πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Sonos’s tone-deaf legacy product policy angers customers ⚠

Stopping software updates for legacy kit is nothing new, but it's the way the company has done it that has Sonos customers' hackles up.

πŸ“– Read

via "Naked Security".
⚠ Apple allegedly made nice with FBI by dropping iCloud encryption plan ⚠

Sources told Reuters that Apple may have been convinced by arguments made during the legal fight over cracking the San Bernardino iPhone.

πŸ“– Read

via "Naked Security".
⚠ UN report alleges that Saudi crown prince hacked Jeff Bezos’s phone ⚠

Digital forensic evidence points to the phone's massive, months-long data egress having likely been triggered by Pegasus mobile spyware.

πŸ“– Read

via "Naked Security".
❌ Google: Flaws in Apple’s Private-Browsing Technology Allow for Third-Party Tracking ❌

New research outlines vulnerabilities in Safari’s Intelligent Tracking Protection that can reveal user browsing behavior to third parties.

πŸ“– Read

via "Threatpost".
⚠ Looking for silver linings in the CVE-2020-0601 crypto vulnerability ⚠

Is there some good news hidden in the story of the CVE-2020-0601 crypto vulnerability?

πŸ“– Read

via "Naked Security".
πŸ•΄ Weathering the Privacy Storm from GDPR to CCPA & PDPA πŸ•΄

A general approach to privacy, no matter the regulation, is the only way companies can avoid a data protection disaster in 2020 and beyond.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Ryuk Ransomware Hit Multiple Oil & Gas Facilities, ICS Security Expert Says πŸ•΄

Attackers 'weaponized' Active Directory to spread the ransomware.

πŸ“– Read

via "Dark Reading: ".
❌ Cisco Warns of Critical Network Security Tool Flaw ❌

The critical flaw exists in Cisco's administrative management tool, used with network security solutions like firewalls.

πŸ“– Read

via "Threatpost".
πŸ” Why many small and midsized businesses remain vulnerable to cyberattack πŸ”

Budget limitations and a lack of knowledge or training are two major factors hurting many SMBs, according to a survey from Untangle.

πŸ“– Read

via "Security on TechRepublic".
πŸ›  Falco 0.19.0 πŸ› 

Sysdig falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
ATENTIONβ€Ό New - CVE-2010-3295

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2008-7314

mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2007-6758

Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Severe Vulnerabilities Discovered in GE Medical Devices πŸ•΄

CISA has released an advisory for six high-severity CVEs for GE Carescape patient monitors, Apex Pro, and Clinical Information Center systems.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Deconstructing Web Cache Deception Attacks: They're Bad; Now What? πŸ•΄

Expect cache attacks to get worse before they get better. The problem is that we don't yet have a good solution.

πŸ“– Read

via "Dark Reading: ".
❌ Shlayer, No. 1 Threat for Mac, Targets YouTube, Wikipedia ❌

The malware uses thousands of partner websites to spread malvertising code.

πŸ“– Read

via "Threatpost".
❌ U.S. Gov Agency Targeted With Malware-Laced Emails ❌

The malicious email campaign included a never-before-seen malware downloader called Carrotball, and may be linked to the Konni Group APT.

πŸ“– Read

via "Threatpost".
πŸ” CISA Warns of Uptick in Emotet Malware πŸ”

CISA is spreading new guidance to ensure admins can properly defend against Emotet malware attacks, which the agency claims are on the rise.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Critical, Unpatched β€˜MDhex’ Bugs Threaten Hospital Devices ❌

The Feds have warned on six vulnerabilities in GE medical equipment that could affect patient monitor alarms and more.

πŸ“– Read

via "Threatpost".
πŸ•΄ NSA Offers Guidance on Mitigating Cloud Flaws πŸ•΄

A new document separates cloud vulnerabilities into four classes and offers mitigations to help businesses protect cloud resources.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ DHS Warns of Increasing Emotet Risk πŸ•΄

Emotet is considered one of the most damaging banking Trojans, primarily through its ability to carry other malware into an organization.

πŸ“– Read

via "Dark Reading: ".