πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Dell Sells RSA to Private Equity Firm for $2.1B πŸ•΄

Deal with private equity entity Symphony Technology Group revealed one week before the security industry's RSA Conference in San Francisco.

πŸ“– Read

via "Dark Reading: ".
❌ FC Barcelona Suffers Likely Credential-Stuffing Attack on Twitter ❌

OurMine took over the Spanish powerhouse soccer team's Twitter account.

πŸ“– Read

via "Threatpost".
πŸ•΄ The Trouble with Free and Open Source Software πŸ•΄

Insecure developer accounts, legacy software, and nonstandard naming schemes are major problems, Linux Foundation and Harvard study concludes.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-0749

A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2054

A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker must have the correct primary credentials in order to successfully exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
⚠ OpenSSH eases admin hassles with FIDO U2F token support ⚠

OpenSSH version 8.2 is out and the big news is that the world’s most popular remote management software now supports authentication using any FIDO (Fast Identity Online) U2F hardware token.

πŸ“– Read

via "Naked Security".
⚠ WordPress plugin hole could have allowed attackers to wipe websites ⚠

A WordPress plugin with over 100,000 active installations had a bug that could have allowed unauthorised attackers to wipe its users' blogs clean, it emerged this week.

πŸ“– Read

via "Naked Security".
⚠ Facebook asks to be regulated kinda like a newspaper, kinda like telco ⚠

Zuckerberg is in Brussels right in time for the European Commission's release of its manifesto on regulating AI.

πŸ“– Read

via "Naked Security".
⚠ Private photos leaked by PhotoSquared’s unsecured cloud storage ⚠

With no password required and no encryption in place, a burglar or ID thief could have seen your photos, your address and more.

πŸ“– Read

via "Naked Security".
❌ Latest Tax Scams Target Apps and Tax-Prep Websites ❌

Traditional e-mail based scams are also in the mix this year, one in particular that uses the legitimate app TeamViewer to take over victims’ systems.

πŸ“– Read

via "Threatpost".
πŸ” How to manage security and privacy in the new Microsoft Edge browser πŸ”

There's a new version of Microsoft Edge in town based on Chromium. Here's how to manage the browser's security and privacy settings.

πŸ“– Read

via "Security on TechRepublic".
❌ Cynet Offers Free Threat Assessment for Mid-Sized and Large Organizations ❌

Cynet Free Threat Assessment spotlights critical, exposed attack surfaces and provides actionable knowledge of attacks that are currently alive and active.

πŸ“– Read

via "Threatpost".
πŸ•΄ Don't Let Iowa Bring Our Elections Back to the Stone Age πŸ•΄

The voting experience should be the same whether the vote is in person, by mail, or over the Internet. Let's not allow one bad incident stop us from finding new ways to achieve this.

πŸ“– Read

via "Dark Reading: ".
πŸ” Coronavirus domain names are the latest hacker trick πŸ”

One site registered in Russia offers a coronavirus cure for $300.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Cybercriminals get creative with tax scams ahead of April 15 πŸ”

Hackers are going after everyone this tax season, including the companies handling our most sensitive information.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Insider data breach survey finds directors most likely to break company policy πŸ”

Report suggests IT leaders think breaches are inevitable and don't have adequate risk management in place.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2014-3622

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-2727

The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-2228

The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

πŸ“– Read

via "National Vulnerability Database".
❌ Hamas Ensnares Israeli Soldiers with Pretty β€˜Ladies’ ❌

The third catfish attempt in three years from the Palestinian militant group adds a few technical advances to the mix.

πŸ“– Read

via "Threatpost".
❌ SMS Attack Spreads Emotet, Steals Bank Credentials ❌

A new Emotet campaign is spread via SMS messages pretending to be from banks and may have ties to the TrickBot trojan.

πŸ“– Read

via "Threatpost".