πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Fake-review purge: Facebook boots 188 groups, eBay bans 140 shills ⚠

After a poke from the UK's watchdog, the companies promised to beef up filters to strain out those who write, buy and sell fluffy nonsense.

πŸ“– Read

via "Naked Security".
⚠ Ransomware pounces on California schools, Las Vegas trounces attack ⚠

We'll have one serving of whatever Las Vegas is eating and wish Pittsburg Unified School District good luck with getting unstuck.

πŸ“– Read

via "Naked Security".
⚠ Hackers use system weakness to rattle doors on Citrix systems ⚠

Attackers are using a serious bug in Citrix products to scan the internet for weaknesses, according to experts.

πŸ“– Read

via "Naked Security".
❌ Oil-and-Gas Specialist APT Pivots to U.S. Power Plants ❌

Researchers say that physically disruptive attacks aren't imminent, but an increased focus on U.S. electrical-grid operators doesn't bode well.

πŸ“– Read

via "Threatpost".
πŸ•΄ Study Points to Lax Focus on Cybersecurity πŸ•΄

Despite ranking at the top of respondents' concerns, organizations still show gaps in acting on cybersecurity, Society for Information Management (SIM) report finds.

πŸ“– Read

via "Dark Reading: ".
πŸ” How cybercriminals are using Microsoft Sway to launch phishing attacks πŸ”

Attackers are creating phishing sites from Sway, an effective approach as links for the domain are typically trusted, says security firm Avanan.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 5 Tips on How to Build a Strong Security Metrics Framework πŸ•΄

The carpentry maxim 'measure twice, cut once' underscores the importance of timely, accurate, and regular metrics to inform security leaders' risk decisions.

πŸ“– Read

via "Dark Reading: ".
πŸ” Friday Five: 1/10 Edition πŸ”

Possible Iranian retaliation may include cyberattacks, laboratory testing company recieves lawsuit after data breach, and another school district hit with ransomware - catch up on the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2011-4595

Pretty-Link WordPress plugin 1.5.2 has XSS

πŸ“– Read

via "National Vulnerability Database".
πŸ” PATSCAN platform detects hidden weapons, chemicals, and bombs πŸ”

At CES 2020, Patriot One Technologies explained its PATSCAN platform, which can detect hidden weapons and more without the perpetrator even knowing they've been scanned.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Indian National Pleads Guilty to Multimillion-Dollar Call Center Scam πŸ•΄

The India-based call centers scammed US victims out of millions of dollars between 2013 and 2016.

πŸ“– Read

via "Dark Reading: ".
⚠ Is the Y2K bug alive after all? ⚠

One way to patch the millennium bug was to move it, rather than actually to fix it... are we looking at Y2.02K?

πŸ“– Read

via "Naked Security".
❌ Lifeline Assistance Phone Users Targeted with β€˜Uninstallable’ Adware ❌

A Virgin Mobile-branded phone distributed by Assurance Wireless to low-income U.S. citizens has a trojan pre-installed that can download additional malware.

πŸ“– Read

via "Threatpost".
❌ Cisco Webex Bug Allows Remote Code Execution ❌

Cisco patched two high-severity flaws this week, in its Webex and IOS XE Software products.

πŸ“– Read

via "Threatpost".
πŸ•΄ 6 Unique InfoSec Metrics CISOs Should Track in 2020 πŸ•΄

You might not find these measurements on a standard cybersecurity department checklist. But they can help evaluate risks you haven't even considered yet.

πŸ“– Read

via "Dark Reading: ".
πŸ” TP-Link routers get a little safer with AI-powered security features πŸ”

The new features come from a partnership with security firm Avira, but they won't be free: They're part of a new package called HomeCare Pro.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How AI, ML, and automation can improve cybersecurity protection πŸ”

Read insights from industry experts on how artificial intelligence and machine learning will help prevent cybersecurity breaches.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2012-3824

In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-3823

Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-3822

Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Major Brazilian Bank Tests Homomorphic Encryption on Financial Data πŸ•΄

The approach allowed researchers to use machine learning on encrypted data without first decrypting it.

πŸ“– Read

via "Dark Reading: ".