Cyber security aggregate rss news

Cyber security aggregator - feeds history

image for Privacy settings in  ...

 Privacy

Theres a huge variety of beers in the world today. But what if you want to keep track of which ones youve already tasted? You guessed it – theres an app for that; actually – quite a few. Among them, Untappd has become the de facto standard with craft beer fans. The app is essentially a specialized social network   show more ...

where users can get information about almost any beer in the world, check in drinks with attached photos and details of where they were bought, rate them, tag friends, make wish lists, and much more. But, for sure, we mustnt forget that attitudes to alcohol consumption vary from person to person. Even in the most booze-tolerant cultures, being too open about such a divisive issue could cause some problems. So its worth playing safe with privacy. Admit it, sharing your beer adventures with the whole world is probably not a super idea. Regrettably, developers of beer or wine apps seem to think otherwise. As we already reported, Vivino makes all user activity in the app open to everyone online by default — a simple search will spill the beans (or grapes in this case). Privacy in Untappd works the same way: the default option makes all your craft-brew adventures public knowledge. Therefore, it makes sense to spend a moment to properly set up privacy. Heres how. 1. Make your profile private Lets start with the most important tip: make your profile private. Seriously, right now, go and do it! Otherwise, anyone can find lots of intriguing stuff about your check-ins simply through an internet search — without even installing the app. An online search will reveal: Full information about your last five beer check-ins: photos, dates, geotags, tagged friends, likes, comments. Less detailed information about your last 25 check-ins of new beer, including dates. Information about most of your other check-ins (accessible via a keyword search with sorting and filters for all your tags, but not with all details, fortunately). Information about the 25 locations where you most often check in. Again, through sorting and filtering by category, its possible to find out much more than your 25 fave places. Your friends list. In theory, this is limited to only 25 of your oldest virtual drinking buddies, but in practice, with search and sorting, many more. Name and approximate location, if given in your profile. Some less private information: wish lists, badges received, breweries liked, and so on. Again, we emphasize that even someone without an Untappd account can find out all of the above. And if this someone can spare a couple of minutes to register in the app, theyd have access to the most detailed information (photos, geotags, friends tags, comments, etc.) about all the check-ins youve made. Unfortunately, Untappd offers no option to partially hide information. For example, you cant ask the app not to show photos, comments, and geotags to another user, while letting them view your check-ins. So, no matter how trite it may sound, the only way to protect your privacy is to make your profile private. To do this: Tap Profile in the lower right corner of the app screen. Tap the gear icon in the upper right corner. Choose Account -> Privacy. In the Account section turn on the Make Account Private switch. How to make your profile private in Untappd Once your profile is private, all information about you will be available only to your friends. Strangers will see just a message stating that your profile is private: Private profile in Untappd In addition, your actions will no longer be visible among the most recent check-ins displayed by Untappd when a beer or location is selected. In general, hats off to the app: Untappd does a pretty good job of hiding the personal information of users who request it. 2. Be careful with Untappd friends Even if you hide your Untappd profile, full information about all your check-ins is still available to your virtual drinking buddies. So think twice before adding someone to your friends list. If youre not a beer blogger, its probably wise to limit your social circle in the app to those folks youd be happy enjoy a pint with in real life. What you should do about this: at least pay close attention to all friend requests you receive, and dont be afraid to reject ones from strangers. Also, you may consider disabling in-app search for your profile, and enable it only when an acquaintance wants to add you as a friend in Untappd. To do this: Go back to privacy settings (Profile tab -> button with gear icon -> Account-> Privacy). Under User Search, toggle Show Activity Status off. How to turn off profile search in Untappd 3. Think about whether to trust breweries Its worth mentioning that Untappd has a separate account type for breweries. Brewery accounts see check-ins of their beers even from users with private profiles. If you dont like that, you can hide your profile from them too. Heres what to do: Go to privacy settings (Profile tab -> button with gear icon -> Account -> Privacy). Swipe down and turn off the Allow breweries to comment on my check-ins to their beer switch. How to hide your Untappd profile from breweries 4. How to make your Untappd account even more private Like any social network, when you create a profile, Untappd asks for some personal data. Theres no great need to tell the app and users you add as friends your real name. A pseudonym or initials will do. Also consider whether you want to include your location, real date of birth, and gender in your profile data. Theres no benefit to be had from this, while the risk of your account being identified rises sharply (say, in the event of a data leak). Its very easy to change the username, date of birth, location, and gender displayed in Untappd: Go to app settings (Profile tab -> button with gear icon). Tap on Account, choose Profile and then edit the information thats indicated on this page. How to edit your Untappd profile Some final tips Its worth taking the time to configure notifications. Turn off any that are unnecessary so you wont get twitchy about frequent Untappd alerts and wont get distracted by friends beer-drinking endeavors. You can do that here: Profile tab -> button with gear icon -> Notifications. And, of course, the privacy of your account depends directly on the strength of your password. Since you wont be entering it all that often, we recommend making it quite complex and long — the longer the better. And so as not to forget it, we advise using a secure password manager.

