πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Poll: A Matter of Trust πŸ•΄

Has working in the cybersecurity industry affected your ability to trust? Take the poll now.

πŸ“– Read

via "Dark Reading: ".
πŸ” Hackers imitating CDC, WHO with coronavirus phishing emails πŸ”

Cybercriminals are now using fears over the outbreak to steal email credentials, security officials say.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ RobbinHood Kills Security Processes Before Dropping Ransomware πŸ•΄

Attackers deploy a legitimate, digitally signed hardware driver to delete security software from machines before encrypting files.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to use 7zip to encrypt files πŸ”

If you need strong command line encryption on Linux, look no further than 7zip.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ CCPA and GDPR: The Data Center Pitfalls of the 'Right to be Forgotten' πŸ•΄

Compliance with the new privacy rules doesn't always fall on data center managers, but when it does, it's more difficult than it may sound.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Android Bluetooth Bug Enables RCE, No User Interaction Needed ❌

The flaw was recently patched in Android's February Security Bulletin.

πŸ“– Read

via "Threatpost".
πŸ•΄ Google Takeout Serves Up Video Files to Strangers πŸ•΄

A limited number of user videos were shared with others in a five-day incident from November.

πŸ“– Read

via "Dark Reading: ".
❌ Wacom Tablet Data Exfiltration Raises Security Concerns ❌

Wacom stated that its data collection is done only in aggregate -- but that doesn't fix the issues, according to security experts.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2011-1086

Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-1085

CSRF vulnerability in Smoothwall Express 3.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-1084

A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.

πŸ“– Read

via "National Vulnerability Database".
πŸ” The most overhyped, and most significant, tech trends of 2020 πŸ”

A survey of IT professionals finds AR and 5G bust for 2020, machine learning and DevOps on top.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to protect your privacy on an iOS device πŸ”

Learn how to keep your iOS devices--and your data--secure with these iOS 13 privacy settings and Apple resources.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2011-3642

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4381

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4029

Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 23 stories of the week ⚠

From Google's OpenSK project to Apple's SMS 2FA proposal, and everything in between. Get up to date with the hot stories of the last week.

πŸ“– Read

via "Naked Security".
⚠ Frustrated author cybersquats novelist’s website ⚠

If you visit the website of renowned Canadian novelist Patrick deWitt today, you'll see a surprising message. "THIS IS NOT PATRICK DEWITT", it says.

πŸ“– Read

via "Naked Security".
⚠ FBI director warns of sustained Russian disinformation threat ⚠

Russia is still using social media in a sustained campaign to dabble in US affairs, according to FBI director Chris Wray.

πŸ“– Read

via "Naked Security".
⚠ Facebook encrypted messaging will β€˜create hiding places for child abuse’ ⚠

Child safety groups penned an open letter to Facebook, urging a delay on encrypted messaging until sufficient safeguards are in place.

πŸ“– Read

via "Naked Security".
⚠ Google Chrome to start blocking downloads served via HTTP ⚠

Google has announced a timetable for phasing out insecure file downloads in the Chrome browser starting with desktop version 81 due next month.

πŸ“– Read

via "Naked Security".