πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ PHP team fixes nasty site-owning remote execution bug ⚠

The PHP development team has fixed a bug that could allow remote code execution in some setups of the programming language.

πŸ“– Read

via "Naked Security".
⚠ Gradient β€œcelebrity matching” photo app sparks privacy fears ⚠

The Kardashians love the Gradient app - but they're being paid to use it, whereas for you it's the other way round. Is it safe?

πŸ“– Read

via "Naked Security".
❌ ThreatList: Most Retail Hardware Bug Bounty Flaws Are Critical ❌

Overall, across all retail programs, more than 18 percent of all bug bounty submissions are critical in severity, a new Bugcrowd report found.

πŸ“– Read

via "Threatpost".
❌ Country of Georgia Suffers Widespread Cyberattack ❌

The attack on local web-hosting provider Pro-Service - likely politically motivated - took out 2,000 websites and the national television station.

πŸ“– Read

via "Threatpost".
πŸ•΄ What Do You Do When You Can't Patch Your IoT Endpoints? πŸ•΄

The answer, in a word, is segmentation. But the inconvenient truth is that segmentation is hard.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why It's Imperative to Bridge the IT & OT Cultural Divide πŸ•΄

As industrial enterprises face the disruptive forces of an increasingly connected world, these two cultures must learn to coexist.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9506 (amazon_s3, easy_digital_downloads)

The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

πŸ“– Read

via "National Vulnerability Database".
❌ Fancy Bear Targets Sporting, Anti-Doping Orgs As 2020 Olympics Loom ❌

The APT is once again targeting the sports world, Microsoft warns.

πŸ“– Read

via "Threatpost".
❌ New Adwind Variant Targets Windows, Chromium Credentials ❌

A new version of the typically platform-agnostic Adwind trojan has been spotted targeting Windows applications and systems and Chromium-based browsers.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cybersecurity Trumps Political, Reputational Concerns for Companies πŸ•΄

The average company has seen its risk increase, with cybersecurity topping the list of business threats, followed by damage to reputation and financial risks, a report finds.

πŸ“– Read

via "Dark Reading: ".
❌ Joker’s Stash Drops Largest-Ever Credit Card Cache on Dark Web ❌

1.3 million stolen cards, mostly from India, could fetch $130 million for the cybercrooks.

πŸ“– Read

via "Threatpost".
πŸ” Research finds 2019 increase in breaches and cybersecurity spending πŸ”

The ServiceNow and Ponemon study found an average 24% increase in cybersecurity spending and a 17% rise in attacks.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Who Made the List Of 2019's Nastiest Malware? πŸ•΄

This year's compilation features well-known ransomware, botnet, and cryptomining software.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google Cloud Adds New Security Management Tools to G Suite πŸ•΄

Desktop devices that log into G Suite will have device management enabled by default, streamlining processes for IT admins.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why Cloud-Native Applications Need Cloud-Native Security πŸ•΄

Today's developers and the enterprises they work for must prioritize security in order to reap the speed and feature benefits these applications and new architectures provide.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to secure OneDrive files and folders with Personal Vault πŸ”

Learn how to make specific folders and files on OneDrive more secure by using Personal Vault.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Hacker Faces Jailtime After Stealing Employee, Company Data At Two Firms πŸ”

A man admitted he installed keyloggers at two companies and used them as a launching pad to steal data on emerging technology they were developing.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ The Real Reasons Why the C-Suite Isn't Complying with Security πŸ•΄

Is the C-suite really that bad at following security policy? Or is it a case of mixed messages and misunderstanding?

πŸ“– Read

via "Dark Reading: ".
❌ Facebook Sues NSO Group Over Alleged WhatsApp Hack ❌

In a new lawsuit, WhatsApp owner Facebook says that NSO Group was behind the WhatsApp zero-day exploits earlier in 2019.

πŸ“– Read

via "Threatpost".
πŸ•΄ Old RAT, New Moves: Adwind Hides in Java Commands to Target Windows πŸ•΄

The Adwind remote access Trojan conceals malicious activity in Java commands to slip past threat intelligence tools and steal user data.

πŸ“– Read

via "Dark Reading: ".