πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Transforming 'Tangible Security' into a Competitive Advantage πŸ•΄

Today's consumers want to see and touch security. Meeting this demand will be a win-win for everyone, from users to vendors to security teams.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Capital One Breach Affects 100M US Citizens, 6M Canadians πŸ•΄

The breach exposed credit card application data, Social Security numbers, and linked bank accounts, among other information.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-16871

A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Insecure Real-Time Video Protocols Allow Hollywood-Style Hacking πŸ•΄

Lack of security in the default settings of Internet-enabled video cameras make co-opting video feeds not just a movie-hacker technique, but a reality for millions of cameras.

πŸ“– Read

via "Dark Reading: ".
πŸ” New York Updates Data Breach Notification Law πŸ”

The law, which updates data breach notification requirements in the state, was one of two forms of legislation signed last week to better protect New York residents against security breaches.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Suffering SOC Saga Continues πŸ•΄

New study exposes low confidence among security professionals in their security operations centers.

πŸ“– Read

via "Dark Reading: ".
❌ Apple iMessage Allows Remote Attackers to Read iPhone Messages, Images ❌

Remote exploitation can be achieved with no user interaction.

πŸ“– Read

via "Threatpost".
πŸ•΄ Apple iOS Flaw Could Give Attacker Access via iMessage πŸ•΄

Google Project Zero researchers found an iOS vulnerability that could let an attacker snoop on a victim's phone remotely.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-18381

The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

πŸ“– Read

via "National Vulnerability Database".
❌ DHS Warning: Small Aircraft are Ripe for Hacking ❌

Hackers with physical access to small aircraft can easily hack the plane's CAN bus system and take control of key navigation systems.

πŸ“– Read

via "Threatpost".
πŸ•΄ Container Security Is Falling Behind Container Deployments πŸ•΄

Organizations are increasingly turning to containers even though they are not as confident in the security of those containers, according to a new survey.

πŸ“– Read

via "Dark Reading: ".
⚠ Cyberattacks on connected cars could gridlock entire cities ⚠

It would require taking over and stranding 20% of a city's cars to freeze traffic, and only 10% to impede ambulances, physicists calculate.

πŸ“– Read

via "Naked Security".
πŸ•΄ Keep Your Eye on Digital Certificates πŸ•΄

X.509 certificates help secure the identity, privacy, and communication between two endpoints, but these digital certificates also have built-in expirations and must be managed.

πŸ“– Read

via "Dark Reading: ".
πŸ” SanDisk's SSD Dashboard uses hardcoded password, lacks encrypted updates πŸ”

Lackadaisical security practices in proprietary management software from a hardware vendor underscore the need for a vendor-agnostic solution.

πŸ“– Read

via "Security on TechRepublic".
πŸ” iOS and Android patched 440 security vulnerabilities in 2019, so far πŸ”

Android patched more CVEs than Apple did, according to a Zimperium report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Capital One is not alone: 3.5B malicious login attacks target banks and customers πŸ”

Phishing and credential stuffing attacks are top threats to financial services organizations and customers, according to Akamai.

πŸ“– Read

via "Security on TechRepublic".
❌ Black Hat USA 2019 Preview ❌

Threatpost editors discuss the top trends, keynotes and sessions that they look forward to at Black Hat USA and DEF CON 2019.

πŸ“– Read

via "Threatpost".
⚠ Georgia hit with malware yet again ⚠

The Department of Public Safety says it won't pay, but given the umpteen times the state's agencies have been hit, somebody's not listening.

πŸ“– Read

via "Naked Security".
⚠ iMessage bug could have allowed attackers to read data from any iPhone ⚠

Google's Project Zero has unveiled details of a bug in Apple's iMessage that lets attackers read data from an iPhone without any user interaction.

πŸ“– Read

via "Naked Security".