πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Facebook bans deepfakes, but not cheapfakes or shallowfakes ⚠

Quick-n-sleazy edits are still OK, such as the 75% slowdown that made Nancy Pelosi slur or the edit that turned Joe Biden into a racist.

πŸ“– Read

via "Naked Security".
⚠ US warns of Iranian cyber threat ⚠

The DHS has issued three warnings in the last few days encouraging people to be on alert for physical and cyber attacks from Iran.

πŸ“– Read

via "Naked Security".
⚠ YouTube to treat all kid-aimed videos like they’re COPPA-liable ⚠

The FTC can fine content creators up to $42,530 per violation - even though they don't collect, receive, nor have access to kids' data.

πŸ“– Read

via "Naked Security".
⚠ REvil ransomware exploiting VPN flaws made public last April ⚠

Researchers report flaws, vendors issue patches, organisations apply them - and everyone lives happily ever after. Right? Wrong!

πŸ“– Read

via "Naked Security".
❌ Get Ready for the Microsoft Windows 7 EOL on January 14th ❌

January 14, 2020, is a day cybersecurity stakeholders should pay attention to, as it marks the end of Microsoft support in Windows 7. From a security perspective, both the routine monthly security patches as well as hot fixes for attacks in the wild will not be available, effectively making any newly discovered vulnerability a Windows 7 zero-day.

πŸ“– Read

via "Threatpost".
❌ TikTok Riddled With Security Flaws ❌

The video sharing app has fixed several flaws allowing partial account takeover and information exposure.

πŸ“– Read

via "Threatpost".
πŸ” Apple exec explains privacy protections, while Facebook leader looks for loopholes πŸ”

At CES 2020, Facebook privacy officer says new California law doesn't apply because the company doesn't sell data, only ads.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The "Art of Cloud War" for Business-Critical Data πŸ•΄

How business executives' best intentions may be negatively affecting security and risk mitigation strategies - and exposing weaknesses in organizational defenses.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-3936 (opsview, opsview_core)

Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.

πŸ“– Read

via "National Vulnerability Database".
❌ Mozilla Releases Firefox 72: High-Severity Bugs Patched, Fingerpinting Nixed ❌

Mozilla tackles high-severity bugs in its latest Firefox 72 and Firefox ESR 68.4 releases at the same time rolls a major privacy feature .

πŸ“– Read

via "Threatpost".
❌ Liverpool Voyeur Used IM-RAT to Video Women at Home ❌

The case highlights the rising issue of stalkerware, which has reached epidemic proportions.

πŸ“– Read

via "Threatpost".
πŸ•΄ In App Development, Does No-Code Mean No Security? πŸ•΄

No-code and low-code development platforms are part of application development, but there are keys to making sure that they don't leave security behind with traditional coding.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ TikTok Bugs Put Users' Videos, Personal Data At Risk πŸ•΄

Researchers found it was possible to spoof SMS messages from TikTok and exploit an API flaw that could grant access to users' personal data.

πŸ“– Read

via "Dark Reading: ".
πŸ” Alleged IP Theft Cost Industrial Cleaning Company $15M πŸ”

The company alleges a former employee violated company policy and betrayed its trust as he "intentionally decimated" its North American business.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy ❌

Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes available before then.

πŸ“– Read

via "Threatpost".
❌ Man Sentenced in ATM Skimming Conspiracy ❌

A Romanian national has been sentenced to 5 years in prison after racking up almost $400,000 in an ATM skimming scheme.

πŸ“– Read

via "Threatpost".
πŸ•΄ Google's Project Zero Policy Change Mandates 90-Day Disclosure πŸ•΄

The updated disclosure policy aims to achieve more thorough and improved patch development, Google reports.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-3941 (xnview)

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
πŸ” CES 2020: How McAfee's Just in Time debugger stops cybercriminals πŸ”

How the Advanced Threat Research Team can stop hackers from stealing personal data from a wearable device.

πŸ“– Read

via "Security on TechRepublic".