πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Unreasonable Security Best Practices vs. Good Risk Management πŸ•΄

Perfection is impossible, and pretending otherwise just makes things worse. Instead, make risk-based decisions.

πŸ“– Read

via "Dark Reading: ".
πŸ” How cybercriminals trick you into giving your information over the phone πŸ”

IBM's Chief People Hacker Stephanie "Snow" Carruthers describes how criminals use caller ID spoofing to get your private data.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to manage Siri privacy settings in iOS 13.2 πŸ”

In iOS 13.2, you can opt out of Siri voice review requests and delete recording history from your Apple devices.

πŸ“– Read

via "Security on TechRepublic".
❌ IoT Security Woes Plague Healthcare Industry ❌

Hospitals and IoT device manufacturers must take a dual approach in securing connected telehealth devices.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2009-5046 (debian_linux, jetty)

JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5045 (debian_linux, jetty)

Dump Servlet information leak in jetty before 6.1.22.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cardplanet Operator Extradited for Facilitating Credit Card Fraud πŸ•΄

Russian national Aleksei Burkov is charged with wire fraud, access device fraud, and conspiracy to commit identity theft, among other crimes.

πŸ“– Read

via "Dark Reading: ".
⚠ November 2019 Patch Tuesday fixes 13 critical flaws and one zero day ⚠

November’s Patch Tuesday arrived to plug 73 CVE-level vulnerabilities across Microsoft’s software products, including 13 'criticals'.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2010-2473 (drupal)

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-2472 (drupal)

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-2471 (debian_linux, drupal)

drupal6 version 6.16 has open redirection

πŸ“– Read

via "National Vulnerability Database".
❌ Google’s Plan to Crunch Health Data on Millions of Patients Draws Fire ❌

"Project Nightingale" is fully HIPAA-compliant, according to Google -- but researchers said they see big red flags for consumer data privacy.

πŸ“– Read

via "Threatpost".
πŸ•΄ Breaches Are Inevitable, So Embrace the Chaos πŸ•΄

Avoid sinking security with principles of shipbuilding known since the 15th century.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2010-2450 (debian_linux, service_provider)

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2007-6745 (clamav, debian_linux)

clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 2019 Trending as Worst Year on Record for Data Breaches πŸ•΄

New Risk Based Security report shows data breaches up 33.3% over last year so far.

πŸ“– Read

via "Dark Reading: ".
πŸ” Insider Stole Billion Dollar Battery Trade Secrets πŸ”

Yet another Chinese national - this time an employee at an Oklahoma petroleum company - has pleaded guilty to trade secret theft.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ The Ripple Effect of Data Breaches: How Damage Spreads πŸ•΄

The financial loss from so-called 'ripple events' is thirteen times greater than the cost of single-party security incidents.

πŸ“– Read

via "Dark Reading: ".
πŸ” Tracking endpoints and ensuring device security a vexing problem for healthcare CIOs πŸ”

The consequences of security incidents in hospitals can be life-or-death, but security practices lag behind other industries.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Cybersecurity: An Organizationwide Responsibility πŸ•΄

C-suite execs must set an example of good practices while also supporting the IT department with enough budget to protect the organization from next-generation cyberattacks.

πŸ“– Read

via "Dark Reading: ".