πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2009-5048

Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5046

JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5045

Dump Servlet information leak in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5043 (burn, debian_linux)

burn allows file names to escape via mishandled quotation marks

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5042 (debian_linux, python-docutils)

python-docutils allows insecure usage of temporary files

πŸ“– Read

via "National Vulnerability Database".
❌ Trend Micro: Rogue Employee Sold Customer Data for 68K Accounts ❌

Trend Micro customers whose data was sold are getting scam calls from criminals purporting to be support staff.

πŸ“– Read

via "Threatpost".
πŸ•΄ Google Announces App Defense Alliance πŸ•΄

The industry partnership will scan apps for malware before they're published on the Google Play Store.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Accounting Scams Continue to Bilk Businesses πŸ•΄

Yes, ransomware is plaguing businesses and government organizations, but impersonators inserting themselves into financial workflows - most often via e-mail - continue to enable big paydays.

πŸ“– Read

via "Dark Reading: ".
❌ You’ve Been Served…with Subpoena-Themed Phishing Emails ❌

A targeted campaign is delivering an information-stealing malware called Predator the Thief.

πŸ“– Read

via "Threatpost".
❌ Microsegmentation and Isolation: 2 Essential Strategies in Zero-Trust Security ❌

Tactics for when authorized users need to connect to network resources, or need to venture out to the web to complete important tasks.

πŸ“– Read

via "Threatpost".
⚠ Warrant let police search online DNA database ⚠

This is a "game changer" when it comes to genetic privacy rights, experts say.

πŸ“– Read

via "Naked Security".
⚠ Facebook scam steals famous faces and BBC branding ⚠

An email scam from earlier this year has resurfaced on Facebook - don't fall for it!

πŸ“– Read

via "Naked Security".
πŸ•΄ Black Hat Q&A: Hacking a '90s Sports Car πŸ•΄

Security researcher Stanislas Lejay offers a preview of his upcoming Black Hat Europe talk on automotive engine computer management and hardware reverse engineering.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Kaspersky Lab Analysis Shines Light on DarkUniverse APT Group πŸ•΄

Threat actor was active between 2009 and 2017, targeting military, government, and private organizations.

πŸ“– Read

via "Dark Reading: ".
⚠ Facebook confesses 100 devs may have accessed leaked Groups data ⚠

It shut down that access in April 2018, or at least thought it did. At least 11 improperly accessed data in the last two months.

πŸ“– Read

via "Naked Security".
❌ Google Enlists Help to Fight Bad Android Apps ❌

After years of unsuccessfully battling malware and bad apps in the Google Play store and on more than 2.5 billion Android devices, Google is finally doing something about it. The tech giant this week unveiled an alliance with three companies with specific expertise in endpoint security to help prevent the spread of malware on its […]

πŸ“– Read

via "Threatpost".
⚠ Pilot presses the wrong button, triggers airport hostage alarm ⚠

We've all been there - faced with a button that is just begging to be pressed...

πŸ“– Read

via "Naked Security".
⚠ Linux users warned to update libarchive to beat flaw ⚠

The bug is identified as CVE-2019-18408, a high-priority β€˜use-after-free’ bug when dealing with a failed archive.

πŸ“– Read

via "Naked Security".
❌ Data Breach Fines: Are They Working to Boost Consumer Safety? ❌

Despite trillions of dollars in breach fine payouts, each year the number of compromised companies and individuals with private data exposed rise.

πŸ“– Read

via "Threatpost".
⚠ WordPress sites hit by malvertising ⚠

An old piece of malware is storming the WordPress community, enabling its perpetrators to take control of sites and inject code of their choosing.

πŸ“– Read

via "Naked Security".
πŸ” You've got malware: Malicious actors are waiting in your inbox πŸ”

Dangerous URL messages, the resurgence of Emotet, and banking trojans flood the cyberthreat landscape, Proofpoint found.

πŸ“– Read

via "Security on TechRepublic".