 Breaches and Incidents

The leaker posted a magnet link that they claim are 'Yandex git sources' consisting of 44.7 GB of files stolen from the company in July 2022. These code repositories allegedly contain all of the company's source code besides anti-spam rules.

 Malware and Vulnerabilities

The months-long operation involved FBI agents accessing Hive’s network and providing victims with the decryption keys needed to regain control of their systems, blocking about $130m in demanded ransoms, senior justice department officials said.

 Trends, Reports, Analysis

Phishing attacks and malware campaigns targeting Ukraine increased sharply in November before falling at year's end, says security firm Trellix. So too did endpoint security alerts in the region tied to "potentially unwanted programs."

 Malware and Vulnerabilities

Unit 42 researchers discovered a PlugX malware variant that stood out as it infects any attached removable USB media devices such as floppy, thumb, or flash drives and any additional systems the USB is later plugged into.

 Malware and Vulnerabilities

Cyble researchers determined that, in order to target a variety of well-known applications, the attackers are actively changing and customizing their phishing websites. Aurora targets data from web browsers and crypto wallets, among others.

 Innovation and Research

The basic claim of the paper, published last Christmas by 24 Chinese researchers, is that they have found an algorithm that enables 2,048-bit RSA keys to be broken even with the relatively low-power quantum computers available today.

 Feed

Debian Linux Security Advisory 5328-1 - Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

 Feed

Red Hat Security Advisory 2023-0483-01 - This asynchronous update patches Red Hat Fuse 7.11.1 on Karaf and Red Hat Fuse 7.11.1 on Spring Boot and several includes security fixes, which are documented in the Release Notes document linked to in the References. Issues addressed include a server-side request forgery vulnerability.

 Feed

The openscap project is a set of open source libraries that support the SCAP (Security Content Automation Protocol) set of standards from NIST. It supports CPE, CCE, CVE, CVSS, OVAL, and XCCDF.

 Feed

Ubuntu Security Notice 5822-2 - USN-5822-1 fixed vulnerabilities in Samba. The update for Ubuntu 20.04 LTS introduced regressions in certain environments. Pending investigation of these regressions, this update temporarily reverts the security fixes. It was discovered that Samba incorrectly handled the bad password   show more ...

count logic. It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure Channel. Greg Hudson discovered that Samba incorrectly handled PAC parsing. Joseph Sutton discovered that Samba could be forced to issue rc4-hmac encrypted Kerberos tickets.

 Feed

Micro Focus GroupWise is a messaging software for email and personal information management. Trovent Security GmbH discovered that the GroupWise web application transmits the session ID in HTTP GET requests in the URL when email content is accessed. The exposed session ID can be recorded in the browser history of the   show more ...

client and in log files of the web server or reverse proxy server. A possible attacker with access to the browser history or the server log files is able to take control of the user session with the help of the session ID. Versions prior to 18.4.2 are affected.

 Feed

Red Hat Security Advisory 2023-0476-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 102.7.1. Issues addressed include a bypass vulnerability.

 Feed

Red Hat Security Advisory 2023-0481-01 - Submariner enables direct networking between pods and services on different Kubernetes clusters that are either on-premises or in the cloud. This advisory contains bug fixes and enhancements to the Submariner container images.

 Feed

Red Hat Security Advisory 2023-0208-01 - The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Issues addressed include a deserialization vulnerability.

 Feed

Red Hat Security Advisory 2023-0210-01 - The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Issues addressed include a deserialization vulnerability.

 Feed

Red Hat Security Advisory 2023-0479-01 - Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol server, as well as command-line utilities and Web UI packages for server administration.

 Feed

Cybersecurity researchers have discovered the real-world identity of the threat actor behind Golden Chickens malware-as-a-service, who goes by the online persona "badbullzvenom." eSentire's Threat Response Unit (TRU), in an exhaustive report published following a 16-month-long investigation, said it "found multiple mentions of the badbullzvenom account being shared between two people." The

 Feed

Cybersecurity researchers have uncovered a PlugX sample that employs sneaky methods to infect attached removable USB media devices in order to propagate the malware to additional systems. "This PlugX variant is wormable and infects USB devices in such a way that it conceals itself from the Windows operating file system," Palo Alto Networks Unit 42 researchers Mike Harbison and Jen Miller-Osborn 

 Feed

Orcus is a Remote Access Trojan with some distinctive characteristics. The RAT allows attackers to create plugins and offers a robust core feature set that makes it quite a dangerous malicious program in its class. RAT is quite a stable type that always makes it to the top. ANY.RUN’s top malware types in 2022 That's why you'll definitely come across this type in your practice, and the Orcus

 Feed

The U.K. National Cyber Security Centre (NCSC) on Thursday warned of spear-phishing attacks mounted by Russian and Iranian state-sponsored actors for information-gathering operations. "The attacks are not aimed at the general public but targets in specified sectors, including academia, defense, government organizations, NGOs, think tanks, as well as politicians, journalists and activists," the

2023-01
SUN
MON
TUE
WED
THU
FRI
SAT
JanuaryFebruaryMarch