πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” COVID-19 brings new security challenges and new allies, says HackerOne CEO πŸ”

Commentary: Even as phishing and other attacks rise in the wake of COVID-19, white-hat hackers are readying their defenses.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-12119

An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12118

An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12117

An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12116

An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12115

An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12114

An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12113

An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12112

An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ TrickBot Module Takes Aim at Remote Desktops πŸ•΄

The module, still in development, focuses on compromising Windows systems by brute-forcing accounts via the Remote Desktop Protocol.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Process Injection Tops Attacker Techniques for 2019 πŸ•΄

Attackers commonly use remote administration and network management tools for lateral movement, a new pool of threat data shows.

πŸ“– Read

via "Dark Reading: ".
❌ Azure Red Flag: Microsoft Accidentally Fixes Cloud Config β€˜Bug’ ❌

Researchers detail a misconfiguration in Microsoft’s Azure cloud platform that could have given hackers carte blanche access to a targeted company's cloud services.

πŸ“– Read

via "Threatpost".
❌ WordPress, Apache Struts Attract the Most Bug Exploits ❌

An analysis found these web frameworks to be the most-targeted by cybercriminals in 2019.

πŸ“– Read

via "Threatpost".
πŸ•΄ Skimmer May Have Put NutriBullet Customers' Card Data at Risk for Nearly a Month πŸ•΄

Blender maker is the latest victim of Magecart.

πŸ“– Read

via "Dark Reading: ".
πŸ” Libya-based hackers using coronavirus pandemic to spread mobile surveillance malware πŸ”

The drastic spread of coronavirus across the world has not stopped cybercriminals from exploiting fear to hack into devices.

πŸ“– Read

via "Security on TechRepublic".
⚠ Android malware uses coronavirus for sextortion and ransomware combo ⚠

The app says it will notify you of coronavirus cases... but in fact it locks up your phone and sextorts you for money at the same time

πŸ“– Read

via "Naked Security".
⚠ Facebook accidentally blocks genuine COVID-19 news ⚠

Facebook is denying that a recent content moderation glitch has anything to do with workforce issues, but blames automatic systems.

πŸ“– Read

via "Naked Security".
⚠ Delayed Adobe patches fix long list of critical flaws ⚠

This week the company made amends, issuing fixes for an unusually high CVE-level 41 vulnerabilities, 21 of which are rated critical.

πŸ“– Read

via "Naked Security".
πŸ•΄ Quantifying Cyber Risk: Why You Must & Where to Start πŸ•΄

Quantifying cybersecurity risks can be a critical step in understanding those risks and getting executive support to address them.

πŸ“– Read

via "Dark Reading: ".
⚠ Cryptojacking is almost conquered – crushed along with coinhive.com ⚠

Cryptojacking may not be entirely gone following the shutdown of notorious cryptomining service Coinhive - but it's drastically diminished.

πŸ“– Read

via "Naked Security".
πŸ” IT security report finds 97% have suspicious network activity πŸ”

The suspicious network activities revealed in the research by Positive Technologies are traffic hiding, VPN tunneling, connections to the Tor anonymous network, and network proxying.

πŸ“– Read

via "Security on TechRepublic".