πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-11024 (odata4j)

odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11023 (odata4j)

odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Cyberattacks rank as the biggest data protection concern facing SMBs πŸ”

World Backup Day is March 31, and while cyberattacks are a potential threat to their data, many SMBs say they don't have a data backup or disaster recovery process, according to data protection company Infrascale.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Coronavirus-themed spam surged 14,000% in two weeks says IBM πŸ”

Since February, spam exploiting the novel coronavirus has jumped by 4,300% and 14,000% in the past 14 days, according to IBM X-Force, IBM's threat intelligence group.

πŸ“– Read

via "Security on TechRepublic".
⚠ 5 tips for keeping your data safe this World Backup Day ⚠

The only backup you will ever regret... is the one you didn't make

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-9508

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authenticated with an administrator account could store a maliciously named file within the web application that would execute each time a user browsed to the page.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-9507

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed as root, this could allow a remote attacker authenticated with an administrator account to execute arbitrary commands as root.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19913

In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19912

In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19606

X-Plane 11.41 and earlier has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19605

X-Plane 11.41 and earlier allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
⚠ β€œInstant bank fraud” warning spread on WhatsApp is a hoax ⚠

No, we don't know why people start hoaxes like this. You can do your bit by not forwarding them, not even "just in case".

πŸ“– Read

via "Naked Security".
❌ Covid-19 Poll Results: One in Four Prioritize Health Over Privacy ❌

An informal Threatpost reader poll shows the majority of site visitors are privacy absolutists. But attitudes shift when the trade off is saving lives.

πŸ“– Read

via "Threatpost".
⚠ Researchers speed the death of β€˜bad’ data in the race against good ⚠

They have a way to inject 'good' data - i.e., accurate COVID-19 news or security patches - to outpace the spread of fake news or malware.

πŸ“– Read

via "Naked Security".
⚠ Data on almost every citizen of Georgia posted on hacker forum ⚠

Where did it all come from? 4.9m records were posted on a hacking forum - and the country only has an estimated population of 3.7m.

πŸ“– Read

via "Naked Security".
πŸ•΄ Limited-Time Free Offers to Secure the Enterprise Amid COVID-19 πŸ•΄

These products and services could be of immediate help to infosec pros now protecting their organizations while working from home.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ How Much Downtime Can Your Company Handle? πŸ•΄

Why every business needs cyber resilience and quick recovery times.

πŸ“– Read

via "Dark Reading: ".
⚠ Dharma ransomware source code on sale for $2,000 ⚠

The source code for ransomware-as-a-service strain Dharma has been put up for sale by hackers.

πŸ“– Read

via "Naked Security".
⚠ Patch now! Critical flaw found in OpenWrt router software ⚠

OpenWrt is an open source operating system used by millions of home and small business routers and embedded devices.

πŸ“– Read

via "Naked Security".
πŸ›  OpenSSL Toolkit 1.1.1f πŸ› 

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols with full-strength cryptography world-wide.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Does the 2020 Online Census Account for Security Risk? πŸ•΄

Experts discuss the security issues surrounding a census conducted online and explain how COVID-19 could exacerbate the risk.

πŸ“– Read

via "Dark Reading: ".