🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Keeping Compliance Data-Centric Amid Accelerating Regulation 🕴

As the regulatory landscape transforms, it's still smart to stay strategically focused on protecting your data.

📖 Read

via "Dark Reading: ".
🛠 ISO-8385 Protocol Fuzzer 🛠

This python script is a fuzzer for the ISO-8385 financial protocol. It is compatible with sulley and bofuzz and is now part of the official bofuzz release.

📖 Go!

via "Security Tool Files ≈ Packet Storm".
🛠 nfstream 3.1.2 🛠

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

📖 Go!

via "Security Tool Files ≈ Packet Storm".
🛠 Clam AntiVirus Toolkit 0.102.2 🛠

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software.

📖 Go!

via "Security Tool Files ≈ Packet Storm".
🔏 SEC Issues Cybersecurity and Resiliency Best Practices 🔏

Data loss prevention is one of eight key practices outlined by the SEC last week to enhance cybersecurity preparedness and operational resiliency.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 Tips on keeping a Google Photos-type video bug from impacting cloud-based files 🔐

The private videos of some Google Photos users were accidentally shared with other people. Here's how to secure online files to protect them from exposure.

📖 Read

via "Security on TechRepublic".
CamuBot Banking Trojan Returns In Targeted Attacks

The malware is back in targeted attacks against Brazilian banking customers, this time using a new technique that involves mobile app authorization.

📖 Read

via "Threatpost".
🕴 What is a Privileged Access Workstation (PAW)? 🕴

Ask the Experts -- about a technological game of keep-away that protects the most precious resources from the greatest dangers.

📖 Read

via "Dark Reading: ".
🕴 Emotet Preps for Tax Season with New Phishing Campaign 🕴

Malicious emails in a new attack campaign contain links and attachments claiming to lead victims to W-9 forms.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2011-0220

Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2010-5304

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2010-4815

Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2010-4662

PmWiki before 2.2.21 has XSS.

📖 Read

via "National Vulnerability Database".
🕴 IoT Malware Campaign Infects Global Manufacturing Sites 🕴

The infection uses Lemon_Duck PowerShell malware variant to exploit vulnerabilities in embedded devices at manufacturing sites.

📖 Read

via "Dark Reading: ".
🕴 Department of Energy Adds Attivo Decoys for Critical Infrastructure Security 🕴

The decoys and lures will help redirect attacks away from devices that can't be protected through traditional means.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2011-1151

Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-1150

bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-1069

PHPShop through 0.8.1 has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-1009

Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-0525

Batavi before 1.0 has CSRF.

📖 Read

via "National Vulnerability Database".
🕴 Majority of Network, App-Layer DDoS Attacks in 2019 Were Small 🕴

Attacks turned to cheaper, shorter attacks to try and disrupt targets, Imperva analysis shows.

📖 Read

via "Dark Reading: ".