πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Researchers Explore Details of Critical VMware Vulnerability πŸ•΄

The vCenter vulnerability, patched on April 9, could give an intruder access to administrative credentials in three steps.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ COVID-Themed Phishing Messages Fill Phishing Filters on Gmail πŸ•΄

In the past week, Google says it identified more than 18 million daily phishing messages featuring coronavirus themes.

πŸ“– Read

via "Dark Reading: ".
❌ DHS Urges Pulse Secure VPN Users To Update Passwords ❌

The DHS urged organizations to update their passwords and make sure that a critical Pulse Secure VPN flaw has been patched, as attackers continue to exploit the flaw.

πŸ“– Read

via "Threatpost".
πŸ” Zoom: A cheat sheet about the video conferencing solution πŸ”

Zoom has become a household name because lots of people are working from home and using the video conferencing software. Here is your guide to Zoom basics, including its security vulnerabilities.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Pen-Test Results Hint at Improvements in Enterprise Security πŸ•΄

Though many problems remain, organizations are making attackers work harder.

πŸ“– Read

via "Dark Reading: ".
⚠ Monday review – the hot 13 stories of the week ⚠

From the critical bug in Google Chrome to Signal's fears over the EARN Act, get yourself up to date with everything we've written in the last week.

πŸ“– Read

via "Naked Security".
⚠ Bot creates millions of fake eyeballs to rip off smart-TV advertisers ⚠

The massive ICEBUCKET scheme has, so far, impersonated more than 2m people in 30+ countries, defrauding more than 300 brands of ad dollars.

πŸ“– Read

via "Naked Security".
πŸ” Scammers exploiting stimulus payments with phishing attacks and malicious domains πŸ”

Since January, more than 4,000 domains related to coronavirus stimulus packages have been registered, many of them malicious or suspicious, according to Check Point Research.

πŸ“– Read

via "Security on TechRepublic".
⚠ New sextortion scam: β€œHigh level of risk. Your account has been hacked.” ⚠

The latest sextortion emails try to fool you with technical terms they hope you won't understand.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2017-18852

Certain NETGEAR devices are affected by CSRF and authentication bypass. This affects R7300DST before 1.0.0.54, R8300 before 1.0.2.100_1.0.82, R8500 before 1.0.2.100_1.0.82, and WNDR3400v3 before 1.0.1.14.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18851

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D8500 through 1.0.3.28, R6400 through 1.0.1.22, R6400v2 through 1.0.2.18, R8300 through 1.0.2.94, R8500 through 1.0.2.94, and R6100 through 1.0.1.12.

πŸ“– Read

via "National Vulnerability Database".
⚠ Fan vibrations can be used transmit data from air-gapped machines ⚠

The scientists known for finding ways to transmit software from non-networked computers, have figured out a way to do it using computer fan vibrations.

πŸ“– Read

via "Naked Security".
πŸ•΄ Remote Access Makes a Comeback: 4 Security Challenges in the Wake of COVID-19 πŸ•΄

As companies continue to support increasing numbers of work-from-home employees, the pressure to secure access and reduce risk has never been greater.

πŸ“– Read

via "Dark Reading: ".
⚠ Maze ransomware hits US giant Cognizant ⚠

The latest company to fall victim to a ransomware attack is Cognizant, a large US IT services company which admitted at the weekend that it had fallen victim to Maze.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2017-18850

Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.12, R6400 before 1.01.24, R6400v2 before 1.0.2.30, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R6900P before 1.0.0.56, R7000 before 1.0.9.4, R7000P before 1.0.0.56, R7100LG before 1.0.0.32, R7300DST before 1.0.0.54, R7900 before 1.0.1.18, R8000 before 1.0.3.44, R8300 before 1.0.2.100_1.0.82, and R8500 before 1.0.2.100_1.0.82.

πŸ“– Read

via "National Vulnerability Database".
❌ Bitcoin Stealers Hide in 700+ Ruby Developer Libraries ❌

Cybercriminals uploaded typosquatted malicious libraries to RubyGems, which contains open-source components that are used as basic application building blocks by software developers.

πŸ“– Read

via "Threatpost".
πŸ•΄ COVID-19 Caption Contest Winners πŸ•΄

It was a tough choice! And the winner is...

πŸ“– Read

via "Dark Reading: ".
❌ Foxit PDF Reader, PhantomPDF Open to Remote Code Execution ❌

Foxit Reader and PhantomPDF are plagued by several high-severity flaws that, if exploited, could enable remote code execution.

πŸ“– Read

via "Threatpost".
πŸ” NYDFS Stresses Cybersecurity Awareness in COVID-19 Pandemic πŸ”

In a reminder to regulated entities, the New York Department of Financial Services warned last week of a potential uptick in phishing, fraud, and third-party risk.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ IT Services Firm Cognizant Hit with Maze Ransomware πŸ•΄

Cognizant is working with cyber defense firms and law enforcement to investigate the attack, disclosed April 17.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-18849

Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.12, R6400 before 1.01.24, R6400v2 before 1.0.2.30, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R6900P before 1.0.0.56, R7000 before 1.0.9.4, R7000P before 1.0.0.56, R7100LG before 1.0.0.32, R7300DST before 1.0.0.54, R7900 before 1.0.1.18, R8000 before 1.0.3.44, R8300 before 1.0.2.100_1.0.82, and R8500 before 1.0.2.100_1.0.82.

πŸ“– Read

via "National Vulnerability Database".