations and must be managed.

πŸ“– Read

via "Dark Reading: ".
πŸ” SanDisk's SSD Dashboard uses hardcoded password, lacks encrypted updates πŸ”

Lackadaisical security practices in proprietary management software from a hardware vendor underscore the need for a vendor-agnostic solution.

πŸ“– Read

via "Security on TechRepublic".