❌ Get Ready for the Microsoft Windows 7 EOL on January 14th ❌
📖 Read
via "Threatpost".
January 14, 2020, is a day cybersecurity stakeholders should pay attention to, as it marks the end of Microsoft support in Windows 7. From a security perspective, both the routine monthly security patches as well as hot fixes for attacks in the wild will not be available, effectively making any newly discovered vulnerability a Windows 7 zero-day.📖 Read
via "Threatpost".
Threat Post
Get Ready for the Microsoft Windows 7 EOL on January 14th
January 14, 2020, is a day cybersecurity stakeholders should pay attention to, as it marks the end of Microsoft support in Windows 7.
❌ TikTok Riddled With Security Flaws ❌
📖 Read
via "Threatpost".
The video sharing app has fixed several flaws allowing partial account takeover and information exposure.📖 Read
via "Threatpost".
Threat Post
TikTok Riddled With Security Flaws
The video sharing app has fixed several flaws allowing partial account takeover and information exposure.
🔐 Apple exec explains privacy protections, while Facebook leader looks for loopholes 🔐
📖 Read
via "Security on TechRepublic".
At CES 2020, Facebook privacy officer says new California law doesn't apply because the company doesn't sell data, only ads.📖 Read
via "Security on TechRepublic".
TechRepublic
Apple exec explains privacy protections, while Facebook leader looks for loopholes
At CES 2020, Facebook privacy officer says new California law doesn't apply because the company doesn't sell data, only ads.
🕴 The "Art of Cloud War" for Business-Critical Data 🕴
📖 Read
via "Dark Reading: ".
How business executives' best intentions may be negatively affecting security and risk mitigation strategies - and exposing weaknesses in organizational defenses.📖 Read
via "Dark Reading: ".
Dark Reading
The Art of Cloud War for Business-Critical Data
How business executives' best intentions may be negatively affecting security and risk mitigation strategies - and exposing weaknesses in organizational defenses.
ATENTION‼ New - CVE-2013-3936 (opsview, opsview_core)
📖 Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.📖 Read
via "National Vulnerability Database".
❌ Mozilla Releases Firefox 72: High-Severity Bugs Patched, Fingerpinting Nixed ❌
📖 Read
via "Threatpost".
Mozilla tackles high-severity bugs in its latest Firefox 72 and Firefox ESR 68.4 releases at the same time rolls a major privacy feature .📖 Read
via "Threatpost".
Threat Post
Mozilla Updates Firefox Browser: Zero-Day Bug Patched, Fingerprinting Nixed
Mozilla tackles high-severity bugs in its latest Firefox 72 and Firefox ESR 68.4 releases at the same time rolls a major privacy feature .
❌ Liverpool Voyeur Used IM-RAT to Video Women at Home ❌
📖 Read
via "Threatpost".
The case highlights the rising issue of stalkerware, which has reached epidemic proportions.📖 Read
via "Threatpost".
Threat Post
Liverpool Voyeur Used IM-RAT to Video Women at Home
The case highlights the rising issue of stalkerware, which has reached epidemic proportions.
🕴 In App Development, Does No-Code Mean No Security? 🕴
📖 Read
via "Dark Reading: ".
No-code and low-code development platforms are part of application development, but there are keys to making sure that they don't leave security behind with traditional coding.📖 Read
via "Dark Reading: ".
Dark Reading
In App Development, Does No-Code Mean No Security?
No-code and low-code development platforms are part of application development, but there are keys to making sure that they don't leave security behind with traditional coding.
🕴 TikTok Bugs Put Users' Videos, Personal Data At Risk 🕴
📖 Read
via "Dark Reading: ".
Researchers found it was possible to spoof SMS messages from TikTok and exploit an API flaw that could grant access to users' personal data.📖 Read
via "Dark Reading: ".
Dark Reading
TikTok Bugs Put Users' Videos, Personal Data At Risk
Researchers found it was possible to spoof SMS messages from TikTok and exploit an API flaw that could grant access to users' personal data.
🔏 Alleged IP Theft Cost Industrial Cleaning Company $15M 🔏
📖 Read
via "Subscriber Blog RSS Feed ".
The company alleges a former employee violated company policy and betrayed its trust as he "intentionally decimated" its North American business.📖 Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Alleged IP Theft Cost Industrial Cleaning Company $15M
The company alleges a former employee violated company policy and betrayed its trust as he "intentionally decimated" its North American business.
❌ Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy ❌
📖 Read
via "Threatpost".
Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes available before then.📖 Read
via "Threatpost".
Threat Post
Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy
Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes available before then.
❌ Man Sentenced in ATM Skimming Conspiracy ❌
📖 Read
via "Threatpost".
A Romanian national has been sentenced to 5 years in prison after racking up almost $400,000 in an ATM skimming scheme.📖 Read
via "Threatpost".
Threat Post
Man Sentenced in ATM Skimming Conspiracy
A Romanian national has been sentenced to 5 years in prison after racking up almost $400,000 in an ATM skimming scheme.
🕴 Google's Project Zero Policy Change Mandates 90-Day Disclosure 🕴
📖 Read
via "Dark Reading: ".
The updated disclosure policy aims to achieve more thorough and improved patch development, Google reports.📖 Read
via "Dark Reading: ".
Dark Reading
Google's Project Zero Policy Change Mandates 90-Day Disclosure
The updated disclosure policy aims to achieve more thorough and improved patch development, Google reports.
ATENTION‼ New - CVE-2013-3941 (xnview)
📖 Read
via "National Vulnerability Database".
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.📖 Read
via "National Vulnerability Database".
🔐 CES 2020: How McAfee's Just in Time debugger stops cybercriminals 🔐
📖 Read
via "Security on TechRepublic".
How the Advanced Threat Research Team can stop hackers from stealing personal data from a wearable device.📖 Read
via "Security on TechRepublic".
TechRepublic
CES 2020: How McAfee's Just in Time debugger stops cybercriminals
How the Advanced Threat Research Team can stop hackers from stealing personal data from a wearable device.
ATENTION‼ New - CVE-2013-3945 (mrsid)
📖 Read
via "National Vulnerability Database".
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.📖 Read
via "National Vulnerability Database".
🕴 Developers Still Don't Properly Handle Sensitive Data 🕴
📖 Read
via "Dark Reading: ".
The top classes of vulnerabilities for 2019 indicate that developers still don't correctly sanitize inputs, nor protect passwords and keys as they should.📖 Read
via "Dark Reading: ".
Dark Reading
Developers Still Don't Properly Handle Sensitive Data
The top classes of vulnerabilities for 2019 indicate that developers still don't correctly sanitize inputs, nor protect passwords and keys as they should.
❌ Drake Lyrics Used as Calling Card in Malware Attack ❌
📖 Read
via "Threatpost".
A hacker who apparently likes the musician Drake leaves lyrics from the artist's song In My Feelings behind in an attack that delivers malware Lokibot or Azorult.📖 Read
via "Threatpost".
Threat Post
Drake Lyrics Used as Calling Card in Malware Attack
A hacker who apparently likes the musician Drake leaves lyrics from the artists song In My Feelings behind in attack that delivers malware Lokibot or Azorult.
ATENTION‼ New - CVE-2011-5266
📖 Read
via "National Vulnerability Database".
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.📖 Read
via "National Vulnerability Database".
ATENTION‼ New - CVE-2011-5250
📖 Read
via "National Vulnerability Database".
Snare for Linux before 1.7.0 has CSRF in the web interface.📖 Read
via "National Vulnerability Database".