🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
Twitter API Abused to Uncover User Identities

State-sponsored actors may have been behind the social media abuse, said Twitter.

📖 Read

via "Threatpost".
🕴 What WON'T Happen in Cybersecurity in 2020 🕴

Predictions are a dime a dozen. Here are six trends that you won't be hearing about anytime soon.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2012-5686

ZPanel 10.0.1 has insufficient entropy for its password reset process.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2012-5618

Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-4937

Joomla! 1.7.1 has core information disclosure due to inadequate error checking.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-4912

Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-3629

Joomla! core 1.7.1 allows information disclosure due to weak encryption

📖 Read

via "National Vulnerability Database".
🕴 Kubernetes Shows Built-in Weakness 🕴

A Shmoocon presentation points out several weaknesses built in to Kubernetes configurations and how a researcher can exploit them.

📖 Read

via "Dark Reading: ".
🕴 Twitter Suspends Fake Accounts Abusing Feature that Matches Phone Numbers and Users 🕴

The company believes state-sponsored actors may also be involved.

📖 Read

via "Dark Reading: ".
🕴 7 Ways SMBs Can Secure Their Websites 🕴

Here's what small and midsize businesses should consider when they decide it's time to up their website security.

📖 Read

via "Dark Reading: ".
Medtronic Patches Implanted Device, CareLink Programmer Bugs

The medical device giant has issued fixes for bugs first disclosed in 2018 and 2019.

📖 Read

via "Threatpost".
Two Critical Android Bugs Get Patched in February Update

As part of its February bug fixes, Google is patching a critical severity remote code execution vulnerability and an information disclosure bug.

📖 Read

via "Threatpost".
🕴 Ransomware Attacks: Why It Should Be Illegal to Pay the Ransom 🕴

For cities, states and towns, paying up is short-sighted and only makes the problem worse.

📖 Read

via "Dark Reading: ".
🔏 HHS Issues Coronavirus HIPAA Guidance 🔏

In the healthcare sector, concerns about the spreading coronavirus outbreak have reignited the discussion around HIPAA, protected health information, and when it's legal for healthcare providers to disclose patient records.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 Why many security pros lack confidence in their implementation of Zero Trust 🔐

Almost half of security professionals don't know where or how to use Zero Trust policies in a hybrid IT environment, says a survey commissioned by security provider Pulse Secure.

📖 Read

via "Security on TechRepublic".
🔐 How to sign up for Firefox breach alerts 🔐

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. Find out how to use Firefox Monitor.

📖 Read

via "Security on TechRepublic".
🔐 How to sign up for Firefox breach alerts 🔐

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. Find out how to use Firefox Monitor.

📖 Read

via "Security on TechRepublic".
🔐 Untested app and no training for volunteers are fatal in Iowa caucus 🔐

HR experts and tech leaders say organizations that skip training during a tech transition almost always pay a high price.

📖 Read

via "Security on TechRepublic".
Ransomware Attack Hinders Toll Group Operations

Customers took to Twitter to air their grievances after some of the transportation giant's operations were downed.

📖 Read

via "Threatpost".
🕴 Microsoft DART Finds Web Shell Threat on the Rise 🕴

Various APT groups are successfully using Web shell attacks on a more frequent basis.

📖 Read

via "Dark Reading: ".
Community Housing Nonprofit Hit with $1.2M Loss in BEC Scam

Red Kite said that domain-spoofing and convincing scam emails claiming to be from suppliers were the cause.

📖 Read

via "Threatpost".