πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ In App Development, Does No-Code Mean No Security? πŸ•΄

No-code and low-code development platforms are part of application development, but there are keys to making sure that they don't leave security behind with traditional coding.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ TikTok Bugs Put Users' Videos, Personal Data At Risk πŸ•΄

Researchers found it was possible to spoof SMS messages from TikTok and exploit an API flaw that could grant access to users' personal data.

πŸ“– Read

via "Dark Reading: ".
πŸ” Alleged IP Theft Cost Industrial Cleaning Company $15M πŸ”

The company alleges a former employee violated company policy and betrayed its trust as he "intentionally decimated" its North American business.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy ❌

Project Zero vulnerability disclosures will now happen at 90 days, even if a patch becomes available before then.

πŸ“– Read

via "Threatpost".
❌ Man Sentenced in ATM Skimming Conspiracy ❌

A Romanian national has been sentenced to 5 years in prison after racking up almost $400,000 in an ATM skimming scheme.

πŸ“– Read

via "Threatpost".
πŸ•΄ Google's Project Zero Policy Change Mandates 90-Day Disclosure πŸ•΄

The updated disclosure policy aims to achieve more thorough and improved patch development, Google reports.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-3941 (xnview)

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
πŸ” CES 2020: How McAfee's Just in Time debugger stops cybercriminals πŸ”

How the Advanced Threat Research Team can stop hackers from stealing personal data from a wearable device.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2013-3945 (mrsid)

The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Developers Still Don't Properly Handle Sensitive Data πŸ•΄

The top classes of vulnerabilities for 2019 indicate that developers still don't correctly sanitize inputs, nor protect passwords and keys as they should.

πŸ“– Read

via "Dark Reading: ".
❌ Drake Lyrics Used as Calling Card in Malware Attack ❌

A hacker who apparently likes the musician Drake leaves lyrics from the artist's song In My Feelings behind in an attack that delivers malware Lokibot or Azorult.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2011-5266

Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-5250

Snare for Linux before 1.7.0 has CSRF in the web interface.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-5247

Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-5018

Koala Framework before 2011-11-21 has XSS via the request_uri parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 15% of Ransomware Victims Paid Ransom in 2019, Quadrupling 2018 πŸ•΄

Increasing sophistication of ransomware attacks might be forcing victims to open their wallets.

πŸ“– Read

via "Dark Reading: ".
πŸ” Developers weigh in on why Rust is so hot πŸ”

Commentary: Rust keeps getting hotter. Here are a few of the top reasons.

πŸ“– Read

via "Security on TechRepublic".
⚠ Google’s Project Zero highlights patch quality with policy tweak ⚠

Google's Project Zero bug-hunting team has tweaked its 90-day responsible disclosure policy to help improve the quality and adoption of vendor patches.

πŸ“– Read

via "Naked Security".
❌ TrickBot Adds Custom, Stealthy Backdoor to its Arsenal ❌

The PowerTrick backdoor, which fetched yet other backdoors, is designed to help TrickBot evade detection.

πŸ“– Read

via "Threatpost".