πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Report calls for web pre-screening to end UK’s child abuse β€˜explosion’ ⚠

The IICSA report cited "unprecedented levels of depravity" and said that encryption is getting in the way of current screening.

πŸ“– Read

via "Naked Security".
⚠ Microsoft patches wormable Windows 10 β€˜SMBGhost’ flaw ⚠

What’s the difference between a scheduled security update and one that’s out-of-band? In this case, it's two days.

πŸ“– Read

via "Naked Security".
πŸ•΄ 4 Ways Thinking 'Childishly' Can Empower Security Professionals πŸ•΄

Younger minds -- more agile and less worried by failure -- provide a useful model for cyber defenders to think more creatively.

πŸ“– Read

via "Dark Reading: ".
πŸ” Report: US Health and Human Services department hit by cyberattack amidst coronavirus fears πŸ”

The Sunday cybersecurity attack was designed to slow down the agency's systems as it tries to grapple with the spread of COVID-19.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-10091

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13063

Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-13060

Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-10125

Contao before 4.5.7 has XSS in the system log.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Fewer Vulnerabilities in Web Frameworks, but Exploits Remain Steady πŸ•΄

Attackers continue to focus on web and application frameworks, such as Apache Struts and WordPress, fighting against a decline in vulnerabilities, according to an analysis.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Hellman & Friedman Acquires Checkmarx for $1.5B πŸ•΄

The private equity firm will buy Checkmarx from Insight Partners, which will continue to own a minority interest.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to enable 2FA on a per-user basis in Nextcloud πŸ”

If you want to enable two-factor authentication for Nextcloud on a per-user basis, it's just a simple app installation away.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to enable 2FA on a per-user basis in Nextcloud πŸ”

If you want to enable two-factor authentication for Nextcloud on a per-user basis, it's just a simple app installation away.

πŸ“– Read

via "Security on TechRepublic".
❌ Microsoft Edge Shares Privacy-Busting Telemetry, Research Alleges ❌

An academic study found Microsoft's Edge browser to be the least private, due to it sending device identifiers and web browsing pages to back-end servers.

πŸ“– Read

via "Threatpost".
πŸ” 88% of IT pros say world is in permanent state of cyberwar πŸ”

A Venafi study looked into what digital infrastructure will suffer from cyberattacks, which are most vulnerable, and what it means.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Case Almost Closed: Motorola Wins Multimillion Dollar Trade Secret Case πŸ”

A jury ruled the telecom is owed upwards to $420 million in damages after a Chinese company was caught stealing its trade secrets for radios.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Five Indicted on Romance and Lottery Fraud Charges πŸ•΄

Fraudsters allegedly targeted elderly victims, ultimately wringing more than $4 million from their bank accounts.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-11073

A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization when passing arguments to the HttpTransactionSensor.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Transaction Sensor and set specific settings when the sensor is executed.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-19325

tcpdump 4.9.2 (and probably lower versions) is prone to a heap-based buffer over-read in the EXTRACT_32BITS function (extract.h, called from the rx_cache_find function, print-rx.c) due to improper serviceId sanitization.

πŸ“– Read

via "National Vulnerability Database".
❌ Convincing Google Impersonation Opens Door to MiTM, Phishing ❌

Using homographic characters is an easy way to execute a convincing fake site.

πŸ“– Read

via "Threatpost".
πŸ•΄ Privacy in a Pandemic: What You Can (and Can't) Ask Employees πŸ•΄

Businesses struggle to strike a balance between workplace health and employees' privacy rights in the midst of a global health emergency.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-12842

Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur. Completing the attack would cost more than a million dollars, and is relevant mainly only in situations where an autonomous system relies solely on an SPV proof for transactions of a greater dollar amount.

πŸ“– Read

via "National Vulnerability Database".