πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Five Eyes nations demand access to encrypted messaging ⚠

The alliance wants tech companies to build backdoor access to users’ encrypted data, by force if necessary.

πŸ“– Read

via "Naked Security".
⚠ North Carolina county falls for BEC scam, to the tune of $1,728,083 ⚠

The county could only claw back some of the $2,504,601 it paid to a scammer posing as a contractor working on building a new high school.

πŸ“– Read

via "Naked Security".
πŸ•΄ A Realistic Path Forward for Security Orchestration and Automation πŸ•΄

Security teams often look to technology to solve their security challenges. Yet sometimes investing in new products can create more issues.

πŸ“– Read

via "Dark Reading: ".
⚠ Researchers hack camera in fake video attack ⚠

Tampering with surveillance cameras is a common activity for Hollywood heroes and criminals alike. Now, researchers have shown how they can do it in real life.

πŸ“– Read

via "Naked Security".
πŸ” Top 10 IoT security risks for businesses πŸ”

Organizations must adopt a security-by-design approach to best combat threats created by the Internet of Things, according to Deloitte.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ SecOps Success Through Employee Retention πŸ•΄

To keep your turnover low, focus on these areas: compensation, advancement opportunities, training, and environment.

πŸ“– Read

via "Dark Reading: ".
❌ For $8.6M, Cisco Settles Suit Over Bug-Riddled Video Surveillance Software ❌

The complaint claims the networking giant knowingly sold bug-riddled software to federal and state governments, that would allow complete network compromise.

πŸ“– Read

via "Threatpost".
πŸ” On Sharing Data While Maintaining Compliance in the U.K. πŸ”

The U.K.'s data protection authority recently issued new draft guidelines to sharing data while maintaining compliance.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Unpatched Flaws in IoT Smart Deadbolt Open Homes to Danger ❌

Researchers are warning that unpatched flaws found in the Hickory Smart BlueTooth Enabled Deadbolt allow an attacker with access to a victim's phone to break into their houses.

πŸ“– Read

via "Threatpost".
❌ Brand-New SystemBC Proxy Malware Spotted Using SOCKS5 for Stealth ❌

The proxy is being distributed by the RIG and Fallout exploit kits.

πŸ“– Read

via "Threatpost".
πŸ” How to build a vulnerability response plan: 6 tips πŸ”

Cybersecurity vulnerabilities continue to increase, and automated scanners can't always detect the most critical ones, according to Bugcrowd.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2016-10852

cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10851

cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10850

cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9291

cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7559

It was found that the Apache ActiveMQ client before 5.15.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-8183

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7474

Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7473

Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to use a Yubikey on Linux with an encrypted drive πŸ”

Looking to use a Yubikey for added security on your encrypted Linux drives? With a few quick commands, you'll enjoy that added layer of security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Demystifying New FIDO Standards & Innovations πŸ•΄

Staying on top of the latest cybersecurity risks and preferred attack methods can feel impossible, but standards like FIDO2 are designed to help relieve the burden.

πŸ“– Read

via "Dark Reading: ".