πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2011-5018

Koala Framework before 2011-11-21 has XSS via the request_uri parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 15% of Ransomware Victims Paid Ransom in 2019, Quadrupling 2018 πŸ•΄

Increasing sophistication of ransomware attacks might be forcing victims to open their wallets.

πŸ“– Read

via "Dark Reading: ".
πŸ” Developers weigh in on why Rust is so hot πŸ”

Commentary: Rust keeps getting hotter. Here are a few of the top reasons.

πŸ“– Read

via "Security on TechRepublic".
⚠ Google’s Project Zero highlights patch quality with policy tweak ⚠

Google's Project Zero bug-hunting team has tweaked its 90-day responsible disclosure policy to help improve the quality and adoption of vendor patches.

πŸ“– Read

via "Naked Security".
❌ TrickBot Adds Custom, Stealthy Backdoor to its Arsenal ❌

The PowerTrick backdoor, which fetched yet other backdoors, is designed to help TrickBot evade detection.

πŸ“– Read

via "Threatpost".
⚠ FBI asks Apple to help it unlock iPhones of naval base shooter ⚠

This could signal a renewed war between Apple and law enforcement over breaking encryption.

πŸ“– Read

via "Naked Security".
⚠ Google voice Assistant gets new privacy β€˜undo’ commands ⚠

Google’s controversial voice Assistant is getting a series of new commands designed to work like privacy-centric β€˜undo’ buttons.

πŸ“– Read

via "Naked Security".
⚠ Apple’s scanning iCloud photos for child abuse images ⚠

It isn't new, all the tech giants do it, and your privacy's intact - unless you're dealing in illegal imagery with telltale hashing.

πŸ“– Read

via "Naked Security".
⚠ S2 Ep22: Word doc stops fraud, bye bye Python 2, latest from the ransomware swamp – Naked Security Podcast ⚠

We discuss the latest cybersecurity news and advice in our latest podcast. Listen now!

πŸ“– Read

via "Naked Security".
⚠ Browser zero day: Update your Firefox right now! ⚠

Firefox has issues an emergency 72.0.1 patch to fix a zero day vulnerability.

πŸ“– Read

via "Naked Security".
πŸ” CES 2020: How McAfee's Just in Time debugger stops cybercriminals πŸ”

How the Advanced Threat Research Team can stop hackers from stealing personal data from a wearable device.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Rockwell Automation to Buy ICS Security Services Firm πŸ•΄

Industrial control systems vendor plans to acquire Avnet Data Security, which provides penetration testing, assessments, training, and managed network and security services for the ICS sector.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 7 Free Tools for Better Visibility Into Your Network πŸ•΄

It's hard to protect what you don't know is there. These free tools can help you understand just what it is that you need to protect -- and need to protect yourself from.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Operationalizing Threat Intelligence at Scale in the SOC πŸ•΄

Open source platforms such as the Malware Information Sharing Platform are well positioned to drive a community-based approach to intelligence sharing.

πŸ“– Read

via "Dark Reading: ".
❌ California’s Tough New Privacy Law and Its Biggest Challenges ❌

The California Consumer Privacy Act has been adopted, but the largest U.S. privacy regulation fails to address how companies can know where their data is.

πŸ“– Read

via "Threatpost".
πŸ” How to access your 2FA Docker Hub account from the command line πŸ”

With 2FA enabled on your Docker Hub account, you'll find you cannot access it with your user password from within the CLI. Jack Wallen shows you how to make this work.

πŸ“– Read

via "Security on TechRepublic".
❌ 4 Ring Employees Fired For Spying on Customers ❌

Ring said that four employees were fired because they for inappropriate access to customers' connected video feeds.

πŸ“– Read

via "Threatpost".
πŸ•΄ AWS Issues 'Urgent' Warning for Database Users to Update Certs πŸ•΄

Users of AWS Aurora, DocumentDB, and RDS databases must download and install a fresh certificate and rotate the certificate authority.

πŸ“– Read

via "Dark Reading: ".
πŸ” EDPS Issues Opinion on Data Protection and Scientific Research πŸ”

The European Data Protection Supervisor has issued a preliminary opinion on how data protection obligations should factor into scientific research in the EU.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Exploit Fully Breaks SHA-1, Lowers the Attack Bar ❌

Users of GnuPG, OpenSSL and Git could be in danger from an attack that's practical for ordinary attackers to carry out.

πŸ“– Read

via "Threatpost".