πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Leaky Server Exposes 419M Phone Numbers of Facebook Users ❌

Server lacked password protection and included multiple databases with records from the U.S., U.K. and Vietnam.

πŸ“– Read

via "Threatpost".
⚠ Author of record-setting IoT botnets pleads guilty ⚠

He kept working on new botnets (and swatting a co-conspirator-cum-competitor) while indicted and on supervised release.

πŸ“– Read

via "Naked Security".
⚠ Android gets September update as price of flaws soars ⚠

When is a security update not a security update? When it’s patching flaws in a version of an OS nobody beyond developers is yet running.

πŸ“– Read

via "Naked Security".
πŸ•΄ It's Not Healthy to Confuse Compliance with Security πŸ•΄

Healthcare organizations should be alarmed by the frequency and severity of cyberattacks. Don't assume you're safe from them just because you're compliant with regulations.

πŸ“– Read

via "Dark Reading: ".
⚠ Firefox won’t follow Chrome’s anti-ad-blocker changes, says Mozilla ⚠

Mozilla has told developers not to fret - it won't follow Google in tweaking its browser to be unfriendly to ad blocking software.

πŸ“– Read

via "Naked Security".
⚠ Scammers deepfake CEO’s voice to talk underling into $243,000 transfer ⚠

The voice had the hint of a German accent and the same β€œmelody” that a UK CEO recognized in his boss's voice.

πŸ“– Read

via "Naked Security".
⚠ Raspberry Pi blasted into space, sends back video of Earth ⚠

Got a Pi? Here's a cool project idea for you...

πŸ“– Read

via "Naked Security".
❌ $5.3M Ransomware Demand: Massachusetts City Says No Thanks ❌

After being hit by a ransomware attack, Massachusetts city New Bedford faced a payout demand of more than $5 million - one of the latest known ransoms ever.

πŸ“– Read

via "Threatpost".
πŸ•΄ 419M Facebook User Phone Numbers Publicly Exposed πŸ•΄

It's still unclear who owned the server storing hundreds of millions of records online without a password.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-18370 (advanced_secure_gateway, proxysg)

The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject malicious JavaScript code in ASG/ProxySG's web listing of a remote FTP server. Exploiting the vulnerability requires the attacker to be able to upload crafted files to the remote FTP server. Affected versions: ASG 6.6 and 6.7 prior to 6.7.4.2; ProxySG 6.5 prior to 6.5.10.15, 6.6, and 6.7 prior to 6.7.4.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Crimeware: How Criminals Built a Business to Target Businesses πŸ•΄

A new report investigates the evolution of crimeware, how businesses underestimate the threat, and why they should be concerned.

πŸ“– Read

via "Dark Reading: ".
πŸ” DoD To Launch New IP Policy Group πŸ”

The team will be tasked with better protecting U.S. IP from data theft; it will also issue and oversee new policies around data rights and how military IP is allocated in the DoD's contracting and acquisition stages.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Automation: Friend of the SOC Analyst πŸ•΄

Faced by increasingly sophisticated threats, organizations are realizing the benefits of automation in their cybersecurity programs.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-11569

Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Attackers Hit Ceiling in Ransomware Demands πŸ•΄

New Bedford, Massachusetts' refusal to pay a $5.3 million ransom highlights how victim towns and cities may be hitting the limit to what they're willing to spend to speed recovery.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New Technique Makes Passwords 14M Percent Harder to Crack, Nonprofit Claims πŸ•΄

Tide's method for protecting passwords splinters them up into tiny pieces and stores them on distributed nodes.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to sign into your Microsoft Account website without a password πŸ”

Learn how to sign in to your Microsoft Account site using your fingerprint, face, or a physical security key via Chrome, Firefox, or Microsoft Edge.

πŸ“– Read

via "Security on TechRepublic".
❌ FunkyBot Malware Intercepts Android Texts, 2FA Codes ❌

The spyware poses as a legitimate application, spreading via SMS messages to victims' contact lists.

πŸ“– Read

via "Threatpost".
❌ Joker Spyware Found in 24 Google Play Apps ❌

Google has kicked 24 apps off of its official Android app marketplace after spyware was discovered in them.

πŸ“– Read

via "Threatpost".
πŸ•΄ Security Pros and 'Black Hats' Agree on Most Tempting Targets πŸ•΄

Malicious actors look for accounts that are springboards to other systems, according to nearly 300 attendees of Black Hat USA.

πŸ“– Read

via "Dark Reading: ".
⚠ Twitter slaps back SMS texting after @Jack hijacking ⚠

Two problems, Twitter says: vulnerabilities that mobile carriers need to fix & its reliance on linked numbers for 2FA.

πŸ“– Read

via "Naked Security".