πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ PsiXBot Adds PornModule, Google DNS Service to Its Arsenal ❌

Porn-recording feature will likely be used for extortion.

πŸ“– Read

via "Threatpost".
πŸ” More than 99% of attacks in the past year relied on human error to gain access πŸ”

Experiencing a data breach purely from being internet-connected is quite rare. Hackers rely on users to open or install a malicious payload, according to Proofpoint.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to set up an SFTP server on Linux πŸ”

These steps walk you through the process of setting up an SFTP server on Linux for the secure transfer of files for specialized file transfer-only users.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 password alternatives πŸ”

Passwords remain the most common way to authenticate your online identity, but companies like Microsoft and Google are using alternate login methods. Tom Merritt offers five alternatives to passwords.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 password alternatives πŸ”

Passwords remain the most common way to authenticate your online identity, but companies like Microsoft and Google are using alternate login methods. Tom Merritt offers five alternatives to passwords.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ More Than 99% of Cyberattacks Need Victims' Help πŸ•΄

Research highlights how most criminals exploit human curiosity and trust to click, download, install, open, and send money or information.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-10253

A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists within the handling of Upload/DomainObjectDocumentUpload.ashx requests because of failure to validate a CSRF token before handling a POST request.

πŸ“– Read

via "National Vulnerability Database".
⚠ Critical TLS flaw opens Exim servers to remote compromise ⚠

A β€˜critical’ security vulnerability has been discovered in the Exim mail server that requires admins' urgent attention.

πŸ“– Read

via "Naked Security".
⚠ Chrome bumps ineffective EV certificates off the omnibar ⚠

Ever notice a missing company name next to the URL address bar? Ever change behavior because of it? Likely not, so bye-bye, useless badge.

πŸ“– Read

via "Naked Security".
⚠ Google & Apple pushed to reveal gun scope app users’ names to feds ⚠

It's a first: The government has never demanded personal data of a single app's users from Apple & Google.

πŸ“– Read

via "Naked Security".
⚠ Mozilla increases browser privacy with encrypted DNS ⚠

Mozilla is about to turn on-by-default an oft-overlooked privacy feature in Firefox.

πŸ“– Read

via "Naked Security".
πŸ•΄ What Are the First Signs of a Cloud Data Leak? πŸ•΄

Most cloud data breaches leave only trace signs of malfeasance, so it can be tricky.

πŸ“– Read

via "Dark Reading: ".
❌ Vulnerabilities in D-Link, Comba Routers Can Leak Credentials ❌

Flaws can potentially affect every device and user on the network by directing them to malicious websites or blocking their access to important data or resources.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-18599

The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18598

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18597

The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18596

The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

πŸ“– Read

via "National Vulnerability Database".
❌ U.S. Manufacturer Most Recent Target of LokiBot Malspam Campaign ❌

A large U.S. manufacturing company is the latest organization to be targeted with the LokiBot trojan - although this most recent campaign harbored some bizarre red flags.

πŸ“– Read

via "Threatpost".
πŸ•΄ AI Is Everywhere, but Don't Ignore the Basics πŸ•΄

Artificial intelligence is no substitute for common sense, and it works best in combination with conventional cybersecurity technology. Here are the basic requirements and best practices you need to know.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-18611

The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css parameter.

πŸ“– Read

via "National Vulnerability Database".