πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Public Exposure Does Little to Slow China-Based Thrip APT πŸ•΄

Over the past year, the cyber-espionage group has attacked at least 12 other companies in the military, telecom, and satellite sectors, Symantec says.

πŸ“– Read

via "Dark Reading: ".
❌ Stealth Falcon Targets Middle East with Windows BITS Feature ❌

Cyberespionage attackers have ditched their PowerShell backdoor in favor of the Windows BITS β€˜notification’ feature.

πŸ“– Read

via "Threatpost".
❌ PsiXBot Adds PornModule, Google DNS Service to Its Arsenal ❌

Porn-recording feature will likely be used for extortion.

πŸ“– Read

via "Threatpost".
πŸ” More than 99% of attacks in the past year relied on human error to gain access πŸ”

Experiencing a data breach purely from being internet-connected is quite rare. Hackers rely on users to open or install a malicious payload, according to Proofpoint.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to set up an SFTP server on Linux πŸ”

These steps walk you through the process of setting up an SFTP server on Linux for the secure transfer of files for specialized file transfer-only users.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 password alternatives πŸ”

Passwords remain the most common way to authenticate your online identity, but companies like Microsoft and Google are using alternate login methods. Tom Merritt offers five alternatives to passwords.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 password alternatives πŸ”

Passwords remain the most common way to authenticate your online identity, but companies like Microsoft and Google are using alternate login methods. Tom Merritt offers five alternatives to passwords.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ More Than 99% of Cyberattacks Need Victims' Help πŸ•΄

Research highlights how most criminals exploit human curiosity and trust to click, download, install, open, and send money or information.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-10253

A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists within the handling of Upload/DomainObjectDocumentUpload.ashx requests because of failure to validate a CSRF token before handling a POST request.

πŸ“– Read

via "National Vulnerability Database".
⚠ Critical TLS flaw opens Exim servers to remote compromise ⚠

A β€˜critical’ security vulnerability has been discovered in the Exim mail server that requires admins' urgent attention.

πŸ“– Read

via "Naked Security".
⚠ Chrome bumps ineffective EV certificates off the omnibar ⚠

Ever notice a missing company name next to the URL address bar? Ever change behavior because of it? Likely not, so bye-bye, useless badge.

πŸ“– Read

via "Naked Security".
⚠ Google & Apple pushed to reveal gun scope app users’ names to feds ⚠

It's a first: The government has never demanded personal data of a single app's users from Apple & Google.

πŸ“– Read

via "Naked Security".
⚠ Mozilla increases browser privacy with encrypted DNS ⚠

Mozilla is about to turn on-by-default an oft-overlooked privacy feature in Firefox.

πŸ“– Read

via "Naked Security".
πŸ•΄ What Are the First Signs of a Cloud Data Leak? πŸ•΄

Most cloud data breaches leave only trace signs of malfeasance, so it can be tricky.

πŸ“– Read

via "Dark Reading: ".
❌ Vulnerabilities in D-Link, Comba Routers Can Leak Credentials ❌

Flaws can potentially affect every device and user on the network by directing them to malicious websites or blocking their access to important data or resources.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-18599

The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18598

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18597

The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18596

The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

πŸ“– Read

via "National Vulnerability Database".