πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-17200

The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream` instance is slightly guarded by disabling the creation of `ProcessBuilder`. However, this can be easily bypassed (and in multiple ways). Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16 r1850017+1850019

πŸ“– Read

via "National Vulnerability Database".
⚠ Error-laden phone location data suspended from use in Danish courts ⚠

10,700 cases will be reviewed over 2 months, and 32 detainees have already been released after finding bugs in software and raw telecom data.

πŸ“– Read

via "Naked Security".
⚠ Google experiments with DNS-over-HTTP in Chrome ⚠

Following hot on Mozilla's trail, Google officially announced its own DNS-over-HTTPS (DoH) experiment in Chrome this week.

πŸ“– Read

via "Naked Security".
⚠ Massive email fraud bust snares 281 suspects ⚠

Operation reWired=tired cops worldwide! 167 suspects were cuffed in Nigeria and 74 in the US, among 8 other countries.

πŸ“– Read

via "Naked Security".
⚠ September 2019’s Patch Tuesday: 2 zero-days, 17 critical bugs ⚠

Sometimes, a Patch Tuesday update arrives with a bang that sends users scrambling for cover - September's update earns that description.

πŸ“– Read

via "Naked Security".
❌ UNICEF Leaks Personal Data of 8,000 Users via Email Blunder ❌

The organization accidentally sent the names, email addresses, gender and professional information of users of its portal Agora in an email sent in August.

πŸ“– Read

via "Threatpost".
πŸ” How data breaches are hurting small businesses πŸ”

Some 30% of consumers surveyed said they would never again use a small business that suffered a data breach, according to a new report from Bank of America.

πŸ“– Read

via "Security on TechRepublic".
⚠ S2 Ep8: Facebook leak, $5m ransoms, DNS controversy – Naked Security Podcast ⚠

The latest Naked Security Podcast is live - listen now!

πŸ“– Read

via "Naked Security".
πŸ•΄ The Fight Against Synthetic Identity Fraud πŸ•΄

Advanced data and innovative technology will help organizations more easily identify abnormal behavior and tell legitimate customers apart from "fake" ones.

πŸ“– Read

via "Dark Reading: ".
❌ 1B Mobile Users Vulnerable to Ongoing β€˜SimJacker’ Surveillance Attack ❌

More than one billion mobile users are at risk from a SIM card flaw being currently exploited by threat actors, researchers warn.

πŸ“– Read

via "Threatpost".
❌ California Passes Bill to Ban Police Use of Facial Recognition ❌

The historic measure, which still needs to be signed into law, would prohibit biometric surveillance, including in bodycams.

πŸ“– Read

via "Threatpost".
πŸ•΄ APIs Get Their Own Top 10 Security List πŸ•΄

OWASP's new list of API weaknesses focuses on issues that have caused recent data breaches and pose common security hazards in modern cloud-based applications.

πŸ“– Read

via "Dark Reading: ".
❌ Library-Themed University Phishing Attack Expands to Massive Scale ❌

Cobalt Dickens (a.k.a. Silent Librarian) is now actively targeting 380 universities, bent on stealing credentials and moving deeper into school networks.

πŸ“– Read

via "Threatpost".
πŸ›  Wireshark Analyzer 3.0.4 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".