πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” How to use iCloud Keychain to manage passwords on your iPhone or iPad πŸ”

Learn how iCloud Keychain can help you keep track of your app and website passwords.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2012-1592

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1115

A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1114

A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.

πŸ“– Read

via "National Vulnerability Database".
⚠ OpenBSD devs patch authentication bypass bug ⚠

One of the internet's most popular free operating systems allowed attackers to bypass its authentication controls.

πŸ“– Read

via "Naked Security".
⚠ Instagram trying to protect kids by getting dates of birth from new users ⚠

It's about showing age-appropriate content, it said. Though staying safe from child-privacy lawsuits doesn't hurt, either.

πŸ“– Read

via "Naked Security".
⚠ US parents file class action against TikTok over children’s privacy ⚠

Collecting children's data without their guardians' consent is illegal under COPPA and already earned TikTok a huge fine.

πŸ“– Read

via "Naked Security".
⚠ Mac users targetted by Lazarus β€˜fileless’ Trojan ⚠

The Lazarus hacking group are trying to sneak a β€˜fileless’ Trojan on to Apple computers, disguised as a fake cryptocurrency trading program.

πŸ“– Read

via "Naked Security".
❌ Stealthy MacOS Malware Tied to Lazarus APT ❌

Researcher discovered a MacOS trojan hiding behind a fake crypto trading platform believed to be the work of the state-sponsored North Korean hackers behind WannaCry.

πŸ“– Read

via "Threatpost".
πŸ” Friday Five: 12/6 Edition πŸ”

A new data breach report highlights risks for 2020, a website selling spying tools taken down, and more - catch up on the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Facebook Alleges Company Infiltrated Thousands for Ad Fraud ❌

Facebook has paid over $4 million to victims to reimburse them for the unauthorized ads purchased using their ad accounts.

πŸ“– Read

via "Threatpost".
πŸ•΄ Success Enablers or Silent Killers? πŸ•΄

These five success enablers will help CISOs report, measure, and demonstrate ROI to the C-suite.

πŸ“– Read

via "Dark Reading: ".
❌ Linux Bug Opens Most VPNs to Hijacking ❌

In a coffee-shop scenario, attackers can hijack "secure" VPN sessions of those working remotely, injecting data into their TCP streams.

πŸ“– Read

via "Threatpost".
πŸ•΄ Mega Breaches Are Forcing Us to a Passwordless World. Are We Finally Ready? πŸ•΄

Passwordless authentication advocates see 2020 as a potential turning point year for the technology. But can the industry get off the dime?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Senators Call for End to Controversial NSA Program πŸ•΄

The program for collecting telephone call metadata has faced increased scrutiny and restrictions since Edward Snowden revealed its existence in 2013.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2012-1615

A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Data Center Provider CyrusOne Confirms Ransomware Attack πŸ•΄

The attack struck CyrusOne's managed services division and compromised six customers primarily serviced by a New York data center.

πŸ“– Read

via "Dark Reading: ".
❌ News Wrap: Authorities Target Evil Corp., Imminent Monitor, Money Mules ❌

In this past week, the authorities have cracked down on various BEC scams and cybercrime gangs.

πŸ“– Read

via "Threatpost".
❌ Feds Crack Down on Money Mules, Warn of BEC Scams ❌

Authorities say they have halted over 600 domestic money mules – exceeding the 400 money mules stopped last year.

πŸ“– Read

via "Threatpost".
πŸ” TeamViewer unveils new patch management system πŸ”

The new tool will provide IT departments with system-wide visibility of all the patches needed.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Analysts worry about tech security threats ahead of 2020 elections πŸ”

Security experts say most voting machines are safe and secure, but disinformation campaigns on platforms like Facebook and Twitter need to be addressed.

πŸ“– Read

via "Security on TechRepublic".