πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Data about inmates and jail staff spilled by leaky prison app ⚠

A web-mapping project came across detainees' prescriptions and other PII that could be used by identity thieves to victimize prisoners.

πŸ“– Read

via "Naked Security".
πŸ” Cloud computing security: These two Microsoft tools can help you battle shadow IT πŸ”

Finding what cloud services employees are using is only half the battle: integrating Microsoft Cloud App Security and Defender Advanced Threat Protection means you can track, block or audit cloud app usage.

πŸ“– Read

via "Security on TechRepublic".
⚠ US charges four Chinese military members with Equifax hack ⚠

The indictment suggests the hack was part of a series of major data thefts organized by Chinese military and intelligence agencies.

πŸ“– Read

via "Naked Security".
❌ FBI: $3.5B Lost in 2019 to Known Cyberscams, Ransomware ❌

Cybercriminals double down on successful internet scams, with a focus on phishing, BEC and other defrauding schemes that have proven to work.

πŸ“– Read

via "Threatpost".
❌ Katie Moussouris: The Bug Bounty Conflict of Interest ❌

Kate Moussouris sounds off on the challenges behind creating successful bug bounty programs.

πŸ“– Read

via "Threatpost".
πŸ•΄ 5 Common Errors That Allow Attackers to Go Undetected πŸ•΄

Make these mistakes and invaders might linger in your systems for years.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Chaos May Be the Key to Quantum-Proof Encryption πŸ•΄

The implications of chaos form the basis of a new approach to encryption that promises quantum-proof perfect secrecy.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2012-0810

The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5140

The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5139

The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

πŸ“– Read

via "National Vulnerability Database".
⚠ Mozilla issues final warning to websites using TLS 1.0 ⚠

From March, the Firefox, Chrome, Safari and Edge browsers will show warnings when users visit websites that only support TLS versions 1.0 or 1.1.

πŸ“– Read

via "Naked Security".
πŸ•΄ Chaos & Order: The Keys to Quantum-Proof Encryption πŸ•΄

The implications of chaos form the basis of a new approach to encryption that promises quantum-proof perfect secrecy. But first, your current crypto needs some tidying up.

πŸ“– Read

via "Dark Reading: ".
πŸ” Data breaches up 17% in 2019 over previous year πŸ”

The Identity Theft Recource Center warns that businesses of all sizes should be vigilant about data security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ What Are Some Basic Ways to Protect My Global Supply Chain? πŸ•΄

Assessing supply chains is one of the more challenging third-party risk management endeavors organizations can take on.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 5G Adoption Should Change How Organizations Approach Security πŸ•΄

With 5G adoption, businesses will be able to power more IoT devices and perform tasks more quickly, but there will be security ramifications.

πŸ“– Read

via "Dark Reading: ".
❌ SoundCloud Tackles DoS, Account Takeover Issues ❌

Among other issues, the music platform didn't limit the number of login attempts someone could make.

πŸ“– Read

via "Threatpost".
πŸ›  NTCrackPipe 2.0 πŸ› 

NTCrackPipe is a basic local Windows account cracking tool.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Stop Defending Everything πŸ•΄

Instead, try prioritizing with the aid of a thorough asset inventory.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2012-0951

A Memory Corruption Vulnerability exists in NVIDIA Graphics Drivers 29549 due to an unknown function in the file proc/driver/nvidia/registry.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-4661

A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (aka CSCtu52820), when configured with Cisco ISR Web Security with Cisco ScanSafe and User Authenticaiton NTLM configured.

πŸ“– Read

via "National Vulnerability Database".
❌ Mozilla Firefox 73 Browser Update Fixes High-Severity RCE Bugs ❌

The release of Firefox 73 fixed high-severity memory safety bugs that could cause arbitrary code execution and missing bounds check that could enable memory corruption.

πŸ“– Read

via "Threatpost".