ATENTIONβΌ New - CVE-2017-18705
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.28, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.88, WNDR4300 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.62.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-18704
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.32, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.16, R6300v2 before 1.0.4.18, R6400 before 1.01.32, R6400v2 before 1.0.2.44, R6700 before 1.0.1.36, R6900 before 1.0.1.34, R7000 before 1.0.9.14, R7000P before 1.3.0.8, R6900P before 1.3.0.8, R7100LG before 1.0.0.34, R7300DST before 1.0.0.56, R7900 before 1.0.1.26, R8000 before 1.0.4.4, R8500 before 1.0.2.106, R8300 before 1.0.2.106, and WNDR3400v3 before 1.0.1.16.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-18703
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, EX6100v2 before 1.0.1.60, EX6150v2 before 1.0.1.60, JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.16, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.18, R6020 before 1.0.0.26, R6050 before 1.0.1.16, R6080 before 1.0.0.26, R6100 before 1.0.1.20, R6220 before 1.1.0.60, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WN3000RPv3 before 1.0.2.50, WN3100RPv2 before 1.0.0.40, WNDR3700v5 before 1.1.0.48, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, WNR1000v4 before 1.1.0.46, WNR2000v5 before 1.0.0.62, WNR2020 before 1.1.0.46, and WNR2050 before 1.1.0.46.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-18702
π Read
via "National Vulnerability Database".
NETGEAR R6220 devices before 1.1.0.60 are affected by incorrect configuration of security settings.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-18701
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by reflected XSS. This affects R6700 before 1.0.1.36 and R6900 before 1.0.1.34.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-18700
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by stored XSS. This affects D6400 before 1.0.0.60, D7000 before 1.0.1.50, D8500 before 1.0.3.29, EX6200 before 1.0.3.84, EX7000 before 1.0.0.60, R6250 before 1.0.4.16, R6300v2 before 1.0.4.18, R6400 before 1.01.32, R6400v2 before 1.0.2.44, R6700 before 1.0.1.36, R6900 before 1.0.1.34, R6900P before 1.3.0.8, R7000 before 1.0.9.14, R7000P before 1.3.0.8, R7100LG before 1.0.0.34, R7300DST before 1.0.0.56, R7900 before 1.0.1.26, R8000 before 1.0.4.4, R8300 before 1.0.2.106, R8500 before 1.0.2.106, R9000 before 1.0.2.52, WNDR3400v3 before 1.0.1.16, WNR3500Lv2 before 1.2.0.46, and WNDR3700v5 before 1.1.0.48.π Read
via "National Vulnerability Database".
π How to protect your Nintendo account after the recent data breach π
π Read
via "Security on TechRepublic".
A breach has impacted the accounts of some 160,000 Nintendo users. Here's what to do if you're one of them.π Read
via "Security on TechRepublic".
TechRepublic
How to protect your Nintendo account after the recent data breach
A breach has impacted the accounts of some 160,000 Nintendo users. Here's what to do if you're one of them.
ATENTIONβΌ New - CVE-2017-18699
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R7800 before 1.0.2.40 and R9000 before 1.0.2.52.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-18698
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6100 before 1.0.1.20, R7800 before 1.0.2.40, and R9000 before 1.0.2.52.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2017-18697
π Read
via "National Vulnerability Database".
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R7800 before 1.0.2.40 and R9000 before 1.0.2.52.π Read
via "National Vulnerability Database".
π΄ Find Your Framework: Thinking Fast and Slow π΄
π Read
via "Dark Reading: ".
Economist Daniel Kahneman's classic book has lessons for those in security, especially now.π Read
via "Dark Reading: ".
Dark Reading
Find Your Framework: Thinking Fast and Slow
Economist Daniel Kahneman's classic book has lessons for those in security, especially now.
π Kapersky offers free cybersecurity training to assist teams working remotely π
π Read
via "Security on TechRepublic".
Telecommuting comes with its own set of cybersecurity risks. Kaspersky has announced a free training module to help remote teams make more informed cybersecurity decisions.π Read
via "Security on TechRepublic".
