πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Hackers exploit SMS gateways to text millions of US numbers ⚠

Receive any strange SMS text messages recently? If you live in the US, there’s a small chance you might have received an SMS with the following text in the last few days from someone called β€˜j3ws3r on Twitter’: I’m here to warn the masses about SMS email gateways. Please look up how to disable it […]

πŸ“– Read

via "Naked Security".
⚠ Google and Apple suspend contractor access to voice recordings ⚠

Apple and Google have announced that they will limit the way audio recorded by their voice assistants, Siri and Google Assistant, are accessed internally by contractors.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2016-10774

cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10773

cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10772

cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10771

cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10770

cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10769

cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10768

cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10767

cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Fighting Back Against Mobile Fraudsters πŸ•΄

The first step toward identifying and preventing mobile fraud threats is acknowledging that mobile security requires a unique solution.

πŸ“– Read

via "Dark Reading: ".
❌ Google and ARM Tackle Android Bugs with Memory-Tagging ❌

Buffer overflows, race conditions, use-after-free and more account for more than half of all vulnerabilities in the Android platform.

πŸ“– Read

via "Threatpost".
❌ Microsoft Lab Offers $300K For Working Azure Exploits ❌

Microsoft says its Azure Security Lab will allow researchers to attack its cloud environment in a customer-safe way.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2016-10766 (edx-platform)

edx-platform before 2016-06-06 allows CSRF.

πŸ“– Read

via "National Vulnerability Database".
❌ Puzzling Gwmndy Botnet Focuses on Low-Volume Proxy Connections ❌

After infecting Fiberhome routers, its sole purpose seems to be setting up SOCKS5 proxies.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Opens Azure Security Lab, Raises Top Azure Bounty to $40K πŸ•΄

Microsoft has invited security experts to 'come and do their worst' to mimic cybercriminals in the Azure Security Lab.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Database of 200M-Plus Potential 'Sextortion' Victims Published πŸ•΄

Researchers have discovered a botnet (and the database it feeds on) dedicated to extortion schemes.

πŸ“– Read

via "Dark Reading: ".
❌ E3 Website Leaks Private Addresses for Thousands of Journalists ❌

Personal data of 2,000 journalists was found publicly accessible on a spreadsheet on the website for popular trade show E3.

πŸ“– Read

via "Threatpost".
πŸ•΄ Destructive Malware Attacks Up 200% in 2019 πŸ•΄

Organizations hit with destructive malware can lose more than 12,000 machines and face $200 million or more in costs, IBM X-Force reports.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Ransomware Used in Multimillion-Dollar Attacks Gets More Automated πŸ•΄

The authors of MegaCortex appear to have traded security for convenience and speed, say researchers at Accenture iDefense.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Mimecast Rejected Over 67 Million Emails. Here's What It Learned πŸ•΄

New research warns that security pros must guard against updates to older malware and more manipulative social-engineering techniques.

πŸ“– Read

via "Dark Reading: ".