🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
Get Ready for the Microsoft Windows 7 EOL on January 14th

January 14, 2020, is a day cybersecurity stakeholders should pay attention to, as it marks the end of Microsoft support in Windows 7. From a security perspective, both the routine monthly security patches as well as hot fixes for attacks in the wild will not be available, effectively making any newly discovered vulnerability a Windows 7 zero-day.

📖 Read

via "Threatpost".
TikTok Riddled With Security Flaws

The video sharing app has fixed several flaws allowing partial account takeover and information exposure.

📖 Read

via "Threatpost".
🔐 Apple exec explains privacy protections, while Facebook leader looks for loopholes 🔐

At CES 2020, Facebook privacy officer says new California law doesn't apply because the company doesn't sell data, only ads.

📖 Read

via "Security on TechRepublic".
🕴 The "Art of Cloud War" for Business-Critical Data 🕴

How business executives' best intentions may be negatively affecting security and risk mitigation strategies - and exposing weaknesses in organizational defenses.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2013-3936 (opsview, opsview_core)

Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.

📖 Read

via "National Vulnerability Database".
Mozilla Releases Firefox 72: High-Severity Bugs Patched, Fingerpinting Nixed

Mozilla tackles high-severity bugs in its latest Firefox 72 and Firefox ESR 68.4 releases at the same time rolls a major privacy feature .

📖 Read

via "Threatpost".
Liverpool Voyeur Used IM-RAT to Video Women at Home

The case highlights the rising issue of stalkerware, which has reached epidemic proportions.

📖 Read

via "Threatpost".
🕴 In App Development, Does No-Code Mean No Security? 🕴

No-code and low-code development platforms are part of application development, but there are keys to making sure that they don't leave security behind with traditional coding.

📖 Read

via "Dark Reading: ".
🕴 TikTok Bugs Put Users' Videos, Personal Data At Risk 🕴

Researchers found it was possible to spoof SMS messages from TikTok and exploit an API flaw that could grant access to users' personal data.

📖 Read

via "Dark Reading: ".
🔏 Alleged IP Theft Cost Industrial Cleaning Company $15M 🔏

The company alleges a former employee violated company policy and betrayed its trust as he "intentionally decimated" its North American business.

📖 Read

via "Subscriber Blog RSS Feed ".
Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy

Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes available before then.

📖 Read

via "Threatpost".
Man Sentenced in ATM Skimming Conspiracy

A Romanian national has been sentenced to 5 years in prison after racking up almost $400,000 in an ATM skimming scheme.

📖 Read

via "Threatpost".
🕴 Google's Project Zero Policy Change Mandates 90-Day Disclosure 🕴

The updated disclosure policy aims to achieve more thorough and improved patch development, Google reports.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2013-3941 (xnview)

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.

📖 Read

via "National Vulnerability Database".
🔐 CES 2020: How McAfee's Just in Time debugger stops cybercriminals 🔐

How the Advanced Threat Research Team can stop hackers from stealing personal data from a wearable device.

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2013-3945 (mrsid)

The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.

📖 Read

via "National Vulnerability Database".
🕴 Developers Still Don't Properly Handle Sensitive Data 🕴

The top classes of vulnerabilities for 2019 indicate that developers still don't correctly sanitize inputs, nor protect passwords and keys as they should.

📖 Read

via "Dark Reading: ".
Drake Lyrics Used as Calling Card in Malware Attack

A hacker who apparently likes the musician Drake leaves lyrics from the artist's song In My Feelings behind in an attack that delivers malware Lokibot or Azorult.

📖 Read

via "Threatpost".
ATENTION New - CVE-2011-5266

Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-5250

Snare for Linux before 1.7.0 has CSRF in the web interface.

📖 Read

via "National Vulnerability Database".