πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Network Data Shows Spikes, Vulnerability of Work-at-Home Shift πŸ•΄

Traffic on the public Internet has grown by half this year, and videoconferencing bandwidth has grown by a factor of five, all driven by remote-work edicts.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2020-11668 (linux_kernel)

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11647 (wireshark)

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11557 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11556 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11555 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11554 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.

πŸ“– Read

via "National Vulnerability Database".
⚠ Microsoft and Google delay online authentication change ⚠

Both Microsoft and Google have postponed a change that would have forced better application security by shutting down an insecure access protocol called Basic Authentication.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2020-11553 (snmpc_online)

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2020-11002 (dropwizard_validation)

dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability. If you are using a self-validating bean an upgrade to Dropwizard 1.3.21/2.0.3 or later is strongly recommended. The changes introduced in Dropwizard 1.3.19 and 2.0.2 for CVE-2020-5245 unfortunately did not fix the underlying issue completely. The issue has been fixed in dropwizard-validation 1.3.21 and 2.0.3 or later. We strongly recommend upgrading to one of these versions.

πŸ“– Read

via "National Vulnerability Database".
⚠ ICANN asks registrars to crack down on scam coronavirus websites ⚠

It doesn't have regulatory authority, so it can't do much, but the hundreds of registrars it authorizes can and should.

πŸ“– Read

via "Naked Security".
⚠ TikTok users beware: Hackers could swap your videos with their own ⚠

TikTok doesn't use HTTPS for its images and videos - so crooks could swap out the videos you see and you would never know.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-11480

The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options when creating the build chroot environment. This could allow an attacker who is able to perform a MITM attack between the build environment and the Ubuntu archive to install a malicious package within the build chroot. This issue affects pc-kernel versions prior to and including 2019-07-16

πŸ“– Read

via "National Vulnerability Database".
❌ Malware Risks Triple on WFH Networks: Experts Offer Advice ❌

New research found that almost half of companies had malware on their corporate-associated home networks - in comparison to malware being found on only 13 percent of corporate networks.

πŸ“– Read

via "Threatpost".
πŸ•΄ 7 Ways COVID-19 Has Changed Our Online Lives πŸ•΄

The pandemic has driven more of our personal and work lives online - and for the bad guys, business is booming. Here's how you can protect yourself.

πŸ“– Read

via "Dark Reading: ".
❌ TikTok Flaw Allows Threat Actors to Plant Forged Videos in User Feeds ❌

The popular video-sharing apps’s use of HTTP to download media content instead of a secure protocol could lead to the spread of misinformation on the platform.

πŸ“– Read

via "Threatpost".
❌ Safe Remote Access to Critical Infrastructure Networks in a Time of Global Crisis ❌

As operators struggle to balance the recommendations of social distancing with the need to keep vital services functioning, there is no getting around the fact that conventional remote connections into industrial control networks are a very bad idea.

πŸ“– Read

via "Threatpost".
πŸ•΄ Web Pioneers Launch Identity Startup That Ditches Passwords πŸ•΄

Legendary founders of Netscape and @Home Network roll out a new cloud-based identity management firm that makes the user his or her own certificate authority.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ You're One Misconfiguration Away from a Cloud-Based Data Breach πŸ•΄

Don't assume that cyberattacks are all you have to worry about. Misconfigurations should also be a top cause of concern.

πŸ“– Read

via "Dark Reading: ".
πŸ” Going phishing: The most imitated big name brands πŸ”

Criminals are using familiar company names to steal user information and payment credentials, Check Point found.

πŸ“– Read

via "Security on TechRepublic".
❌ Cyberattacks Target Healthcare Orgs on Coronavirus Frontlines ❌

Cybercriminals aren't sparing medical professionals, hospitals and healthcare orgs on the frontlines of the coronavirus pandemic when it comes to cyberattacks, ransomware attacks and malware.

πŸ“– Read

via "Threatpost".