πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Palo Alto Networks to Buy CloudGenix for $420M πŸ•΄

Palo Alto Networks plans to integrate CloudGenix's SD-WAN technology into its Prisma SASE platform following the deal.

πŸ“– Read

via "Dark Reading: ".
⚠ Marriott International confirms data breach of up to 5.2 million guests ⚠

Marriott International has today announced that it has suffered a data breach affecting up to 5.2 million people.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-2391

Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Phishing emails claim recipient has been infected with coronavirus πŸ”

A new phishing campaign is using the fear of being infected as a way to spread malware, as spotted by security trainer KnowBe4.

πŸ“– Read

via "Security on TechRepublic".
πŸ” IBM providing 9 free public cloud business services to customers during coronavirus pandemic πŸ”

With companies sending employees home to work during the COVID-19 threat, IBM offers a range of tools to support critical IT applications.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to better secure your Microsoft Remote Desktop Protocol connections πŸ”

Microsoft's Remote Desktop Protocol has been saddled with security bugs and weaknesses, which means you need to take certain precautions when using RDP for remote connections.

πŸ“– Read

via "Security on TechRepublic".
❌ 8-Year-Old VelvetSweatshop Bug Resurrected in LimeRAT Campaign ❌

An old RAT learns an old trick.

πŸ“– Read

via "Threatpost".
❌ Zoom Scrutinized As Security Woes Mount ❌

The New York Attorney General has inquired about Zoom's data security strategy, as the conferencing platform comes under heavy scrutiny for its privacy policies.

πŸ“– Read

via "Threatpost".
πŸ•΄ Patching Poses Security Problems with Move to More Remote Work πŸ•΄

Security teams were not ready for the wholesale move to remote work and the sudden expansion of the attack surface area, experts say.

πŸ“– Read

via "Dark Reading: ".
πŸ” Keep these privacy considerations in mind when using Zoom at home for work collaboration πŸ”

The platform allows a host to monitor users' activities while screen sharing, as well as access to a participant's device information and other details.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Why Third-Party Risk Management Has Never Been More Important πŸ•΄

Given today's coronavirus pandemic, the need for companies to collect cybersecurity data about their business partners is more critical than ever. Here's how to start.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Latest Security News & Commentary about COVID-19 πŸ•΄

Check out Dark Reading's updated, exclusive news and commentary surrounding the coronavirus pandemic.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Data from 5.2M Marriott Loyalty Program Members Hit by Breach πŸ•΄

The data was breached through the credentials of two franchisee employees.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-14905

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10180

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Researchers Uncover Unsophisticated - But Creative - Watering-Hole Attack πŸ•΄

Holy Water campaign is targeting users of a specific religious and ethnic group in Asia, Kaspersky says.

πŸ“– Read

via "Dark Reading: ".
πŸ” Two Exabeam employees at RSA conference who tested positive for COVID-19 are recovering πŸ”

Exabeam's employees are recovering from coronavirus. Both tested positive for coronavirus after attending RSA in San Francisco.

πŸ“– Read

via "Security on TechRepublic".
πŸ” FBI warns about Zoom bombing as hijackers take over school and business video conferences πŸ”

Teleconferences are being disrupted by internet trolls shouting profanity and racist remarks and posting pornographic and hate images.

πŸ“– Read

via "Security on TechRepublic".
πŸ” FBI Urges Vigiliance Around COVID-19 Scams, Malware πŸ”

It’s been difficult keeping track of all the scams leveraging the COVID-19 pandemic to steal your money or your personal information. Now, the FBI is warning of increased attacks that target the supply chain and the healthcare industry in addition to β€œZoom-bombing” style attacks.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2019-13495

In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.

πŸ“– Read

via "National Vulnerability Database".