πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Serious SSH bug lets crooks log in just by asking nicely… ⚠

A serious bug in libssh could allow crooks to connect to your server - with no password requested or required. Here's what you need to know.

πŸ“– Read

via "Naked Security".
❌ Podcast: A Utility Ransomware Attack Post-Hurricane ❌

A β€œcritical water utility” was hit by a recent ransomware attack, significantly impeding the service in the week after Hurricane Florence hit the East Coast of the U.S. The Onslow Water and Sewer Authority (ONWASA) said in a Monday release that a β€œsophisticated ransomware attack… has left the utility with limited computer capabilities.” While customer data […]

πŸ“– Read

via "The first stop for security news | Threatpost ".
ATENTIONβ€Ό New - CVE-2017-17176

The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B156, versions earlier before MHA-CL00BC00B156, versions earlier before MHA-DL00BC00B156, versions earlier before MHA-TL00BC00B156, versions earlier before LON-AL00BC00B156, versions earlier before LON-CL00BC00B156, versions earlier before LON-DL00BC00B156, versions earlier before LON-TL00BC00B156 has a arbitrary memory read/write vulnerability due to the input parameters validation. An attacker with the root privilege of the Android system could exploit this vulnerability to read and write memory data anywhere or execute arbitrary code in the TrustZone.

πŸ“– Read

via "National Vulnerability Database".
⚠ Weirdo Twitter messages were a glitch, not a hack ⚠

Were you one of the dozens of people who got a bizarre Twitter message yesterday? It's OK. It wasn't a disturbance in the Matrix.

πŸ“– Read

via "Naked Security".
❌ libssh Authentication Bypass Makes it Trivial to Pwn Rafts of Servers ❌

The flaw affects thousands of servers; but GitHub, a major libssh user, is unaffected.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ Startup Spun Out of Securosis Secures $2.5 Million Seed Investment πŸ•΄

DistruptOps officially rolls out its SaaS for automating control of cloud operations and security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ SEC Warns Public Companies on Accounting Control Use πŸ•΄

A new SEC investigative report urges public organizations to keep cyberthreats in mind when implementing internal accounting tools.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cybercrime-as-a-Service: No End in Sight πŸ•΄

Cybercrime is easy and rewarding, making it a perfect arena for criminals everywhere.

πŸ“– Read

via "Dark Reading: ".
❌ Oracle Fixes 301 Flaws in October Critical Patch Update ❌

The update includes one critical flaw in Oracle GoldenGate with a CVSS 3.0 score of 10.0.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ (ISC) 2 : Global Cybersecurity Workforce Short 3 Million People πŸ•΄

With the skills gap still wide, security leaders explain the challenges of hiring and retaining security experts.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Oracle Issues Massive Collection of Critical Security Updates πŸ•΄

The software updates from Oracle address a record number of vulnerabilities.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 3 Years After Attacks on Ukraine Power Grid, BlackEnergy Successor Poses Growing Threat πŸ•΄

In what could be a precursor to future attacks, GreyEnergy is targeting critical infrastructure organizations in Central and Eastern Europe.

πŸ“– Read

via "Dark Reading: ".
⚠ Twitter publishes data on Iranian and Russian troll farms ⚠

Over 1m tweets show that we're suckers for funny/sarcastic/edgy, not so much for blah-blah-blah β€œnews” spreaders.

πŸ“– Read

via "Naked Security".
⚠ You don’t have to sequence your DNA to be identifiable by your DNA ⚠

If you have European ancestry, there's a 60% chance that somebody vaguely related to you can be used to find out who you are.

πŸ“– Read

via "Naked Security".
⚠ Is Google’s Android app unbundling good for security? ⚠

If you live in the EU, turning on a new Android device after 29 October 2018 could look quite different...

πŸ“– Read

via "Naked Security".
⚠ The libssh β€œlogin with no password” bug – what you need to know [VIDEO] ⚠

Here's a video that explains the libssh "no password needed" bug - jargon-free and in plain English. Enjoy...

πŸ“– Read

via "Naked Security".
πŸ” State of Washington has new laws and the Air National Guard to help secure 2018 midterm election πŸ”

Washington state aims to stay protected this election season via anti-hacking efforts of the Air National Guard, as well as strengthened audit procedures

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Inside the Dark Web's 'Help Wanted' Ads πŸ•΄

How cybercriminals recruit everyone from car drivers to corporate insiders and pay them according to the risk they assume.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-9069

A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Apache Access Vulnerability Could Affect Thousands of Applications πŸ•΄

A recently discovered issue with a common file access method could be a major new attack surface for malware authors.

πŸ“– Read

via "Dark Reading: ".
❌ GreyEnergy Spy APT Mounts Sophisticated Effort Against Critical Infrastructure ❌

The group is a successor to BlackEnergy and a subset of the TeleBots gang--and its activity is potentially a prelude to a much more destructive attack.

πŸ“– Read

via "The first stop for security news | Threatpost ".