πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Google Details Its Responses to Cyber Attacks, Disinformation πŸ•΄

Government groups continue to attack user credentials and distribute disinformation according to a new blog post from Google's Threat Analysis Group.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Analysis of Jira Bug Stresses Impact of SSRF in Public Cloud πŸ•΄

More than 3,100 Jira instances are still vulnerable to a server-side request forgery vulnerability patched in August.

πŸ“– Read

via "Dark Reading: ".
❌ SDKs Misused to Scrape Twitter, Facebook Account Info ❌

Malicious mobile apps could be created to scrape and share profile information, email addresses and more.

πŸ“– Read

via "Threatpost".
πŸ” The sinister timing of deepfakes and the 2020 election πŸ”

Education and legislation are needed to combat the significant threat of deepfakes.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ SQL Injection Errors No Longer the Top Software Security Issue πŸ•΄

In newly updated Common Weakness Enumeration (CWE), SQL injection now ranks sixth.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-2187

xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2177

OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.

πŸ“– Read

via "National Vulnerability Database".
❌ NSO Group President Defends Controversial Tactics ❌

Firm defends controversial business offerings, claims it should be considered a force of good.

πŸ“– Read

via "Threatpost".
πŸ•΄ A Cause You Care About Needs Your Cybersecurity Help πŸ•΄

By donating their security expertise, infosec professionals are supporting non-profits, advocacy groups, and communities in-need.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-2480

Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2207

dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Edge Feature Section πŸ•΄

Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-2717

The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2523

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2515

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
⚠ Twitter says it won’t delete tweets from those who have died ⚠

It "was a miss on our part", Twitter said.

πŸ“– Read

via "Naked Security".
⚠ HPE warns of impending SSD disk doom ⚠

The company has revealed that many of its SSDs are set to permanently fail by default after 32,768 hours of operation.

πŸ“– Read

via "Naked Security".
⚠ Ransomware attack freezes health records access at 110 nursing homes ⚠

In some cases, nurses can’t update and order drugs. For one assisted-living facility, lack of timely Medicaid billing could force closure.

πŸ“– Read

via "Naked Security".
⚠ Kids’ smartwatch security tracker can be hacked by anyone ⚠

For researchers at testing outfit AV-Test, the SMA M2 kids’ smartwatch is just the tip of an iceberg of terrible security.

πŸ“– Read

via "Naked Security".
⚠ S2 Ep18: Missing cryptoqueen, festive phishing and can the web be saved? – Naked Security Podcast ⚠

New episode available now!

πŸ“– Read

via "Naked Security".