πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10180

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Researchers Uncover Unsophisticated - But Creative - Watering-Hole Attack πŸ•΄

Holy Water campaign is targeting users of a specific religious and ethnic group in Asia, Kaspersky says.

πŸ“– Read

via "Dark Reading: ".
πŸ” Two Exabeam employees at RSA conference who tested positive for COVID-19 are recovering πŸ”

Exabeam's employees are recovering from coronavirus. Both tested positive for coronavirus after attending RSA in San Francisco.

πŸ“– Read

via "Security on TechRepublic".
πŸ” FBI warns about Zoom bombing as hijackers take over school and business video conferences πŸ”

Teleconferences are being disrupted by internet trolls shouting profanity and racist remarks and posting pornographic and hate images.

πŸ“– Read

via "Security on TechRepublic".
πŸ” FBI Urges Vigiliance Around COVID-19 Scams, Malware πŸ”

It’s been difficult keeping track of all the scams leveraging the COVID-19 pandemic to steal your money or your personal information. Now, the FBI is warning of increased attacks that target the supply chain and the healthcare industry in addition to β€œZoom-bombing” style attacks.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2019-13495

In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.

πŸ“– Read

via "National Vulnerability Database".
❌ Watering-Holes Target Asian Ethnic Victims with Flash Update Decoy ❌

About 10 compromised websites employ a multi-stage, targeted effort to fingerprint and compromise victims.

πŸ“– Read

via "Threatpost".
πŸ•΄ Defense Evasion Dominated 2019 Attack Tactics πŸ•΄

Researchers mapped tactics and techniques to the MITRE ATT&CK framework to determine which were most popular last year.

πŸ“– Read

via "Dark Reading: ".
⚠ Microsoft’s Edge browser to get breached credential alerts ⚠

Microsoft has announced a list of new security and privacy features it plans to add to forthcoming versions in an effort to take on its rivals.

πŸ“– Read

via "Naked Security".
πŸ•΄ Major Cloud, CDN Providers Join Secure Routing Initiative πŸ•΄

Akamai, AWS, Azion, Cloudflare, Facebook, and Netflix are now members of the Mutually Agreed Norms for Routing Security (MANRS) effort.

πŸ“– Read

via "Dark Reading: ".
⚠ QR code generator scam steals thousands in Bitcoin ⚠

Every once in a while an attack comes along that is so simple to set up, and yet so effective, that it makes your jaw drop. Here's one.

πŸ“– Read

via "Naked Security".
⚠ Bill Gates’s YouTube β€˜Bitcoin giveaway’ is a big fat scam ⚠

And no, Microsoft said, none of our verified accounts have been hijacked, vehemently denying early reports.

πŸ“– Read

via "Naked Security".
❌ Top Email Protections Fail in Latest COVID-19 Phishing Campaign ❌

An effective spoofing campaign promises users important information about new coronavirus cases in their local area, scooting past Proofpoint and Microsoft Office 356 ATPs.

πŸ“– Read

via "Threatpost".
πŸ•΄ The SOC Emergency Room Faces Malware Pandemic πŸ•΄

To keep users and networks healthy and secure, security teams need to mimic countries that have taken on COVID-19 with a rapid, disciplined approach.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ COVID-19: Latest Security News & Commentary πŸ•΄

Check out Dark Reading's updated, exclusive news and commentary surrounding the coronavirus pandemic.

πŸ“– Read

via "Dark Reading: ".
❌ Two Zoom Zero-Day Flaws Uncovered ❌

The zero-day Zoom flaws could give local, unprivileged attackers root privileges, and allow them to access victims’ microphone and camera.

πŸ“– Read

via "Threatpost".
πŸ•΄ Could Work-From-Home Staff be Violating Privacy Laws During Conference Calls? πŸ•΄

If you are lucky enough to be able to do your job from home right now, you should be aware of a few key things.

πŸ“– Read

via "Dark Reading: ".
πŸ” Holy Water watering hole attack targets visitors of certain websites with malware πŸ”

This campaign tries to trick users into accepting a fake Adobe Flash update, which then installs malware to give the attacker full remote access, says Kaspersky.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Alerts Healthcare to Human-Operated Ransomware πŸ•΄

Microsoft has notified dozens of hospitals with vulnerable gateway and VPN appliances in their infrastructure, which could put them at risk.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10231

TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.

πŸ“– Read

via "National Vulnerability Database".