πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ U.S. Universities Get Failing Grades for DMARC Adoption ❌

Of the 200 schools in the report, the University of Pittsburgh and Georgetown University received top marks, with their DMARC policy set to "reject."

πŸ“– Read

via "Threatpost".
πŸ” How to protect your business against phishing attacks that exploit major tech brands πŸ”

Users of Microsoft, PayPal, DHL, and Dropbox are among the top targets of phishers, according to a new report from cloud service provider Akamai.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2011-2186

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
❌ WhatsApp Spyware Attack: Uncovering NSO Group Activity ❌

John Scott Railton with Citizen Lab, who helped WhatsApp investigate the NSO Group over the alleged WhatsApp hack, said the subsequent lawsuit is a "certified big deal."

πŸ“– Read

via "Threatpost".
πŸ•΄ Security Pros Fear Insider Attacks Stem from Cloud Apps πŸ•΄

More than half of security practitioners surveyed say insider attack detection has grown more difficult since migrating to cloud.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Ransomware Attack Hits Las Cruces, New Mexico Public Schools πŸ•΄

The attack early in the morning of October 29 has taken all of the school district's systems offline.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Facebook Says Israeli Firm Was Involved in Recent WhatsApp Intrusion πŸ•΄

Evidence suggests NSO Group used WhatsApps servers to distribute mobile spyware to targeted devices.

πŸ“– Read

via "Dark Reading: ".
❌ Insurance Pays Out a Sliver of Norsk Hydro’s Cyberattack Damages ❌

The company received $3.6 million in cyber insurance - out of $71 million incurred in damages after a massive March cyberattack.

πŸ“– Read

via "Threatpost".
πŸ” How to avoid malware on Android in one easy step πŸ”

Jack Wallen offers up his best advice for avoiding malware on Android.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Black Hat Europe Brings Enterprise-Grade Cybersecurity Insights to London πŸ•΄

Don't miss all the promising enterprise security Briefings at Black Hat Europe in London this December.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cybersecurity's 'Moral Imperative' πŸ•΄

Cybersecurity professionals often talk about the economic drivers of security. But should the conversation shift to include a moral component? At least one analyst says "yes."

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ As Phishing Kits Evolve, Their Lifespans Shorten πŸ•΄

Most phishing kits last less than 20 days, a sign defenders are keeping up in the race against cybercrime.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-1391

Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0207

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0206

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-1673

A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0749

Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0748

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0747

drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0737

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0398

The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack.

πŸ“– Read

via "National Vulnerability Database".