πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ PayPal SMS scams – don’t fall for them! ⚠

Text messages may be old hat - but SMS is still a handy tool for crooks out to find more about you.

πŸ“– Read

via "Naked Security".
⚠ Coronavirus β€œsafety measures” email is a phishing scam ⚠

Sadly, cybercrooks love a crisis, because it gives them a believable reason to contact you with a phishing scam. Take care out there!

πŸ“– Read

via "Naked Security".
❌ New Lemon Duck Malware Campaign Targets IoT, Large Manufacturers ❌

Malware campaign targets global manufacturers that are still dependent on Windows 7 subsystems to run fleets of IoT endpoints.

πŸ“– Read

via "Threatpost".
πŸ•΄ Keeping Compliance Data-Centric Amid Accelerating Regulation πŸ•΄

As the regulatory landscape transforms, it's still smart to stay strategically focused on protecting your data.

πŸ“– Read

via "Dark Reading: ".
πŸ›  ISO-8385 Protocol Fuzzer πŸ› 

This python script is a fuzzer for the ISO-8385 financial protocol. It is compatible with sulley and bofuzz and is now part of the official bofuzz release.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  nfstream 3.1.2 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  Clam AntiVirus Toolkit 0.102.2 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ” SEC Issues Cybersecurity and Resiliency Best Practices πŸ”

Data loss prevention is one of eight key practices outlined by the SEC last week to enhance cybersecurity preparedness and operational resiliency.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Tips on keeping a Google Photos-type video bug from impacting cloud-based files πŸ”

The private videos of some Google Photos users were accidentally shared with other people. Here's how to secure online files to protect them from exposure.

πŸ“– Read

via "Security on TechRepublic".
❌ CamuBot Banking Trojan Returns In Targeted Attacks ❌

The malware is back in targeted attacks against Brazilian banking customers, this time using a new technique that involves mobile app authorization.

πŸ“– Read

via "Threatpost".
πŸ•΄ What is a Privileged Access Workstation (PAW)? πŸ•΄

Ask the Experts -- about a technological game of keep-away that protects the most precious resources from the greatest dangers.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Emotet Preps for Tax Season with New Phishing Campaign πŸ•΄

Malicious emails in a new attack campaign contain links and attachments claiming to lead victims to W-9 forms.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-0220

Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5304

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-4815

Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-4662

PmWiki before 2.2.21 has XSS.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ IoT Malware Campaign Infects Global Manufacturing Sites πŸ•΄

The infection uses Lemon_Duck PowerShell malware variant to exploit vulnerabilities in embedded devices at manufacturing sites.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Department of Energy Adds Attivo Decoys for Critical Infrastructure Security πŸ•΄

The decoys and lures will help redirect attacks away from devices that can't be protected through traditional means.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-1151

Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-1150

bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-1069

PHPShop through 0.8.1 has XSS.

πŸ“– Read

via "National Vulnerability Database".