πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-21049 (android)

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is an arbitrary memory write in a Trustlet because a secure driver allows access to sensitive APIs. The Samsung ID is SVE-2018-12881 (November 2018).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21048 (android)

An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device in Standalone Dex mode. The Samsung ID is SVE-2018-12925 (November 2018).

πŸ“– Read

via "National Vulnerability Database".
πŸ” IoT security, neglected infrastructure, and a crisis of trust deemed major threats for 2022 πŸ”

The Internet Security Forum predicts the coming threats with a very good track record so far. Get your company ready for these threats.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Cybercrime May Be the World's Third-Largest Economy by 2021 πŸ•΄

The underground economy is undergoing an industrialization wave and booming like never before.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Pandemic Could Make Schools Bigger Targets of Ransomware Attacks πŸ•΄

Most have had to implement distance learning, making them much more vulnerable, Armor says.

πŸ“– Read

via "Dark Reading: ".
❌ Overlay Malware Leverages Chrome Browser, Targets Banks and Heads to Spain ❌

The Grandoreiro banking malware uses remote overlay and a fake Chrome browser plugin to steal from banking customers.

πŸ“– Read

via "Threatpost".
πŸ” SEC Settles With Two Traders Involved in 2016 Hack πŸ”

Two of the illicit traders indicted in a 2016 hack of the SEC have agreed to settle and in turn, give back six figure sums of money they made with information stolen from a SEC system.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
⚠ Monday review – the hot 15 stories of the week ⚠

Get yourself up to date with everything we've written in the last seven days - it's weekly roundup time.

πŸ“– Read

via "Naked Security".
❌ Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update ❌

Oracle will detail 405 new security vulnerabilities Tuesday, part of its quarterly Critical Patch Update Advisory.

πŸ“– Read

via "Threatpost".
πŸ” The end of passwords: Industry experts explore the possibilities and challenges πŸ”

Passwords have been an industry standard and industry headache for decades. Learn some best practice tips for password administration from tech security insiders.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Dutch Police Shut Down 15 DDoS-for-Hire Services πŸ•΄

Officials arrested a man suspected of launching a DDoS attack against two websites that send government updates to citizens.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Dell Releases Security Tool to Defend PCs from BIOS Attacks πŸ•΄

The SafeBIOS Events & Indicators of Attack tool gives admins visibility into BIOS configuration changes and alerts them to potential threats.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Network Data Shows Spikes, Vulnerability of Work-at-Home Shift πŸ•΄

Traffic on the public Internet has grown by half this year, and videoconferencing bandwidth has grown by a factor of five, all driven by remote-work edicts.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-11668 (linux_kernel)

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11647 (wireshark)

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11557 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11556 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11555 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11554 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.

πŸ“– Read

via "National Vulnerability Database".
⚠ Microsoft and Google delay online authentication change ⚠

Both Microsoft and Google have postponed a change that would have forced better application security by shutting down an insecure access protocol called Basic Authentication.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2020-11553 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.

πŸ“– Read

via "National Vulnerability Database".