πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Friday Five: 9/6 Edition πŸ”

iPhone hacking levels up, military veterans targeted in an identity fraud scam, and more - catch up on the week's biggest stories with the Friday Five!

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ News Wrap: Deepfake CEO Voice Scam, Facebook Phone Data Exposed ❌

From deepfake to data exposures, the Threatpost team talks about the top security trends driving this week's biggest news stories.

πŸ“– Read

via "Threatpost".
πŸ•΄ Mail System Vulnerability Delivers Root Privileges πŸ•΄

The vulnerability in Exim could allow an attacker to remotely execute code with root privileges.

πŸ“– Read

via "Dark Reading: ".
❌ Back-to-School Scams Target Students with Library-Themed Emails ❌

Students should keep their eyes peeled for phishing emails purporting to be from their colleges, as well as online student resources laced with malware, researchers warn.

πŸ“– Read

via "Threatpost".
❌ China’s APT3 Pilfers Cyberweapons from the NSA ❌

Large portions of APT3's remote code-execution package were likely reverse-engineered from prior attack artifacts.

πŸ“– Read

via "Threatpost".
❌ ThreatList: Police Use of Facial Recognition is Just Fine, Say Most Americans ❌

A survey by Pew Research Center finds that Americans support use of facial recognition by law enforcement , but not by tech or advertising companies.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2016-7398

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11198

An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10937

IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

πŸ“– Read

via "National Vulnerability Database".
⚠ Patch early, patch often – and patch everything! ⚠

Here's our latest Naked Security Live video - all about WordPress, plugins and patching.

πŸ“– Read

via "Naked Security".
⚠ Monday review – the hot 21 stories of the week ⚠

From backdooring WordPress sites to Raspberry Pi in space, and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ US city balks at paying $5.3 million ransomware demand ⚠

The attack quickly encrypted 158 workstations - and would have been worse had it struck later in the working day.

πŸ“– Read

via "Naked Security".
⚠ Facebook launches $10m deepfake detection project ⚠

If you're worried about the evil potential of deepfake video, you're not alone; so is Facebook.

πŸ“– Read

via "Naked Security".
⚠ Brave accuses Google of sidestepping GDPR ⚠

A senior executive at private browser company Brave has accused Google of using a workaround that lets it identify users to ad networks.

πŸ“– Read

via "Naked Security".
⚠ WordPress 5.2.3 fixes new clutch of security vulnerabilities ⚠

WordPress version 5.2.3 has just appeared on the download pipe featuring half a dozen security fixes and software enhancements.

πŸ“– Read

via "Naked Security".
❌ Apple Claims Google is Spreading FUD Over Patched iPhone Bugs ❌

Apple said Google’s recent analysis of vulnerabilities found January in iOS painted a misleading picture of the scope of the attacks and the risk involved

πŸ“– Read

via "Threatpost".
πŸ•΄ Phishers' Latest Tricks for Reeling in New Victims πŸ•΄

Phishing works because people are, by nature, trusting -- but these evolving phishing techniques make it even tougher for security managers to stay on top.

πŸ“– Read

via "Dark Reading: ".
πŸ” Google hopes to protect users with open source differential privacy library πŸ”

Google's differential privacy library will give organizations a way to study their data while protecting people's information.

πŸ“– Read

via "Security on TechRepublic".
❌ Critical Exim Flaw Opens Millions of Servers to Takeover ❌

A critical vulnerability found in Exim servers could enable a remote, unauthenticated attacker to execute arbitrary code with root privileges.

πŸ“– Read

via "Threatpost".