πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Phishing attacks spoof Microsoft Teams to steal user credentials πŸ”

Attackers are exploiting the surge in the use of Microsoft Teams in an attempt to trap unsuspecting users, says Abnormal Security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ DHS CISA Launches Site for Teleworking Security πŸ•΄

The new website is intended to be a one-stop source for information on securing teleworkers and their employers.

πŸ“– Read

via "Dark Reading: ".
πŸ” Microsoft catches cybercriminals adding malware to "John Wick 3," "Contagion" torrents πŸ”

In a Twitter thread, Microsoft warned people in Spain and South America to watch what they torrent.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Fake Microsoft Teams Emails Phish for Credentials πŸ•΄

Employees belonging to organizations in industries such as energy, retail, and hospitality have been recipients, Abnormal Security says.

πŸ“– Read

via "Dark Reading: ".
❌ Upgraded Cerberus Spyware Spreads Rapidly via MDM ❌

No longer a simple Android banker, Cerberus is now a full-fledged RAT that can take complete control of devices and automatically spread via mobile device management servers.

πŸ“– Read

via "Threatpost".
⚠ Monday review – the hot 11 stories of the week ⚠

It's weekly roundup time!

πŸ“– Read

via "Naked Security".
⚠ Uncle Sam to agencies: No encrypted DNS for you! ⚠

The US federal government has been protecting its users by blocking malicious destinations for years, but it won’t let them take advantage of the latest protective measure in DNS – encryption – just yet.

πŸ“– Read

via "Naked Security".
⚠ Coronavirus pandemic coincides with spike in online puppy scams ⚠

Got plenty of quaran-time to teach something to roll over? Be careful! Puppy lust is leading to broken hearts and emptied wallets.

πŸ“– Read

via "Naked Security".
⚠ S2 Ep37: Microsoft fixes, airgap fun and free games for 2FA – Naked Security Podcast ⚠

Get the latest cybersecurity news, opinion and advice from Sophos.

πŸ“– Read

via "Naked Security".
πŸ•΄ 7 Tips for Security Pros Patching in a Pandemic πŸ•΄

The shift to remote work has worsened patch management challenges and created new ones. Security pros share insights and best practices.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybersecurity: SMBs are keeping up with big companies according to Cisco survey πŸ”

Cisco survey finds security experts at mid-sized companies have strong incident response plans and prioritize proactive threat hunting.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-11823

CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Cybersecurity Hiring Conundrum: Youth vs. Experience πŸ•΄

How working together across the spectrum of young to old makes our organizations more secure.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-17557

It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.

πŸ“– Read

via "National Vulnerability Database".
❌ Oracle: Unpatched Versions of WebLogic App Server Under Active Attack ❌

CVE-2020-2883 was patched in Oracle's April 2020 Critical Patch Update - but proof of concept exploit code was published shortly after.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-13285

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12864

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21233

TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.

πŸ“– Read

via "National Vulnerability Database".
⚠ ILOVEYOU: The Love Bug virus 20 years on – could it happen again? ⚠

If you weren't using a computer 20 years ago, this is what people mean when they talk with dismay about ILOVEYOU or the Love Bug...

πŸ“– Read

via "Naked Security".
πŸ•΄ Zoom Installers Used to Spread WebMonitor RAT πŸ•΄

Researchers warn the installers are legitimate but don't come from official sources of the Zoom app, including the Apple App Store and Google Play.

πŸ“– Read

via "Dark Reading: ".
πŸ” New Data Protection Act Would Regulate COVID-19 Tracing Apps πŸ”

The act would require β€œaffirmative express consent” for transferring any health, location and proximity data, and allow individuals to opt out of data collection.

πŸ“– Read

via "Subscriber Blog RSS Feed ".