πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ›  SerialTweaker 1.1 πŸ› 

SerialTweaker is a tool that can be used to load a serialized object, change its contents, and reserialize it to a new serialized object with modified fields inside.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  nfstream 3.2.2 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
ATENTIONβ€Ό New - CVE-2019-17026

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 23 stories of the week ⚠

From Chrome's mystery zero-day to why the EC has switched to Signal, get yourself up to date with everything we've written in the last week.

πŸ“– Read

via "Naked Security".
πŸ” 5G and IoT security: Why cybersecurity experts are sounding an alarm πŸ”

Without regulation and strong proactive measures, 5G networks remain vulnerable to cyberattacks, and the responsibility falls on businesses and governments.

πŸ“– Read

via "Security on TechRepublic".
⚠ Facebook sues data analytics firm OneAudience over malicious SDK ⚠

Facebook says OneAudience paid developers to install its social-media-profile-looting SDK into their apps to get marketing data for clients.

πŸ“– Read

via "Naked Security".
⚠ Fresh phish! Stripe scam baked and delivered in under an hour ⚠

Less than an hour after the crooks registered their scamming domain, the phishing attack was under way.

πŸ“– Read

via "Naked Security".
⚠ Ironpie robot vacuum can suck up your privacy ⚠

You might want to unplug this not-so-smart robot: researchers found they can watch video streams piped out from its security camera.

πŸ“– Read

via "Naked Security".
⚠ Let’s Encrypt issues one billionth free certificate ⚠

Thanks to this flood of free certificates, the web is a lot more encrypted than it was a few years ago.

πŸ“– Read

via "Naked Security".
πŸ•΄ What Disney+ Can Teach Businesses About Customer Security πŸ•΄

Businesses must prioritize customer protection by taking on some of the responsibility to prevent credential stuffing attacks through multipronged authentication and identity management.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2018-17058

An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via FileUploader.aspx.cs in FileUploader.aspx by using empty w and h parameters. This file may contain arbitrary aspx code that may be executed by accessing /Jec/ProductImages/<number>/<filename>. Accessing the file once uploaded does not require authentication.

πŸ“– Read

via "National Vulnerability Database".
❌ Walgreens Mobile App Leaks Prescription Data ❌

A security error in the Walgreens mobile app may have leaked customers' full names, prescriptions and shipping addresses.

πŸ“– Read

via "Threatpost".
πŸ•΄ Name That Toon: Holy Cow! πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading: ".
πŸ” Morphisec is using the Windows 10 transition to help companies boost security πŸ”

Morphisec combines the anti-virus protection in the new Microsoft OS with its own defenses against malware.

πŸ“– Read

via "Security on TechRepublic".
❌ TrickBot Adds ActiveX Control, Hides Dropper in Images ❌

The tricky trojan has evolved again, to stay a step ahead of defenders.

πŸ“– Read

via "Threatpost".
πŸ•΄ Tesla, SpaceX Parts Manufacturer Suffers Data Breach πŸ•΄

Visser Precision has confirmed a security incident likely caused by the data-stealing DoppelPaymer ransomware.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-12183

Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12580

An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example, "ntmarta.dll"). When the installer EXE is executed by the user, the DLL located in the EXE's current directory will be loaded instead of the Windows DLL, allowing the attacker to run arbitrary code on the affected system.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1583

Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.

πŸ“– Read

via "National Vulnerability Database".
❌ RSAC: Keeping Smart Cities Safe From Hacks ❌

As cities grow more connected, municipal operators must deal with new risks like ransomware, IoT hacks and more.

πŸ“– Read

via "Threatpost".