πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Phishing Campaign Uses SharePoint to Slip Past Defenses πŸ•΄

Cybercriminals targeting financial institutions in the UK bypassed Symantec email gateway and other perimeter technologies.

πŸ“– Read

via "Dark Reading: ".
❌ Android Zero-Day Bug Opens Door to Privilege Escalation Attack, Researchers Warn ❌

The zero-day vulnerability could enable privilege escalation, and is not part of Google's Android September security update.

πŸ“– Read

via "Threatpost".
πŸ•΄ 5G Standard to Get New Security Specifications πŸ•΄

Researchers had recently demonstrated how attackers could intercept device capability information and use it against 5G mobile subscribers.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Meet FPGA: The Tiny, Powerful, Hackable Bit of Silicon at the Heart of IoT πŸ•΄

Field-Programmable Gate Arrays are flexible, agile-friendly components that populate many infrastructure and IoT devices -- and have recently become the targets of researchers finding vulnerabilities.

πŸ“– Read

via "Dark Reading: ".
⚠ S2 Ep7: iPhone attack, Twitter hack and Android bots – Naked Security Podcast ⚠

Episode 7 of the Naked Security podcast is available now!

πŸ“– Read

via "Naked Security".
❌ Leaky Server Exposes 419M Phone Numbers of Facebook Users ❌

Server lacked password protection and included multiple databases with records from the U.S., U.K. and Vietnam.

πŸ“– Read

via "Threatpost".
⚠ Author of record-setting IoT botnets pleads guilty ⚠

He kept working on new botnets (and swatting a co-conspirator-cum-competitor) while indicted and on supervised release.

πŸ“– Read

via "Naked Security".
⚠ Android gets September update as price of flaws soars ⚠

When is a security update not a security update? When it’s patching flaws in a version of an OS nobody beyond developers is yet running.

πŸ“– Read

via "Naked Security".
πŸ•΄ It's Not Healthy to Confuse Compliance with Security πŸ•΄

Healthcare organizations should be alarmed by the frequency and severity of cyberattacks. Don't assume you're safe from them just because you're compliant with regulations.

πŸ“– Read

via "Dark Reading: ".
⚠ Firefox won’t follow Chrome’s anti-ad-blocker changes, says Mozilla ⚠

Mozilla has told developers not to fret - it won't follow Google in tweaking its browser to be unfriendly to ad blocking software.

πŸ“– Read

via "Naked Security".
⚠ Scammers deepfake CEO’s voice to talk underling into $243,000 transfer ⚠

The voice had the hint of a German accent and the same β€œmelody” that a UK CEO recognized in his boss's voice.

πŸ“– Read

via "Naked Security".
⚠ Raspberry Pi blasted into space, sends back video of Earth ⚠

Got a Pi? Here's a cool project idea for you...

πŸ“– Read

via "Naked Security".
❌ $5.3M Ransomware Demand: Massachusetts City Says No Thanks ❌

After being hit by a ransomware attack, Massachusetts city New Bedford faced a payout demand of more than $5 million - one of the latest known ransoms ever.

πŸ“– Read

via "Threatpost".
πŸ•΄ 419M Facebook User Phone Numbers Publicly Exposed πŸ•΄

It's still unclear who owned the server storing hundreds of millions of records online without a password.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-18370 (advanced_secure_gateway, proxysg)

The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject malicious JavaScript code in ASG/ProxySG's web listing of a remote FTP server. Exploiting the vulnerability requires the attacker to be able to upload crafted files to the remote FTP server. Affected versions: ASG 6.6 and 6.7 prior to 6.7.4.2; ProxySG 6.5 prior to 6.5.10.15, 6.6, and 6.7 prior to 6.7.4.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Crimeware: How Criminals Built a Business to Target Businesses πŸ•΄

A new report investigates the evolution of crimeware, how businesses underestimate the threat, and why they should be concerned.

πŸ“– Read

via "Dark Reading: ".
πŸ” DoD To Launch New IP Policy Group πŸ”

The team will be tasked with better protecting U.S. IP from data theft; it will also issue and oversee new policies around data rights and how military IP is allocated in the DoD's contracting and acquisition stages.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Automation: Friend of the SOC Analyst πŸ•΄

Faced by increasingly sophisticated threats, organizations are realizing the benefits of automation in their cybersecurity programs.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-11569

Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Attackers Hit Ceiling in Ransomware Demands πŸ•΄

New Bedford, Massachusetts' refusal to pay a $5.3 million ransom highlights how victim towns and cities may be hitting the limit to what they're willing to spend to speed recovery.

πŸ“– Read

via "Dark Reading: ".