πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Microsoft says it will honor California’s new privacy law across US ⚠

Microsoft said CCPA is good news, given the failure of Congress to pass a comprehensive privacy protection law at the federal level.

πŸ“– Read

via "Naked Security".
❌ Federal Court: Suspicionless Search of Traveler Devices by Border Agents Is Unconstitutional ❌

U.S. Customs agents now must have reasonable cause and suspicion to search traveler devices at points of entry.

πŸ“– Read

via "Threatpost".
⚠ US-CERT warns of critical flaws in Medtronic equipment ⚠

Medtronic's latest problem is in their Valleylab electrosurgical generators used by surgeons things like cauterisation during operations.

πŸ“– Read

via "Naked Security".
⚠ Apple pulls Instagram-watching app from store ⚠

Apple has yanked an app from its iTunes App Store that allowed Instagram users to follow their friends’ activities on the social network.

πŸ“– Read

via "Naked Security".
πŸ” Five reasons healthcare data security is at Ebola crisis levels πŸ”

Lots of PHI, low security, and multiple entry points make hospitals the perfect target for hackers and ransomware attacks are up 45% in Q3.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Unreasonable Security Best Practices vs. Good Risk Management πŸ•΄

Perfection is impossible, and pretending otherwise just makes things worse. Instead, make risk-based decisions.

πŸ“– Read

via "Dark Reading: ".
πŸ” How cybercriminals trick you into giving your information over the phone πŸ”

IBM's Chief People Hacker Stephanie "Snow" Carruthers describes how criminals use caller ID spoofing to get your private data.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to manage Siri privacy settings in iOS 13.2 πŸ”

In iOS 13.2, you can opt out of Siri voice review requests and delete recording history from your Apple devices.

πŸ“– Read

via "Security on TechRepublic".
❌ IoT Security Woes Plague Healthcare Industry ❌

Hospitals and IoT device manufacturers must take a dual approach in securing connected telehealth devices.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2009-5046 (debian_linux, jetty)

JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5045 (debian_linux, jetty)

Dump Servlet information leak in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cardplanet Operator Extradited for Facilitating Credit Card Fraud πŸ•΄

Russian national Aleksei Burkov is charged with wire fraud, access device fraud, and conspiracy to commit identity theft, among other crimes.

πŸ“– Read

via "Dark Reading: ".
⚠ November 2019 Patch Tuesday fixes 13 critical flaws and one zero day ⚠

November’s Patch Tuesday arrived to plug 73 CVE-level vulnerabilities across Microsoft’s software products, including 13 'criticals'.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2010-2473 (drupal)

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-2472 (drupal)

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-2471 (debian_linux, drupal)

drupal6 version 6.16 has open redirection

πŸ“– Read

via "National Vulnerability Database".
❌ Google’s Plan to Crunch Health Data on Millions of Patients Draws Fire ❌

"Project Nightingale" is fully HIPAA-compliant, according to Google -- but researchers said they see big red flags for consumer data privacy.

πŸ“– Read

via "Threatpost".
πŸ•΄ Breaches Are Inevitable, So Embrace the Chaos πŸ•΄

Avoid sinking security with principles of shipbuilding known since the 15th century.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2010-2450 (debian_linux, service_provider)

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2007-6745 (clamav, debian_linux)

clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

πŸ“– Read

via "National Vulnerability Database".