TechRepublic
Kaspersky offers free cybersecurity training to assist teams working remotely
Telecommuting comes with its own set of cybersecurity risks. Kaspersky has announced a free training module to help remote teams make more informed cybersecurity decisions.
π΄ Cybercrime Group Steals $1.3M from Banks π΄
π Read
via "Dark Reading: ".
A look at how the so-called Florentine Banker Group lurked for two months in a sophisticated business email compromise attack on Israeli and UK financial companies.π Read
via "Dark Reading: ".
Dark Reading
Cybercrime Group Steals $1.3M from Banks
A look at how the so-called Florentine Banker Group lurked for two months in a sophisticated business email compromise attack on Israeli and UK financial companies.
π Adult dating site attacks targeted colleges with remote access trojan π
π Read
via "Security on TechRepublic".
Aimed at students and faculty at colleges in the US, this phishing campaign tried to infect machines with the Hupigon remote access trojan, says security provider Proofpoint.π Read
via "Security on TechRepublic".
TechRepublic
Adult dating site attacks targeted colleges with remote access trojan
Aimed at students and faculty at colleges in the US, this phishing campaign tried to infect machines with the Hupigon remote access trojan, says security provider Proofpoint.
π΄ Apple Downplays Threat Posed by Newly Disclosed Zero-Days in iOS π΄
π Read
via "Dark Reading: ".
Bugs don't pose an immediate threat, and there is no evidence they were exploited, as ZecOps claimed earlier this week, Apple says.π Read
via "Dark Reading: ".
Dark Reading
Apple Downplays Threat Posed by Newly Disclosed Zero-Days in iOS
Bugs don't pose an immediate threat, and there is no evidence they were exploited, as ZecOps claimed earlier this week, Apple says.
π Friday Five: 4/24 π
π Read
via "Subscriber Blog RSS Feed ".
267 million Facebook profiles found being sold on the dark web, the virtual NFL draft raises cybersecurity concerns, and email phishing campaigns target US healthcare providers - catch up on the week's news with the Friday Five.π Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Friday Five: 4/24
267 million Facebook profiles found being sold on the dark web, the virtual NFL draft raises cybersecurity concerns, and email phishing campaigns target US healthcare providers - catch up on the week's news with the Friday Five.
β Latest Apple Text-Bomb Crashes iPhones via Message Notifications β
π Read
via "Threatpost".
Sindhi-language characters can crash iPhones and other iOS/macOS devices if a victim views texts, Twitter posts or messages within various apps containing them.π Read
via "Threatpost".
Threat Post
Latest Apple Text-Bomb Crashes iPhones via Message Notifications
Sindhi-language characters can crash iPhones and other iOS/macOS devices if a victim views texts, Twitter posts or messages within various apps containing them.
β SAS@home Virtual Summit Showcases New Threat Intel, Industry Changes β
π Read
via "Threatpost".
The free online conference, scheduled for April 28-30, will feature top security researchers from across the industry.π Read
via "Threatpost".
Threat Post
SAS@home Virtual Summit Showcases New Threat Intel, Industry Changes
The free online conference, scheduled for April 28-30, will feature top security researchers from across the industry.
β Single Malicious GIF Opened Microsoft Teams to Nasty Attack β
π Read
via "Threatpost".
Now patched flaw allowed attacker to take over an organizationβs entire roster of Microsoft Teams accounts.π Read
via "Threatpost".
Threat Post
Single Malicious GIF Opened Microsoft Teams to Nasty Attack
Now patched flaw allowed attacker to take over an organizationβs entire roster of Microsoft Teams accounts.
β Monday review β the hot 16 stories of the week β
π Read
via "Naked Security".
It's weekly roundup time!π Read
via "Naked Security".
Naked Security
Monday review β the hot 16 stories of the week
Itβs weekly roundup time!
β Web shell warning issued by US and Australia β
π Read
via "Naked Security".
The US NSA and its Australian counterpart the ASD have published a set of guidelines to help companies avoid a common kind of attack: web shell exploits.π Read
via "Naked Security".
Naked Security
Web shell warning issued by US and Australia
The US NSA and its Australian counterpart the ASD have published a set of guidelines to help companies avoid a common kind of attack: web shell exploits.