πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ The Myths of Multifactor Authentication πŸ•΄

Organizations without MFA are wide open to attack when employees fall for phishing scams or share passwords. What's holding them back?

πŸ“– Read

via "Dark Reading: ".
❌ Plugging the Data Leak in Manufacturing ❌

IIoT-generated data – calibrations, measurements and other parameters – still need to be stored, managed and shared securely.

πŸ“– Read

via "Threatpost".
πŸ•΄ New DDoS Attacks Leverage TCP Amplification πŸ•΄

Attackers over the past month have been using a rarely seen approach to disrupt services at large organizations in several countries.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Patches RCE Bug Actively Under Attack ❌

Microsoft tackles 74 bugs as part of its November Patch Tuesday security bulletin.

πŸ“– Read

via "Threatpost".
❌ Insider Threats, a Cybercriminal Favorite, Not East to Mitigate ❌

Rogue employees -- not just external threat groups -- pose a formidable threat to incident response teams.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Patches IE Zero-Day Among 74 Vulnerabilities πŸ•΄

The November Patch Tuesday update fixed 13 critical flaws, including a zero-day bug in Internet Explorer.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Companies Increasingly Fail Interim Security Test, But Gap Narrows πŸ•΄

Stability of PCI DSS helps companies cope and create more mature security programs, but some parts of the Payment Card Industry's Data Secure Standard continue to cause headaches.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2010-2247 (makepasswd)

makepasswd 1.10 default settings generate insecure passwords

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ While CISOs Fret, Business Leaders Tout Security Robustness πŸ•΄

A new Nominet survey shows a familiar disconnect between business and security teams on the matter of cyber preparedness.

πŸ“– Read

via "Dark Reading: ".
⚠ No, YouTube isn’t planning to jettison your unprofitable channel ⚠

Or your small/new channel, or to shut you down if you use an ad blocker, though a clause in its new ToS is leading people to fear the worst.

πŸ“– Read

via "Naked Security".
⚠ Microsoft says it will honor California’s new privacy law across US ⚠

Microsoft said CCPA is good news, given the failure of Congress to pass a comprehensive privacy protection law at the federal level.

πŸ“– Read

via "Naked Security".
❌ Federal Court: Suspicionless Search of Traveler Devices by Border Agents Is Unconstitutional ❌

U.S. Customs agents now must have reasonable cause and suspicion to search traveler devices at points of entry.

πŸ“– Read

via "Threatpost".
⚠ US-CERT warns of critical flaws in Medtronic equipment ⚠

Medtronic's latest problem is in their Valleylab electrosurgical generators used by surgeons things like cauterisation during operations.

πŸ“– Read

via "Naked Security".
⚠ Apple pulls Instagram-watching app from store ⚠

Apple has yanked an app from its iTunes App Store that allowed Instagram users to follow their friends’ activities on the social network.

πŸ“– Read

via "Naked Security".
πŸ” Five reasons healthcare data security is at Ebola crisis levels πŸ”

Lots of PHI, low security, and multiple entry points make hospitals the perfect target for hackers and ransomware attacks are up 45% in Q3.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Unreasonable Security Best Practices vs. Good Risk Management πŸ•΄

Perfection is impossible, and pretending otherwise just makes things worse. Instead, make risk-based decisions.

πŸ“– Read

via "Dark Reading: ".
πŸ” How cybercriminals trick you into giving your information over the phone πŸ”

IBM's Chief People Hacker Stephanie "Snow" Carruthers describes how criminals use caller ID spoofing to get your private data.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to manage Siri privacy settings in iOS 13.2 πŸ”

In iOS 13.2, you can opt out of Siri voice review requests and delete recording history from your Apple devices.

πŸ“– Read

via "Security on TechRepublic".
❌ IoT Security Woes Plague Healthcare Industry ❌

Hospitals and IoT device manufacturers must take a dual approach in securing connected telehealth devices.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2009-5046 (debian_linux, jetty)

JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5045 (debian_linux, jetty)

Dump Servlet information leak in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".