πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 5 Measures to Harden Election Technology πŸ•΄

Voting machinery needs hardware-level security. The stakes are the ultimate, and the attackers among the world's most capable.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2012-1567

LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintUpdate.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1566

LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Citrix RCE Flaw Still Threatens 1,000s of Corporate LANs ❌

RCE and myriad other types of attacks could take aim at the 19 percent of vulnerable companies that haven't yet patched CVE-2019-19781.

πŸ“– Read

via "Threatpost".
πŸ›  UFONet 1.4 πŸ› 

UFONet abuses OSI Layer 7-HTTP to create/manage 'zombies' and to conduct different attacks using GET/POST, multithreading, proxies, origin spoofing methods, cache evasion techniques, etc.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ” How Shadow IT could put your organization at risk πŸ”

Employees who create external accounts but use them internally pose a risk to your security, says password manager company 1Password.

πŸ“– Read

via "Security on TechRepublic".
⚠ Robbin Hood – the ransomware that brings its own bug ⚠

When you need a vulnerability to exploit, but there isn't one... why not simply bring your own, along with your malware?

πŸ“– Read

via "Naked Security".
❌ Google Chrome To Bar HTTP File Downloads ❌

File downloads like images or executables may not be delivered over HTTPS - even if they are available from an HTTPS website.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2010-4658

statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2008-3793

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3792. Reason: This candidate is a duplicate of CVE-2008-3792. Notes: All CVE users should reference CVE-2008-3792 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ From 1s & 0s to Wobbly Lines: The Radio Frequency (RF) Security Starter Guide πŸ•΄

Although radio frequency energy (RF) communications are increasingly essential to modern wireless networking and IoT, the security of RF is notoriously lax.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Poll: A Matter of Trust πŸ•΄

Has working in the cybersecurity industry affected your ability to trust? Take the poll now.

πŸ“– Read

via "Dark Reading: ".
πŸ” Hackers imitating CDC, WHO with coronavirus phishing emails πŸ”

Cybercriminals are now using fears over the outbreak to steal email credentials, security officials say.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ RobbinHood Kills Security Processes Before Dropping Ransomware πŸ•΄

Attackers deploy a legitimate, digitally signed hardware driver to delete security software from machines before encrypting files.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to use 7zip to encrypt files πŸ”

If you need strong command line encryption on Linux, look no further than 7zip.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ CCPA and GDPR: The Data Center Pitfalls of the 'Right to be Forgotten' πŸ•΄

Compliance with the new privacy rules doesn't always fall on data center managers, but when it does, it's more difficult than it may sound.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Android Bluetooth Bug Enables RCE, No User Interaction Needed ❌

The flaw was recently patched in Android's February Security Bulletin.

πŸ“– Read

via "Threatpost".
πŸ•΄ Google Takeout Serves Up Video Files to Strangers πŸ•΄

A limited number of user videos were shared with others in a five-day incident from November.

πŸ“– Read

via "Dark Reading: ".
❌ Wacom Tablet Data Exfiltration Raises Security Concerns ❌

Wacom stated that its data collection is done only in aggregate -- but that doesn't fix the issues, according to security experts.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2011-1086

Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-1085

CSRF vulnerability in Smoothwall Express 3.

πŸ“– Read

via "National Vulnerability Database".