πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-4630

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.

πŸ“– Read

via "National Vulnerability Database".
⚠ Apple privacy portal lets you see everything it knows about you ⚠

The Apple website's privacy and data area lets you download and correct your data.

πŸ“– Read

via "Naked Security".
⚠ Serious D-Link router security flaws may never be patched ⚠

Six routers with serious security flaws are considered end of life (EOL) and may never be updated.

πŸ“– Read

via "Naked Security".
⚠ β€œWe know you watch porn” (and here’s fake proof…) [PODCAST] ⚠

Here's Episode 6 of the Naked Security podcast... enjoy!

πŸ“– Read

via "Naked Security".
πŸ” AI, cybersecurity shape the CIO agenda for 2019 as IT budgets rise πŸ”

Companies are scaling digital transformation projects, but privacy remains a top concern, according to a Gartner report.

πŸ“– Read

via "Security on TechRepublic".
❌ Trivial Post-Intrusion Attack Exploits Windows RID ❌

Simple technique enables attackers to leverage Windows OS component to maintain stealth and persistence post system compromise.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ•΄ Risky Business: Dark Reading Caption Contest Winners πŸ•΄

Phishing, anti-shoulder surfing, Russia and other hysterical identity management puns and comments. And the winners are ...

πŸ“– Read

via "Dark Reading: ".
πŸ” Why we need more cybersecurity workers right now πŸ”

At the 2018 Grace Hopper Celebration, Katie Jenkins of Liberty Mutual explained how to attract more diverse candidates to cybersecurity roles.

πŸ“– Read

via "Security on TechRepublic".
❌ AWS FreeRTOS Bugs Allow Compromise of IoT Devices ❌

The bugs let hackers crash IoT devices, leak their information, and completely take them over.

πŸ“– Read

via "The first stop for security news | Threatpost ".
πŸ” Apple Pay: A cheat sheet πŸ”

Apple Pay is a mobile payment solution that's accepted by millions of retailers in various countries. This guide covers what you need to know to use Apple Pay.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ WSJ Report: Facebook Breach the Work of Spammers, Not Nation-State Actors πŸ•΄

A report by the Wall Street Journal points finger at group that is know to Facebook Security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google Patch to Block Spectre Slowdown in Windows 10 πŸ•΄

Microsoft will incorporate Google's Retpoline patch to prevent Spectre Variant 2 from slowing down its operating system.

πŸ“– Read

via "Dark Reading: ".
❌ Two Critical RCE Bugs Patched in Drupal 7 and 8 ❌

Drupal's advisory also included three patches for "moderately critical" bugs.

πŸ“– Read

via "The first stop for security news | Threatpost ".
⚠ Monday review – the hot 20 stories of the week ⚠

From a serious libssh bug to the sextortionists that spoof your email address, and all the stories in between. Catch up with everything we've written in the last seven days - it's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Maker of LuminosityLink RAT gets 30 months in the clink ⚠

Prosecutors said that the 21-year-old LuminosityLink author had no respect for the law and showed contempt for moral rules and social norms.

πŸ“– Read

via "Naked Security".
⚠ Up to 9.5 million net neutrality comments were fake ⚠

New York has expanded its probe to subpoena 14 industry groups and lobbyists, saying that fake comments "distort[ed] public opinion."

πŸ“– Read

via "Naked Security".
⚠ Alleged robber busted after Facebook-friending victim to apologize ⚠

He told her to put down the pizza delivery and all her money on top of it. 26 days later, he found her on Facebook and reached out.

πŸ“– Read

via "Naked Security".
⚠ Popular website plugin harboured a serious 0-day for years ⚠

The flaw in the popular file uploader allows an attacker to upload files and run their own command line shell on any affected server.

πŸ“– Read

via "Naked Security".
πŸ•΄ Understanding SOCs' 4 Top Deficiencies πŸ•΄

In most cases, the areas that rankle SANS survey respondents the most about security operations centers can be addressed with the right mix of planning, policies, and procedures.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Bug Impacts Live555 Media Streaming Libraries ❌

A critical streaming bug impacts Live Networks LIVE555 RTSPServer, but not the popular VLC and MPLayer client-side software.

πŸ“– Read

via "The first stop for security news | Threatpost ".