πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” How to prevent ClipIt clipboard manager from copying sensitive information from apps πŸ”

If you use a clipboard manager, you need to make sure to exclude certain applications. Find out how this is done with ClipIt.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 281 Arrested in International BEC Takedown πŸ•΄

Conspirators stole more than 250,000 identities and filed more than 10,000 fraudulent tax returns, the Department of Justice reports.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Fed Kaspersky Ban Made Permenant by New Rules πŸ•΄

A new set of regulations converts the government ban on using Kaspersky products from a temporary rule to one that's permenant.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Fed Kaspersky Ban Made Permanent by New Rules πŸ•΄

A new set of regulations converts the government ban on using Kaspersky products from a temporary rule to one that's permanent.

πŸ“– Read

via "Dark Reading: ".
❌ Major Groupon, Ticketmaster Fraud Scheme Exposed By Insecure Database ❌

An exposed database containing 17 million email addresses exposed a massive fraud scheme impacting vendors like Groupon and Ticketmaster.

πŸ“– Read

via "Threatpost".
πŸ•΄ Proposed Browser Security Guidelines Would Mean More Work for IT Teams πŸ•΄

CA/Browser Forum wants SSL certificates to expire after a year. Many businesses that rely on them aren't equipped to cope.

πŸ“– Read

via "Dark Reading: ".
πŸ” 281 Arrests Made Worldwide in Massive BEC Scam Disruption πŸ”

The suspects, arrested worldwide, allegedly stole more than 250,000 identities, filed more than 10,000 fake tax returns, and tried to receive more than $91 million in refunds.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” How to enable DNS-over-HTTPS in Firefox πŸ”

If you're looking to gain as much privacy and security from the Firefox browser, you might want to enable DNS-over-HTTPS.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Community Projects Highlight Need for Security Volunteers πŸ•΄

From university courses to open source self-starters, community software projects aim to solve problems for populations in need. A focus on security is required as well.

πŸ“– Read

via "Dark Reading: ".
❌ ThreatList: Apple Adware, Phishing, APT Attacks Threaten macOS Users ❌

Telemetry for the first half of the year shows that Apple's ecosystem is firmly in cybercriminals' sights.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-0189

The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-17200

The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream` instance is slightly guarded by disabling the creation of `ProcessBuilder`. However, this can be easily bypassed (and in multiple ways). Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16 r1850017+1850019

πŸ“– Read

via "National Vulnerability Database".
⚠ Error-laden phone location data suspended from use in Danish courts ⚠

10,700 cases will be reviewed over 2 months, and 32 detainees have already been released after finding bugs in software and raw telecom data.

πŸ“– Read

via "Naked Security".
⚠ Google experiments with DNS-over-HTTP in Chrome ⚠

Following hot on Mozilla's trail, Google officially announced its own DNS-over-HTTPS (DoH) experiment in Chrome this week.

πŸ“– Read

via "Naked Security".
⚠ Massive email fraud bust snares 281 suspects ⚠

Operation reWired=tired cops worldwide! 167 suspects were cuffed in Nigeria and 74 in the US, among 8 other countries.

πŸ“– Read

via "Naked Security".
⚠ September 2019’s Patch Tuesday: 2 zero-days, 17 critical bugs ⚠

Sometimes, a Patch Tuesday update arrives with a bang that sends users scrambling for cover - September's update earns that description.

πŸ“– Read

via "Naked Security".
❌ UNICEF Leaks Personal Data of 8,000 Users via Email Blunder ❌

The organization accidentally sent the names, email addresses, gender and professional information of users of its portal Agora in an email sent in August.

πŸ“– Read

via "Threatpost".