πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Insurance Pays Out a Sliver of Norsk Hydro’s Cyberattack Damages ❌

The company received $3.6 million in cyber insurance - out of $71 million incurred in damages after a massive March cyberattack.

πŸ“– Read

via "Threatpost".
πŸ” How to avoid malware on Android in one easy step πŸ”

Jack Wallen offers up his best advice for avoiding malware on Android.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Black Hat Europe Brings Enterprise-Grade Cybersecurity Insights to London πŸ•΄

Don't miss all the promising enterprise security Briefings at Black Hat Europe in London this December.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cybersecurity's 'Moral Imperative' πŸ•΄

Cybersecurity professionals often talk about the economic drivers of security. But should the conversation shift to include a moral component? At least one analyst says "yes."

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ As Phishing Kits Evolve, Their Lifespans Shorten πŸ•΄

Most phishing kits last less than 20 days, a sign defenders are keeping up in the race against cybercrime.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-1391

Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0207

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0206

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-1673

A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0749

Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0748

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0747

drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0737

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-0398

The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Digital Guardian Announces Special Offer for Symantec DLP Customers πŸ”

Post-acquisition, Symantec DLP customers looking to reduce vendor uncertainty should take advantage of this exclusive offer.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
⚠ WhatsApp sues spyware maker for allegedly hacking phones worldwide ⚠

WhatsApp has publicly attributed the attack on its users in May 2019 to the Israeli spyware makers, NSO Group.

πŸ“– Read

via "Naked Security".
⚠ Researchers find hole in EU-wide identity system ⚠

The EU has fixed a flaw in the powerful yet complex eIDAS digital identification system that let people authenticate as someone else.

πŸ“– Read

via "Naked Security".
⚠ Judge lambasts porn company for spewing copyright lawsuits ⚠

A US court shielded ISP account holders from a request for expedited discovery to see whose IP addresses were used to share pirated videos.

πŸ“– Read

via "Naked Security".
❌ Valve Source Engine, Fortnite Servers Crippled By Gafgyt Variant ❌

Servers hosting Valve Source Engine and popular games like Fortnite are targeted by a new variant of the Gafgyt botnet.

πŸ“– Read

via "Threatpost".
❌ Fake Voicemail/Office 365 Attack Targets Enterprise Execs ❌

Executives at high-profile companies are being targeted by a fake voicemail campaign hunting for Office 365 credentials.

πŸ“– Read

via "Threatpost".
⚠ Linux maintainer: Patching side-channel flaws is killing performance ⚠

Mirror, mirror on the wall, which is the worst side-channel vulnerability of them all?

πŸ“– Read

via "Naked Security".