πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Top Email Protections Fail in Latest COVID-19 Phishing Campaign ❌

An effective spoofing campaign promises users important information about new coronavirus cases in their local area, scooting past Proofpoint and Microsoft Office 356 ATPs.

πŸ“– Read

via "Threatpost".
πŸ•΄ The SOC Emergency Room Faces Malware Pandemic πŸ•΄

To keep users and networks healthy and secure, security teams need to mimic countries that have taken on COVID-19 with a rapid, disciplined approach.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ COVID-19: Latest Security News & Commentary πŸ•΄

Check out Dark Reading's updated, exclusive news and commentary surrounding the coronavirus pandemic.

πŸ“– Read

via "Dark Reading: ".
❌ Two Zoom Zero-Day Flaws Uncovered ❌

The zero-day Zoom flaws could give local, unprivileged attackers root privileges, and allow them to access victims’ microphone and camera.

πŸ“– Read

via "Threatpost".
πŸ•΄ Could Work-From-Home Staff be Violating Privacy Laws During Conference Calls? πŸ•΄

If you are lucky enough to be able to do your job from home right now, you should be aware of a few key things.

πŸ“– Read

via "Dark Reading: ".
πŸ” Holy Water watering hole attack targets visitors of certain websites with malware πŸ”

This campaign tries to trick users into accepting a fake Adobe Flash update, which then installs malware to give the attacker full remote access, says Kaspersky.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Microsoft Alerts Healthcare to Human-Operated Ransomware πŸ•΄

Microsoft has notified dozens of hospitals with vulnerable gateway and VPN appliances in their infrastructure, which could put them at risk.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-10231

TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical WordPress Plugin Bug Can Lock Admins Out of Websites ❌

A second vulnerability could be used to prevent access to almost all of a site’s existing content, by simply redirecting visitors.

πŸ“– Read

via "Threatpost".
πŸ•΄ Active Directory Attacks Hit the Mainstream πŸ•΄

Understanding the limitations of authentication protocols, especially as enterprises link authentication to cloud services to Active Directory, is essential for security teams in the modern federated enterprise.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-3945

Web server running on Parrot ANAFI can be crashed due to the SDK command "Common_CurrentDateTime" being sent to control service with larger than expected date length.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-3944

Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-3942

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11106

NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Zoom’s Privacy Problems Snowball as Two Zero Days Uncovered πŸ”

Amid increased scrutiny from researchers and privacy activists, two new zero days in the teleconferencing app surfaced on Wednesday.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Coronavirus β€˜Financial Relief’ Phishing Attacks Spike ❌

A spate of phishing attacks have promised financial relief due to the coronavirus pandemic - but in reality swiped victims' credentials, payment card data and more.

πŸ“– Read

via "Threatpost".
πŸ•΄ Why All Employees Are Responsible for Company Cybersecurity πŸ•΄

It's not just the IT and security team's responsibility to keep data safe -- every member of the team needs to be involved.

πŸ“– Read

via "Dark Reading: ".
πŸ” COVID-19 pandemic impact pushing smart home voice control devices to predicted 30% growth πŸ”

Global shipments of smart home speakers will increase this year due to fear of coronavirus germs, according to ABI Research.

πŸ“– Read

via "Security on TechRepublic".
❌ Wiper Malware Called β€œCoronavirus” Spreads Among Windows Victims ❌

Like NotPetya, it overwrites the master boot record to render computers "trashed."

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-9163

The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-11254

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.

πŸ“– Read

via "National Vulnerability Database".