πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-10221

A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10179

A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to create a Kubernetes security policy πŸ”

If you're looking to take your Kubernetes security to the next level, you'll want to start working with pod security policies. Here's a quick introduction to this feature.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Proof of Concept Released for kr00k Wi-Fi Vulnerability πŸ•΄

The code demonstrates a relatively simple method to exploit a vulnerability in more than a billion devices.

πŸ“– Read

via "Dark Reading: ".
⚠ Trolls ZoomBomb work-from-home videocall with filth ⚠

Trolls have been joining videoconferencing calls to expose meeting participants to disturbing videos.

πŸ“– Read

via "Naked Security".
⚠ S2 Ep31: Remote working, malwareless ransomware and EARN IT – Naked Security Podcast ⚠

Listen to the latest episode now!

πŸ“– Read

via "Naked Security".
πŸ” How to deal with network security and bandwidth issues during the coronavirus pandemic πŸ”

Experts discuss what precautions companies need to be taking right now that a record number of people are working outside of offices.

πŸ“– Read

via "Security on TechRepublic".
❌ News Wrap, Coronavirus Edition: WFH Security Woes, Pwn2Own ❌

Threatpost editors discuss this week's top news stories from COVID-19 themed malware attacks to Pwn2Own updates.

πŸ“– Read

via "Threatpost".
πŸ•΄ Dark Reading Cybersecurity Crossword Puzzle πŸ•΄

Here's a little something to snuggle up with if you're on lockdown.

πŸ“– Read

via "Dark Reading: ".
❌ Defying Covid-19’s Pall: Pwn2Own Goes Virtual ❌

Hacking contest goes virtual with participants remotely winning $295k in prizes for taking down Adobe Reader, Safari and Ubuntu.

πŸ“– Read

via "Threatpost".
❌ Revamped HawkEye Keylogger Swoops in on Coronavirus Fears ❌

Emails claiming to be directly from WHO’s Dr. Tedros Adhanom Ghebreyesus offer "drug advice" -- and malware infections.

πŸ“– Read

via "Threatpost".
πŸ•΄ 200M Records of US Citizens Leaked in Unprotected Database πŸ•΄

Researchers have not determined who owns the database, which was one of several large exposed instances disclosed this week.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-11574

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7487

On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to Ò€œsystemҀ�, which allows remote attackers to execute arbitrary code via TCP port 9000.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  GNU Privacy Guard 2.2.20 πŸ› 

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
⚠ Monday review – the hot 23 stories of the week ⚠

From the EARN IT Act to the Martinelli hoax - and everything in between. It’s your weekly security roundup.

πŸ“– Read

via "Naked Security".
⚠ Firefox is dropping FTP support ⚠

Heads up, Firefox users who rely on FTP: the browser is eliminating support for this venerable protocol.

πŸ“– Read

via "Naked Security".
⚠ Stolen data of company that refused REvil ransom payment now on sale ⚠

A comment from one buyer of data purportedly from Brooks International: "It even has credit card number & a password. lol !!"

πŸ“– Read

via "Naked Security".
⚠ Tour guide/Chinese spy gets four years for SD card dead drops ⚠

The dead drops were very James Bond: once, the data mule taped the SD card to the underside of a desk in a hotel.

πŸ“– Read

via "Naked Security".
⚠ Cisco issues urgent fixes for SD-WAN router flaws ⚠

Cisco has patched a clutch of high-priority vulnerabilities in its SD-WAN routes and their management software.

πŸ“– Read

via "Naked Security".