πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-11059

Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-06, D500 before 2017-01-06, D1500 before 2017-01-06, D3600 before 2017-01-06, D6000 before 2017-01-06, D6100 before 2017-01-06, D6200 before 2017-01-06, D6200B before 2017-01-06, D6300B before 2017-01-06, D6300 before 2017-01-06, DGN1000v3 before 2017-01-06, DGN2200v1 before 2017-01-06, DGN2200v3 before 2017-01-06, DGN2200V4 before 2017-01-06, DGN2200Bv3 before 2017-01-06, DGN2200Bv4 before 2017-01-06, DGND3700v1 before 2017-01-06, DGND3700v2 before 2017-01-06, DGND3700Bv2 before 2017-01-06, JNR1010v1 before 2017-01-06, JNR1010v2 before 2017-01-06, JNR3300 before 2017-01-06, JR6100 before 2017-01-06, JR6150 before 2017-01-06, JWNR2000v5 before 2017-01-06, R2000 before 2017-01-06, R6050 before 2017-01-06, R6100 before 2017-01-06, R6200 before 2017-01-06, R6200v2 before 2017-01-06, R6220 before 2017-01-06, R6250 before 2017-01-06, R6300 before 2017-01-06, R6300v2 before 2017-01-06, R6700 before 2017-01-06, R7000 before 2017-01-06, R7900 before 2017-01-06, R7500 before 2017-01-06, R8000 before 2017-01-06, WGR614v10 before 2017-01-06, WNR1000v2 before 2017-01-06, WNR1000v3 before 2017-01-06, WNR1000v4 before 2017-01-06, WNR2000v3 before 2017-01-06, WNR2000v4 before 2017-01-06, WNR2000v5 before 2017-01-06, WNR2200 before 2017-01-06, WNR2500 before 2017-01-06, WNR3500Lv2 before 2017-01-06, WNDR3400v2 before 2017-01-06, WNDR3400v3 before 2017-01-06, WNDR3700v3 before 2017-01-06, WNDR3700v4 before 2017-01-06, WNDR3700v5 before 2017-01-06, WNDR4300 before 2017-01-06, WNDR4300v2 before 2017-01-06, WNDR4500v1 before 2017-01-06, WNDR4500v2 before 2017-01-06, and WNDR4500v3 before 2017-01-06.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11058

The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11057

Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR614 before 2017-01-06, WNR618 before 2017-01-06, JWNR2000v5 before 2017-01-06, WNR2020 before 2017-01-06, JWNR2010v5 before 2017-01-06, WNR1000v4 before 2017-01-06, WNR2020v2 before 2017-01-06, R6220 before 2017-01-06, and WNDR3700v5 before 2017-01-06.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11056

Certain NETGEAR devices are affected by anonymous root access. This affects ReadyNAS Surveillance 1.1.1-3-armel and earlier and ReadyNAS Surveillance 1.4.1-3-amd64 and earlier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11055

Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11, PLW1000 before 2017-01-11, PLW1010 before 2017-01-11, WNR500 before 2017-01-11, WNR612v3 before 2017-01-11, N450 before 2017-01-11, and CG3000Dv2 before 2017-01-11.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11054

NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.

πŸ“– Read

via "National Vulnerability Database".
πŸ” DoD Issues Guidelines to Protect PHI During Pandemic πŸ”

The U.S. Department of Defense is urging military medical treatment facilities to protect controlled unclassified data, like patient health information and personally identifiable information.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ 5 Big Lessons from the Work-from-Home SOC πŸ•΄

Accustomed to working in the same room, security teams now must find ways to operate effectively in the new remote reality.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Adobe Illustrator, Bridge and Magento Flaws Patched ❌

Adobe fixed critical flaws in Illustrator, Magento and Bridge in an out-of-band security update.

πŸ“– Read

via "Threatpost".
❌ β€˜Black Rose Lucy’ is Back, Now Pushing Ransomware ❌

Researchers say incidents of mobile malware are becoming more common and growing more sophisticated.

πŸ“– Read

via "Threatpost".
πŸ•΄ 5-Year-Long Cyber Espionage Campaign Hid in Google Play πŸ•΄

OceanLotus targeted Android devices in the so-called PhantomLance campaign.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Rapid7 Announces Plan to Buy DivvyCloud πŸ•΄

The purchase will boost Rapid7's multicloud capabilities.

πŸ“– Read

via "Dark Reading: ".
❌ Enterprise Security Woes Explode with Home Networks in the Mix ❌

Thanks to WFH, IoT refrigerators, Samsung TVs and more can now be back-channel proxies into the corporate network.

πŸ“– Read

via "Threatpost".
πŸ•΄ Continued Use of Python 2 Will Heighten Security Risks πŸ•΄

With support for the programming language no longer available, organizations should port to Python 3, security researches say.

πŸ“– Read

via "Dark Reading: ".
πŸ” Microsoft: This is how to protect your machine-learning applications πŸ”

Understanding failures and attacks can help us build safer AI applications.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Microsoft Office 365: This new feature will keep you safe from malware-filled documents πŸ”

Application Guard for Office and Safe Documents will make phishing attacks harder and the Office experience better for users, starting with Office 365 Pro Plus and E5 licences.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Losing a password can be as stressful as facing illness πŸ”

A NordPass survey explores how people manage passwords and found forgetting one is as anxiety-inducing as losing a wallet.

πŸ“– Read

via "Security on TechRepublic".
⚠ Twitter turns off SMS-based tweeting in most countries ⚠

Buh-bye, original way of tweeting. Twitter said it's to keep our accounts safe, referring to unspecified SMS-enabled vulnerabilities.

πŸ“– Read

via "Naked Security".
⚠ Flaw in defunct WordPress plugin exploited to create backdoor ⚠

A vulnerability in the defunct OneTone WordPress theme plugin is being exploited to compromise entire sites while installing backdoor admin accounts.

πŸ“– Read

via "Naked Security".
❌ EFF: Google, Apple’s Contact-Tracing System Open to Cyberattacks ❌

Malicious actors could potentially harvest data over the air and use it to shake confidence in the public-health system, EFF says.

πŸ“– Read

via "Threatpost".
πŸ•΄ 4 Ways to Get to Defensive When Faced by an Advanced Attack πŸ•΄

To hold your own against nation-state-grade attacks, you must think and act differently.

πŸ“– Read

via "Dark Reading: ".