πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 5 Security Resolutions to Prevent a Ransomware Attack in 2020 πŸ•΄

Proactively consider tools to detect anomalous behavior, automatically remediate, and segment threats from moving across the network.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2012-2312

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.

πŸ“– Read

via "National Vulnerability Database".
❌ Ring Plagued by Security Issues, Flood of Hacks ❌

A Motherboard report found Ring lacking basic security measures for preventing hackers from hijacking the devices.

πŸ“– Read

via "Threatpost".
❌ Why Cloud, Collaboration Breed Insider Threats ❌

Many employees don't follow company security policies when they use handy productivity tools.

πŸ“– Read

via "Threatpost".
πŸ” FBI tech tips for safe holiday travel πŸ”

Whether you're traveling by plane, planning a road trip, or hosting guests for the holidays, it's important to practice good cybersecurity.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2012-2656

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Wireshark Analyzer 3.2.0 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  GRR 3.4.0.1 πŸ› 

GRR Rapid Response is an incident response framework focused on remote live forensics. The goal of GRR is to support forensics and investigations in a fast, scalable manner to allow analysts to quickly triage attacks and perform analysis remotely. GRR consists of 2 parts: client and server. GRR client is deployed on systems that one might want to investigate. On every such system, once deployed, GRR client periodically polls GRR frontend servers for work. "Work" means running a specific action: downloading file, listing a directory, etc. GRR server infrastructure consists of several components (frontends, workers, UI servers) and provides web-based graphical user interface and an API endpoint that allows analysts to schedule actions on clients and view and process collected data.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ” Getting ready for the end of Basic Authentication in Exchange Web Services πŸ”

Prepare your applications and users for big changes on 13 October 2020.

πŸ“– Read

via "Security on TechRepublic".
⚠ Instagram hides β€˜false’ content, unless it’s from a politician ⚠

Instagram's expanding its fact-checking program but, like Facebook, says it won't keep political speech away from "public debate and scrutiny."

πŸ“– Read

via "Naked Security".
⚠ Proposed standard would make warrant canaries machine-readable ⚠

For years, organisations have been using a common tactic called the warrant canary to warn people that the government has secretly demanded access to their private information. Now, a proposed standard could make this tool easier to use.

πŸ“– Read

via "Naked Security".
⚠ Get in line! 38,000 students and staff forced to queue for new passwords ⚠

It's not a bread line, and it's not a line to see Santa - it's an analog response to a nasty cyber attack.

πŸ“– Read

via "Naked Security".
⚠ S2 Ep21: Plundervolt, domain name gunfight, Facebook snubs Congress – Naked Security Podcast ⚠

Latest podcast episode - listen now!

πŸ“– Read

via "Naked Security".
⚠ Chrome 79 patched after Android WebView app chaos ⚠

Google has rushed out a fix for a bug in the Android version of Chrome that left some app users unable to access accounts or retrieve stored data.

πŸ“– Read

via "Naked Security".
πŸ” What is Identity and Access Management (IAM)? πŸ”

Learn about identity and access management (IAM), how IAM works, and why organizations should have IAM in Data Protection 101, our series on the fundamentals of information security.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Why 5G harbors multiple security weaknesses πŸ”

Certain security flaws in 2G, 3G, and 4G have not been resolved, and 5G is vulnerable as well, says a new report from Positive Technologies.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ How a Password-Free World Could Have Prevented the Biggest Breaches of 2019 πŸ•΄

If history has taught us anything, it's that hackers can (and will) compromise passwords. Innovation in authentication technology is poised to change that in the coming year.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google Cloud External Key Manager Now in Beta πŸ•΄

Cloud EKM is designed to separate data at rest from encryption keys stored in a third-party management system.

πŸ“– Read

via "Dark Reading: ".
❌ Honda Leaks Data of 26K North American Customers ❌

The leaky database was online for about a week, exposing customers' vehicles information and personal identifiable information.

πŸ“– Read

via "Threatpost".
⚠ Hiding malware downloads in Taylor Swift pics! New SophosLabs report ⚠

Just because a malware family isn't all over the headlines doesn't mean it isn't interesting... or important... or dangerous!

πŸ“– Read

via "Naked Security".
πŸ•΄ Privacy Requirements & Penalties Grow, Causing Firms to Struggle πŸ•΄

Between Europe's and California's privacy laws, companies have a complex landscape to navigate in 2020. Even data-mature industries, such as financial services, see problems ahead.

πŸ“– Read

via "Dark Reading: ".