πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ When You Know Too Much: Protecting Security Data from Security People πŸ•΄

As security tools gather growing amounts of intelligence, experts explain how companies can protect this data from rogue insiders and other threats.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Target Seeks $74M in Data Breach Reimbursement from Insurance Company πŸ•΄

The funds would cover some of the money Target paid to reimburse financial institutions for credit card replacement after the 2013 breach.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Flaws in VNC Threaten Industrial Environments ❌

Some of the bugs allow remote code-execution.

πŸ“– Read

via "Threatpost".
πŸ•΄ Researchers Explore How Mental Health Is Tracked Online πŸ•΄

An analysis of popular mental health-related websites revealed a vast number of trackers, many of which are used for targeted advertising.

πŸ“– Read

via "Dark Reading: ".
❌ Three Areas to Consider, to Focus Your Cyber-Plan ❌

DNS, rogue employees and phishing/social engineering should be top of the list of threat areas for organizations to address.

πŸ“– Read

via "Threatpost".
πŸ‘1
⚠ Monday review – the hot 20 stories of the week ⚠

From a WhatsApp-attacking video file to the latest adopter of DNS-over-HTTPS, and everything in between. It's the weekly security roundup.

πŸ“– Read

via "Naked Security".
⚠ Russian hacker gets 4 years in jail for NeverQuest banking malware ⚠

The NeverQuest Trojan has been used by cybermuggers to try to weasel millions of dollars out of victims’ bank accounts.

πŸ“– Read

via "Naked Security".
⚠ Russian bans sale of devices that don’t come with β€œRussian software” ⚠

The Russian Government’s campaign to control how its citizens use the internet seems to be gathering steam.

πŸ“– Read

via "Naked Security".
⚠ Ad-blocking companies block β€˜unblockable’ tracker ⚠

Ad-blockers have figured out a way to block the unblockable - a pernicious tracker technique that hides advertising networks in plain sight.

πŸ“– Read

via "Naked Security".
⚠ OneCoin crypto-scam lawyer found guilty of worldwide $400m fraud ⚠

A lawyer who boasted of making "50 by 50" - as in, $50m by the age of 50 - is now facing a potential 50+ years behind bars.

πŸ“– Read

via "Naked Security".
πŸ•΄ Time to Warn Users About Black Friday & Cyber Monday Scams πŸ•΄

Warn your employees to avoid the inevitable scams associated with these two "holidays," or you risk compromising your company's network.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ They See You When You're Shopping: Holiday Cybercrime Starts Early πŸ•΄

Researchers notice year-end phishing attacks starting in July and ramping up in September.

πŸ“– Read

via "Dark Reading: ".
❌ PoS Malware Exposes Customer Data of Catch Restaurants ❌

A newly announced data breach of several popular Catch restaurants stemmed from malware on its point-of-sale (PoS) systems.

πŸ“– Read

via "Threatpost".
πŸ•΄ New: 2019 State of the Internet / Security: Financial Services Attack Economy πŸ•΄

Every organization should be paying attention to the attacks targeting financial services systems.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Home Safe: 20 Cybersecurity Tips for Your Remote Workers πŸ•΄

How can you protect your precious corporate endpoints from the mysterious dangers that might await when you're not by their side? Empower home office users with these tips.

πŸ“– Read

via "Dark Reading: ".
πŸ” Meet Harlan Carvey, Digital Guardian's New Senior Threat Hunter πŸ”

In this Q&A, we sit down with Harlan Carvey, Digital Guardian's new Senior Threat Hunter, to dig into how he approaches threat hunting, incident response, and more.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2011-4924

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2924 (debian_linux, fedora, foomatic-filters)

foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2923 (debian_linux, foomatic-filters)

foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

πŸ“– Read

via "National Vulnerability Database".