πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Twitter bans political ads ⚠

Interesting timing: Right before Facebook's earnings call, two weeks after Facebook said it won't pull political ads that spout lies.

πŸ“– Read

via "Naked Security".
❌ Android Keyboard App Could Swindle 40M Users Out of Millions ❌

The Ai.type app was removed from Google Play in June 2019 – but still remains on millions of Android devices and is still available from other Android marketplaces, researchers warn.

πŸ“– Read

via "Threatpost".
⚠ Happy Birthday, CVE! ⚠

The Common Vulnerabilities and Exposures (CVE) system is 20 years old this week.

πŸ“– Read

via "Naked Security".
πŸ•΄ Raising Security Awareness: Why Tools Can't Replace People πŸ•΄

Training your people and building relationships outside of the security organization is the most significant investment a CISO can make.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2005-3056

TWiki allows arbitrary shell command execution via the Include function

πŸ“– Read

via "National Vulnerability Database".
⚠ Apple props up macOS Catalina with 10.15.1 update ⚠

A vocal minority of the committed Apple base has been quick to express dissatisfaction at the move to Catalina from macOS 10.14 Mojave.

πŸ“– Read

via "Naked Security".
πŸ” How to allow SSH connections from LAN and WAN on different ports πŸ”

Is it possible to configure SSH to listen for connections on both internal and external interfaces, using different ports? Jack Wallen says "yes."

πŸ“– Read

via "Security on TechRepublic".
❌ Google Discloses Chrome Flaw Exploited in the Wild ❌

Google warns exploits in the wild against a Use After Free vulnerability in Chrome's audio component.

πŸ“– Read

via "Threatpost".
πŸ•΄ 8 Holiday Security Tips for Retailers πŸ•΄

As retailers head into the holiday rush, here's how they can protect their businesses from attackers and scammers hoping to wreak havoc during the most wonderful time of the year.

πŸ“– Read

via "Dark Reading: ".
⚠ S2 Ep15: City under attack! VPN hacked, floppies nixed ⚠

A latest episode of the Naked Security podcast is out now!

πŸ“– Read

via "Naked Security".
πŸ•΄ Google Patches Chrome Zero-Day Under Active Attack πŸ•΄

The fix addresses CVE-2019-13720, a high-severity, use-after-free vulnerability discovered by Kaspersky Lab researchers.

πŸ“– Read

via "Dark Reading: ".
❌ Stubborn Malware Targets QNAP NAS Hardware Specifically ❌

QNAP Systems says there is no known way to remove the Qsnatch malware infecting its NAS devices besides a full factory reset.

πŸ“– Read

via "Threatpost".
❌ Global Crime Ring Bilks U.S. Military Members, Vets Out of Millions ❌

An elaborate fraudster ring stole PII then used DoD and VA benefits portals to steal payments and funds from bank accounts.

πŸ“– Read

via "Threatpost".
πŸ” How to copy a file from one server to another from a third with SSH πŸ”

Find out how to work some SSH magic, by transferring a file from one machine to another from a third.

πŸ“– Read

via "Security on TechRepublic".
πŸ›  Samhain File Integrity Checker 4.4.0 πŸ› 

Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  SQLMAP - Automatic SQL Injection Tool 1.3.11 πŸ› 

sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Details of Attack on Electric Utility Emerge πŸ•΄

The March 5 DDoS attack interrupted communications between generating facilities and the electrical grid in three western states.

πŸ“– Read

via "Dark Reading: ".
πŸ” Friday Five: 11/1 Edition πŸ”

The hackers behind Uber's 2016 breach finally plead guilty, WhatsApp pushes back against NSO Group, and an army admin steals millions from veterans - catch up on the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ News Wrap: APTs, Office 365 Voicemail Phish and Bed Bath & Beyond Breach ❌

Threatpost editors discuss this week's biggest news - from a data breach of Bed Bath & Beyond, a tricky phishing attack and widespread APT activity. 

πŸ“– Read

via "Threatpost".
πŸ” Wanted: More women hackers πŸ”

Capture the Flag challenge encourages women to pursue cybersecurity careers and connects experts with newcomers

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2005-2351

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

πŸ“– Read

via "National Vulnerability Database".