πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2017-18758

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18757

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.30, R6100 before 1.0.1.16, R7500 before 1.0.0.116, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, R9000 before 1.0.2.40, WNDR4300v2 before 1.0.0.48, WNDR4300v1 before 1.0.2.90, and WNDR4500v3 before 1.0.0.48.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18756

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6220 before 1.0.0.32, D6400 before 1.0.0.66, D8500 before 1.0.3.35, DGN2200Bv4 before 1.0.0.94, DGN2200v4 before 1.0.0.94, R6250 before 1.0.4.14, R6300v2 before 1.0.4.18, R6400 before 1.01.32, R6400v2 before 1.0.2.44, R6700 before 1.0.1.36, R6900 before 1.0.1.30, R6900P before 1.3.0.8, R7000 before 1.0.9.14, R7000P before 1.3.0.8, R7100LG before 1.0.0.34, R7900 before 1.0.2.4, R8000 before 1.0.4.2, WN2500RPv2 before 1.0.1.50, WNDR3400v3 before 1.0.1.14, and WNDR4000 before 1.0.2.10.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18755

Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000P before 1.0.0.86, R6900P before 1.0.0.56, R7300 before 1.0.0.54, R8300 before 1.0.2.106, R8500 before 1.0.2.106, DGN2200v4 before 1.0.0.86, DGND2200Bv4 before 1.0.0.86, R6050 before 1.0.0.86, JR6150 before 1.0.1.10, R6220 before 1.1.0.50, and WNDR3700v5 before V1.1.0.48.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18754

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.90, and WNR2000v5 before 1.0.0.58.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18752

Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST before 1.0.0.52, R7900 before 1.0.1.12, R8000 before 1.0.3.24, and R8500 before 1.0.2.94.

πŸ“– Read

via "National Vulnerability Database".
πŸ” FBI Details COVID-19 Phishing Attacks on Healthcare Industry πŸ”

The FBI, which has been urging vigilance around COVID-19 themed phishing attacks, this week gave indicators of compromise and hashes to aid admins in the fight.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Learning From the Honeypot: A Researcher and a Duplicitous Docker Image πŸ•΄

When Larry Cashdollar set up a honeypot in a Docker image, he found behavior that was more enlightening than he had imagined.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 11 Tips for Protecting Active Directory While Working from Home πŸ•΄

To improve the security of your corporate's network, protect the remote use of AD credentials.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ NSA Issues Guidance for Combating Web Shell Malware πŸ•΄

The US intelligence agency teamed up with Australian Signals Directorate in newly released information on how to protect Web servers from the malware.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Apple iOS Zero-Day Vulnerabilities Exploited in Targeted Attacks πŸ•΄

One of the flaws is remotely exploitable with no user interaction needed, ZecOps says.

πŸ“– Read

via "Dark Reading: ".
❌ Fast-Moving DDoS Botnet Exploits Unpatched ZyXel RCE Bug ❌

The rapidly evolving Hoaxcalls botnet is exploiting an unpatched vulnerability in the ZyXEL Cloud CNM SecuManager in a bid to widen its spread.

πŸ“– Read

via "Threatpost".
πŸ•΄ IBM Cloud Data Shield Brings Confidential Computing to Public Cloud πŸ•΄

The Cloud Data Shield relies on confidential computing, which protects data while it's in use by enterprise applications.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Attackers Prefer Ransomware to Stealing Data πŸ•΄

Financial data is still in demand, but ransomware becomes the most popular way to try to cash in from compromised companies, according to Trustwave.

πŸ“– Read

via "Dark Reading: ".
⚠ S2 Ep36: Rogue Chrome extensions, Signal fears and Darth Vader – Naked Security podcast ⚠

We discuss the biggest cybersecurity news stories of the week. New podcast episode out now!

πŸ“– Read

via "Naked Security".
πŸ” Lessons learned from the Small Business Administration's data breach πŸ”

The event impacted the accounts of almost 8,000 people. Here are tips on how to protect yourself and your organization from website breaches.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How businesses and individuals can be ensnared by coronavirus-related spam πŸ”

Many people said they would respond to emails claiming to be from the IRS or WHO, according to IBM X-Force.

πŸ“– Read

via "Security on TechRepublic".
⚠ Password-free database of exercise app Kinomap leaks 42m user records ⚠

It's like a cloud of personal information breathed out in a plume by a database that didn't bother to wear a mask.

πŸ“– Read

via "Naked Security".
❌ Fake Skype, Signal Apps Used to Spread Surveillanceware ❌

Threat groups are increasingly relying on trojanized apps pretending to be legitimate - such as Skype or Signal - but are really spreading surveillanceware.

πŸ“– Read

via "Threatpost".
⚠ Trove of RubyGems malware highlights software supply chain issues ⚠

Ruby developers beware: a would-be cryptocurrency thief is out to get at your digital wallet, and they're using typosquatting code to do it.

πŸ“– Read

via "Naked Security".
❌ Skype Phishing Attack Targets Remote Workers’ Passwords ❌

Attackers are sending convincing emails that ultimately steal victims' Skype credentials.

πŸ“– Read

via "Threatpost".