ATENTIONโผ New - CVE-2015-3006
๐ Read
via "National Vulnerability Database".
On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been up and running for some time, but immediately after boot, the entropy is very low. This issue only affects the QFX3500 and QFX3600 switches. No other Juniper Networks products or platforms are affected by this weak entropy vulnerability.๐ Read
via "National Vulnerability Database".
๐ Fraud alert: Voice authentication platform analyzes 1,380 data points per call ๐
๐ Read
via "Security on TechRepublic".
Pindrop's dashboard scores the caller, the device, and the behavior to spot bad actors and authentic customers.๐ Read
via "Security on TechRepublic".
TechRepublic
Fraud alert: Voice authentication platform analyzes 1,380 data points per call
Pindrop's dashboard scores the caller, the device, and the behavior to spot bad actors and authentic customers.
๐ SerialTweaker 1.1 ๐
๐ Go!
via "Security Tool Files โ Packet Storm".
SerialTweaker is a tool that can be used to load a serialized object, change its contents, and reserialize it to a new serialized object with modified fields inside.๐ Go!
via "Security Tool Files โ Packet Storm".
Packetstormsecurity
SerialTweaker 1.1 โ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
๐ nfstream 3.2.2 ๐
๐ Go!
via "Security Tool Files โ Packet Storm".
nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.๐ Go!
via "Security Tool Files โ Packet Storm".
Packetstormsecurity
nfstream 3.2.2 โ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
ATENTIONโผ New - CVE-2019-17026
๐ Read
via "National Vulnerability Database".
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.๐ Read
via "National Vulnerability Database".
โ Monday review โ the hot 23 stories of the week โ
๐ Read
via "Naked Security".
From Chrome's mystery zero-day to why the EC has switched to Signal, get yourself up to date with everything we've written in the last week.๐ Read
via "Naked Security".
Sophos News
Naked Security โ Sophos News
๐ 5G and IoT security: Why cybersecurity experts are sounding an alarm ๐
๐ Read
via "Security on TechRepublic".
Without regulation and strong proactive measures, 5G networks remain vulnerable to cyberattacks, and the responsibility falls on businesses and governments.๐ Read
via "Security on TechRepublic".
TechRepublic
5G and IoT security: Why cybersecurity experts are sounding an alarm
Without regulation and strong proactive measures, 5G networks remain vulnerable to cyberattacks, and the responsibility falls on businesses and governments.
โ Facebook sues data analytics firm OneAudience over malicious SDK โ
๐ Read
via "Naked Security".
Facebook says OneAudience paid developers to install its social-media-profile-looting SDK into their apps to get marketing data for clients.๐ Read
via "Naked Security".
Naked Security
Facebook sues data analytics firm OneAudience over malicious SDK
Facebook says OneAudience paid developers to install its social-media-profile-looting SDK into their apps to get marketing data for clients.
โ Fresh phish! Stripe scam baked and delivered in under an hour โ
๐ Read
via "Naked Security".
Less than an hour after the crooks registered their scamming domain, the phishing attack was under way.๐ Read
via "Naked Security".
Naked Security
Fresh phish! Stripe scam baked and delivered in under an hour
Less than an hour after the crooks registered their scamming domain, the phishing attack was under way.
โ Ironpie robot vacuum can suck up your privacy โ
๐ Read
via "Naked Security".
You might want to unplug this not-so-smart robot: researchers found they can watch video streams piped out from its security camera.๐ Read
via "Naked Security".
Naked Security
Ironpie robot vacuum can suck up your privacy
You might want to unplug this not-so-smart robot: researchers found they can watch video streams piped out from its security camera.
โ Letโs Encrypt issues one billionth free certificate โ
๐ Read
via "Naked Security".
Thanks to this flood of free certificates, the web is a lot more encrypted than it was a few years ago.๐ Read
via "Naked Security".
Naked Security
Letโs Encrypt issues one billionth free certificate
Thanks to this flood of free certificates, the web is a lot more encrypted than it was a few years ago.
๐ด What Disney+ Can Teach Businesses About Customer Security ๐ด
๐ Read
via "Dark Reading: ".
Businesses must prioritize customer protection by taking on some of the responsibility to prevent credential stuffing attacks through multipronged authentication and identity management.๐ Read
via "Dark Reading: ".
Dark Reading
What Disney+ Can Teach Businesses About Customer Security - Dark Reading
Businesses must prioritize customer protection by taking on some of the responsibility to prevent credential stuffing attacks through multipronged authentication and identity management.
ATENTIONโผ New - CVE-2018-17058
๐ Read
via "National Vulnerability Database".
An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via FileUploader.aspx.cs in FileUploader.aspx by using empty w and h parameters. This file may contain arbitrary aspx code that may be executed by accessing /Jec/ProductImages/<number>/<filename>. Accessing the file once uploaded does not require authentication.๐ Read
via "National Vulnerability Database".
โ Walgreens Mobile App Leaks Prescription Data โ
๐ Read
via "Threatpost".
A security error in the Walgreens mobile app may have leaked customers' full names, prescriptions and shipping addresses.๐ Read
via "Threatpost".
Threat Post
Walgreens Mobile App Leaks Prescription Data
A security error in the Walgreens mobile app may have leaked customers' full names, prescriptions and shipping addresses.
๐ด Name That Toon: Holy Cow! ๐ด
๐ Read
via "Dark Reading: ".
Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.๐ Read
via "Dark Reading: ".
Dark Reading
Name That Toon: Holy Cow!
Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.
๐ Morphisec is using the Windows 10 transition to help companies boost security ๐
๐ Read
via "Security on TechRepublic".
Morphisec combines the anti-virus protection in the new Microsoft OS with its own defenses against malware.๐ Read
via "Security on TechRepublic".
TechRepublic
Morphisec is using the Windows 10 transition to help companies boost security
Morphisec combines the anti-virus protection in the new Microsoft OS with its own defenses against malware.
โ TrickBot Adds ActiveX Control, Hides Dropper in Images โ
๐ Read
via "Threatpost".
The tricky trojan has evolved again, to stay a step ahead of defenders.๐ Read
via "Threatpost".
Threat Post
TrickBot Adds ActiveX Control, Hides Dropper in Images
The tricky trojan has evolved again, to stay a step ahead of defenders.
๐ด Tesla, SpaceX Parts Manufacturer Suffers Data Breach ๐ด
๐ Read
via "Dark Reading: ".
Visser Precision has confirmed a security incident likely caused by the data-stealing DoppelPaymer ransomware.๐ Read
via "Dark Reading: ".
Darkreading
Tesla, SpaceX Parts Manufacturer Suffers Data Breach
Visser Precision has confirmed a security incident likely caused by the data-stealing DoppelPaymer ransomware.
ATENTIONโผ New - CVE-2019-12183
๐ Read
via "National Vulnerability Database".
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.๐ Read
via "National Vulnerability Database".