πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Mozilla Firefox 73 Browser Update Fixes High-Severity RCE Bugs ❌

The release of Firefox 73 fixed high-severity memory safety bugs that could cause arbitrary code execution and missing bounds check that could enable memory corruption.

πŸ“– Read

via "Threatpost".
πŸ” U.S. Counterintelligence Center Pledges to Focus on Supply Chains, Democracy πŸ”

The National Counterintelligence and Security Center said this week it plans to double down on securing critical infrastructure, supply chain, the economy, democratic institutions, and cyber/technical operations.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2011-4338

Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-3901

Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-3336

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2499

Mambo CMS through 4.6.5 has multiple XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2343

The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ FBI: Business Email Compromise Cost Businesses $1.7B in 2019 πŸ•΄

BEC attacks comprised nearly half of cybercrime losses last year, which totaled $3.5 billion overall as Internet-enabled crimes ramped up.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Avast Under Investigation by Czech Privacy Agency πŸ•΄

The software security maker is suspected of selling data about more than 100 million users to companies including Google, Microsoft, and Home Depot.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-4908

TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-4906

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Third-Party Breaches - and the Number of Records Exposed - Increased Sharply in 2019 πŸ•΄

Each breach exposed an average of 13 million records, Risk Based Security found.

πŸ“– Read

via "Dark Reading: ".
⚠ Google to force Nest users to turn on 2FA ⚠

Nest users who aren't using 2FA or a Google account will be required to take an extra step by verifying their identity via email.

πŸ“– Read

via "Naked Security".
❌ Google: Efforts Against Bad Android Apps on Play Store Are Working ❌

The tech giant acknowledged some achievements in efforts to bolster mobile app security but recognized more needs to be done.

πŸ“– Read

via "Threatpost".
⚠ FBI: Cybercrime tore a $3.5b hole in victims’ pockets last year ⚠

The FBI's Internet Crime Report shows that business email comprise is the biggest money-maker for cybercriminals.

πŸ“– Read

via "Naked Security".
⚠ IE zero day and heap of RDP flaws fixed in February Patch Tuesday ⚠

Microsoft has finally patched the Internet Explorer (IE) zero-day flaw the company said in January was being used in β€œlimited targeted attacks”.

πŸ“– Read

via "Naked Security".
⚠ Dell fixes privilege elevation bug in support software ⚠

Users of Dell SupportAssist should patch their software immediately to fix a software bug that could lead to arbitrary code execution.

πŸ“– Read

via "Naked Security".
⚠ Firefox six-weekly security fixes are out – get them now! ⚠

No zero-day bugs, so by updating promptly you are keeping ahead of the crooks, not merely catching up!

πŸ“– Read

via "Naked Security".
πŸ” Why password management is critical to mitigating data breaches πŸ”

The Identity Theft Resource Center warns that businesses of all sizes should be vigilant about data security. The COO offers advice about passwords, cloud security, and patch management.

πŸ“– Read

via "Security on TechRepublic".
❌ Puerto Rico Gov Hit By $2.6M Phishing Scam ❌

A recent phishing scam targeted Puerto Rico’s Industrial Development Company.

πŸ“– Read

via "Threatpost".
⚠ S2 Ep26: Robbin Hood ransomware, Twitter parodies and SMS 2FA WHAT? – Naked Security Podcast ⚠

Listen now!

πŸ“– Read

via "Naked Security".