๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.9K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ” Groups Seek to Bump CCPA Enforcement Date Amid Coronavirus Confusion ๐Ÿ”

As with many things currently, details of the California Consumer Privacy Act are unclear. That, plus confusion around COVID-19, has many interest groups hoping enforcement around the law is postponed.

๐Ÿ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONโ€ผ New - CVE-2019-17561

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-17560

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. รขโ‚ฌœApache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โŒ Nation-State Attacks Drop in Latest Google Analysis โŒ

Phishing and zero-days continue to be a core part of the APT arsenal.

๐Ÿ“– Read

via "Threatpost".
โš  No, Houseparty hasnโ€™t hacked your phone and stolen your bank details โš 

There's one thing missing in all the claims that deleting the Houseparty app will "unhack" you - evidence"

๐Ÿ“– Read

via "Naked Security".
๐Ÿ” COVID-19: Security risks are increasing as more people work from home ๐Ÿ”

A security expert offers tips on how to keep employees safe in this work-from-home environment during the coronavirus pandemic.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ” COVID-19: Security risks are increasing as more people work from home ๐Ÿ”

A security expert offers tips on how to keep employees safe in this work-from-home environment during the coronavirus pandemic.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ•ด Microsoft Edge Will Tell You If Credentials Are Compromised ๐Ÿ•ด

Password Monitor, InPrivate mode, and ad-tracking prevention are three new additions to Microsoft Edge.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ•ด Researchers Spot Sharp Increase in Zoom-Themed Domain Registrations ๐Ÿ•ด

Attackers are attempting to take advantage of the surge in teleworking prompted by COVID-19, Check Point says.

๐Ÿ“– Read

via "Dark Reading: ".
๐Ÿ•ด Untangling Third-Party Risk (and Fourth, and Fifth...) ๐Ÿ•ด

Third parties bring critical products and services to your organization. They also bring risk that must be understood and managed.

๐Ÿ“– Read

via "Dark Reading: ".
ATENTIONโ€ผ New - CVE-2019-20634

An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. The insights gathered allow an attacker to craft emails that receive preferable scores, with a goal of delivering malicious emails.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2016-11024 (odata4j)

odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2016-11023 (odata4j)

odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ” Cyberattacks rank as the biggest data protection concern facing SMBs ๐Ÿ”

World Backup Day is March 31, and while cyberattacks are a potential threat to their data, many SMBs say they don't have a data backup or disaster recovery process, according to data protection company Infrascale.

๐Ÿ“– Read

via "Security on TechRepublic".
๐Ÿ” Coronavirus-themed spam surged 14,000% in two weeks says IBM ๐Ÿ”

Since February, spam exploiting the novel coronavirus has jumped by 4,300% and 14,000% in the past 14 days, according to IBM X-Force, IBM's threat intelligence group.

๐Ÿ“– Read

via "Security on TechRepublic".
โš  5 tips for keeping your data safe this World Backup Day โš 

The only backup you will ever regret... is the one you didn't make

๐Ÿ“– Read

via "Naked Security".
ATENTIONโ€ผ New - CVE-2019-9508

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authenticated with an administrator account could store a maliciously named file within the web application that would execute each time a user browsed to the page.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-9507

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed as root, this could allow a remote attacker authenticated with an administrator account to execute arbitrary commands as root.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-19913

In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.

๐Ÿ“– Read

via "National Vulnerability Database".
ATENTIONโ€ผ New - CVE-2019-19912

In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.

๐Ÿ“– Read

via "National Vulnerability Database".