πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Cisco Drops a Dozen Vulnerability Patches πŸ•΄

Among them are three for critical authentication bypass flaws.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Ransomware Victim Southwire Sues Maze Operators πŸ•΄

Attackers demanded $6 million from the wire and cable manufacturer when they launched a December ransomware campaign.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2012-5878

Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-5693

Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the phNo2Attack parameter to (5) CSAttack.pl or (6) SEAttack.pl in frameworkgui/; the (7) platformDD2 parameter to frameworkgui/SEAttack.pl; the (8) agentURLPath or (9) agentControlKey parameter to frameworkgui/attach2agents.pl; or the (10) controlKey parameter to frameworkgui/attachMobileModem.pl. NOTE: The hostingPath parameter to CSAttack.pl and SEAttack.pl vectors and the appURLPath parameter to attachMobileModem.pl vector are covered by CVE-2012-5878.

πŸ“– Read

via "National Vulnerability Database".
πŸ” 5 predictions for protecting data in the payments and security ecosystem πŸ”

As demand for personalization and seamless consumer experiences grow, security must keep up, said VISA's chief risk officer.

πŸ“– Read

via "Security on TechRepublic".
⚠ Monday review – the hot stories of the holidays ⚠

From 'Greta Thunberg' malware to Python 3, get yourself up to date with everything we've written since Christmas.

πŸ“– Read

via "Naked Security".
πŸ•΄ What Tools Will Find Misconfigurations in My AWS S3 Cloud Buckets? πŸ•΄

Misconfigured cloud buckets leak sensitive data. Here's how to keep your Amazon Web Services (AWS) Simple Server Storage (S3) buckets secured.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Client-Side JavaScript Risks & the CCPA πŸ•΄

How California's new privacy law increases the liability for securing Web-facing user data, and what enterprises can do to mitigate their risk.

πŸ“– Read

via "Dark Reading: ".
❌ Hackers Deface U.S. Gov Website With Pro-Iran Messages ❌

The Federal Depository Library Program (FDLP) website was defaced over the weekend to show a picture of a bloodied President Donald Trump.

πŸ“– Read

via "Threatpost".
⚠ Don’t fall for the β€œStart your 2020 with a gift from us” scam… ⚠

There is no free Macbook. There IS no free Macbook. There is NO free Macbook.

πŸ“– Read

via "Naked Security".
πŸ•΄ Mimecast Acquires Segasec to Boost Phishing Defense πŸ•΄

Segasec's technology will be integrated into Mimecast's email and Web security services to identify malicious domains.

πŸ“– Read

via "Dark Reading: ".
❌ DeathRansom Campaign Linked to Malware Cornucopia ❌

One threat actor appears to be behind several ongoing, related campaigns.

πŸ“– Read

via "Threatpost".
πŸ•΄ US Government Publishing Office Website Defaced πŸ•΄

The Federal Depository Library Program (FDLP) website was attacked by a group of hackers claiming to represent the government of Iran.

πŸ“– Read

via "Dark Reading: ".
πŸ” Mozilla Allows Users to Delete Firefox Telemetry Data πŸ”

Companies like Mozilla are using the passage of the CCPA as a way to better empower users to delete their own personal data.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Magecart Hits Parents and Students via Blue Bear Attack ❌

The latest attack takes aim at a vertical-specific e-commerce platform.

πŸ“– Read

via "Threatpost".
❌ ToTok Returned to Google Play Despite β€˜Spy Tool’ Claims ❌

The communications app faces continued backlash after a New York Times report said it was used as a government spying tool.

πŸ“– Read

via "Threatpost".
πŸ” Comcast announces new Wi-Fi 6-certified gateway, security features for internet customers at CES 2020 πŸ”

Comcast is making its internet service faster and more secure with new hardware and free security features that alerts customers to threats.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Malicious Google Play Apps Linked to SideWinder APT πŸ•΄

The active attack involving three malicious Android applications is the first exploiting CVE-2019-2215, Trend Micro researchers report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Widely Known Flaw in Pulse Secure VPN Being Used in Ransomware Attacks πŸ•΄

New Year's Eve attack on currency exchange service Travelex may have involved use of the flaw.

πŸ“– Read

via "Dark Reading: ".
⚠ US military branches ban TikTok following Pentagon’s warning ⚠

The latest attempt to prove it's not under China's thumb: TikTok's first transparency report.

πŸ“– Read

via "Naked Security".
⚠ IT exec sets up fake biz to scam his employer out of $6m ⚠

He cooked up an IT vendor, its invoices, its vapor-gear, and the phantom employees who never showed up to do all those services.

πŸ“– Read

via "Naked Security".