πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Google throws bug bounty bucks at mega-popular third-party apps ⚠

Google’s going to throw more bug bounty money at the problem of nasty apps in its Play Store, it announced on Thursday. In a post from the Android Security & Privacy team’s Adam Bacchus, Sebastian Porst, and Patrick Mutchlerβ€Š, the company said that it’s throwing the security net over not just its own apps, but […]

πŸ“– Read

via "Naked Security".
❌ Gamification Can Transform Company Cybersecurity Culture ❌

Implementing game mechanics and competition into the mix can incentivize employees to improve their cybersecurity posture.

πŸ“– Read

via "Threatpost".
πŸ•΄ ISAC 101: Unlocking the Power of Information πŸ•΄

How information sharing and analysis centers provide contextual threat information by creating communities that helps security professionals and their organizations grow in maturity and capability.

πŸ“– Read

via "Dark Reading: ".
⚠ WordPress sites are being backdoored with rogue admin users ⚠

A malvertising campaign has evolved to give hackers control of entire sites.

πŸ“– Read

via "Naked Security".
⚠ XKCD forums breached ⚠

How did the Correct Horse Battery get Stapled?

πŸ“– Read

via "Naked Security".
⚠ FBI asks Google for help finding criminals ⚠

FBI agents issued Google with a warrant in November 2018, seeking its help with a bank robbery the month before.

πŸ“– Read

via "Naked Security".
⚠ China’s new face-swapping app Zao gets whiplash-fast privacy backlash ⚠

Fast trip: in two days, it debuted, shot to the top of China's App Store, sparked privacy outrage, and got banned by WeChat.

πŸ“– Read

via "Naked Security".
❌ β€˜USBAnywhere’ Bugs Open Supermicro Servers to Remote Attackers ❌

Trivial-to-exploit authentication flaws can give an unsophisticated remote attacker 'omnipotent' control over a server and its contents.

πŸ“– Read

via "Threatpost".
⚠ iPhone attack may have targeted Android and Windows too ⚠

A sophisticated and sustained watering hole attack affecting iPhones may have targeted Windows and Android too.

πŸ“– Read

via "Naked Security".
❌ Data Leak Impacts Millions of Yves Rocher Cosmetics Company Customers ❌

International cosmetics brand Yves Rocher found itself caught in a third-party data exposure incident that leaked the personal information of millions of customers.

πŸ“– Read

via "Threatpost".
πŸ” Part 4: Why Frank Abagnale, security expert and inspiration for the hit movie Catch Me if You Can, likes blockchain and dislikes cryptocurrency πŸ”

Frank Abagnale, the real life subject of the movie Catch Me If You Can, shares his views on blockchain, passwords, and cryptocurrency.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why cybersecurity is a big problem for small businesses πŸ”

Cybersecurity attacks can cripple small businesses that aren't prepared. TechRepublic's Karen Roby talks with a security expert about ransomware, phishing attacks, and inadequate IT defense plans.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Why cybersecurity is a big problem for small businesses πŸ”

Cybersecurity attacks can cripple small businesses that aren't prepared. TechRepublic's Karen Roby talks with a security expert about ransomware, phishing attacks, and inadequate IT defense plans.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Report: Iranian 'Mole' Carried Stuxnet to Iranian Nuclear Facility πŸ•΄

An engineer recruited by the Dutch intelligence agency AIVD helped bring to Iran's Natanz nuclear facility the malware via USB that ultimately infected systems there and sabotaged centrifuges, according to an exclusive report from Yahoo News.

πŸ“– Read

via "Dark Reading: ".
❌ WordPress Plugins Anchor Widespread Malvertising, Rogue Backdoor Campaign ❌

An ongoing attack on websites has added new exploits and an administrative backdoor to its bag of tricks.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9355 (two-factor-authentication)

The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 3 Promising Technologies Making an Impact on Cybersecurity πŸ•΄

The common thread: Each acts as a force multiplier, adding value to every other security technology around it.

πŸ“– Read

via "Dark Reading: ".
❌ How to Get a Handle on Patch Management ❌

As the number vulnerabilities hit a historic high, battle-worn security teams are upping their patching game.

πŸ“– Read

via "Threatpost".
❌ Firefox 69 Release Kills Default Tracking Cookies, Flash Support ❌

Mozilla's newest Firefox iteration also offers new fixes for critical and high-severity vulnerabilities.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9358 (feedwordpress)

The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().

πŸ“– Read

via "National Vulnerability Database".