πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Google tests biometric authentication for Android autofill ⚠

Google is testing out a feature to make Android's built-in password manager safer.

πŸ“– Read

via "Naked Security".
⚠ β€˜Cable Haunt’ vulnerability exposes 200 million cable modem users ⚠

A fortnight in to 2020 and we have the first security flaw to be given its own name: Cable Haunt - complete with eye-catching logo.

πŸ“– Read

via "Naked Security".
❌ Apple Denies FBI Request to Unlock Shooter’s iPhoneβ€”Again ❌

Refusal to unlock the phones of a Florida shooter could set up another legal battle between Apple and the Feds over data privacy in the case of criminal investigations.

πŸ“– Read

via "Threatpost".
πŸ•΄ How to Keep Security on Life Support After Software End-of-Life πŸ•΄

It's the end of support this week for Windows 7 and Server 2008. But what if you truly can't migrate off software, even after security updates stop coming?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Industrial Control System Features at Risk πŸ•΄

How some ICS product functions can be weaponized by altering their configurations.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Processor Vulnerabilites Put Virtual Workloads at Risk πŸ•΄

Meltdown, Spectre exploits will likely lead to customers making tradeoffs between performance and security of applications, especially virtual and cloud-based apps

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-5018 (koala_framework)

Koala Framework before 2011-11-21 has XSS via the request_uri parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Dustman Attack Underscores Iran's Cyber Capabilities πŸ•΄

For nearly six months, an attack group linked to Iran reportedly had access to the network of Bahrain's national oil company, Bapco, before it executed a destructive payload.

πŸ“– Read

via "Dark Reading: ".
❌ Adobe Patches Five Critical Illustrator CC Flaws ❌

Overall Adobe patched nine flaws in Illustrator CC and Experience Manager.

πŸ“– Read

via "Threatpost".
⚠ Fleeceware is back in Google Play – massive fees for not much at all ⚠

The apps itself isn't malicious - the treachery lies in the payment model.

πŸ“– Read

via "Naked Security".
πŸ•΄ Consumer Reports Calls for IoT Manufacturers to Raise Security Standards πŸ•΄

A letter to 25 companies says Consumer Reports will change ratings to reflect stronger security and privacy standards.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Packet Fence 9.3.0 πŸ› 

PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
⚠ Windows 7 computers will no longer be patched after today ⚠

Today's the day. The balloon goes up. The ship goes down. The patches fall behind. The crooks pull ahead.

πŸ“– Read

via "Naked Security".
❌ Public Bug Bounty Takes Aim at Kubernetes Container Project ❌

The cloud-focused program will pay out $10,000 as its top reward.

πŸ“– Read

via "Threatpost".
❌ Google to Nix Chrome Support for Third-Party Cookies by 2022 ❌

Google says it has a two-year timeline for phasing out support for third-party cookies in its Chrome web browser.

πŸ“– Read

via "Threatpost".
πŸ•΄ Global Predictions for Energy Cyber Resilience in 2020 πŸ•΄

How prepared is the energy sector for an escalating attack surface in the operating technology environment? Here are five trends to watch.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Attackers Increasingly Focus on Business Disruption πŸ•΄

Network intruders are staying undetected for an average of 95 days, enabling them to target critical systems and more completely disrupt business.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to protect your Windows 7 computers and data after Microsoft cuts off support πŸ”

With no bug fixes or patches available for Windows 7 after Jan. 14, Veritas CIO John Abel offers tips to safeguard the PCs in your organization.

πŸ“– Read

via "Security on TechRepublic".
πŸ” CISA Continues to Warn About Pulse Secure Attacks πŸ”

CISA, the DHS agency that oversees cybersecurity matters in the US, is urging organizations to patch Pulse Secure VPN servers in the wake of news that they're being used to spread ransomware.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Google: Chrome Will Remove Third-Party Cookies and Tracking πŸ•΄

It's "not about blocking" but removing them altogether, the company said.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 'Fancy Bear' Targets Ukrainian Oil Firm Burisma in Phishing Attack πŸ•΄

The oil & gas company is at the heart of the ongoing US presidential impeachment case.

πŸ“– Read

via "Dark Reading: ".