πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Fake Microsoft Teams Emails Phish for Credentials πŸ•΄

Employees belonging to organizations in industries such as energy, retail, and hospitality have been recipients, Abnormal Security says.

πŸ“– Read

via "Dark Reading: ".
❌ Upgraded Cerberus Spyware Spreads Rapidly via MDM ❌

No longer a simple Android banker, Cerberus is now a full-fledged RAT that can take complete control of devices and automatically spread via mobile device management servers.

πŸ“– Read

via "Threatpost".
⚠ Monday review – the hot 11 stories of the week ⚠

It's weekly roundup time!

πŸ“– Read

via "Naked Security".
⚠ Uncle Sam to agencies: No encrypted DNS for you! ⚠

The US federal government has been protecting its users by blocking malicious destinations for years, but it won’t let them take advantage of the latest protective measure in DNS – encryption – just yet.

πŸ“– Read

via "Naked Security".
⚠ Coronavirus pandemic coincides with spike in online puppy scams ⚠

Got plenty of quaran-time to teach something to roll over? Be careful! Puppy lust is leading to broken hearts and emptied wallets.

πŸ“– Read

via "Naked Security".
⚠ S2 Ep37: Microsoft fixes, airgap fun and free games for 2FA – Naked Security Podcast ⚠

Get the latest cybersecurity news, opinion and advice from Sophos.

πŸ“– Read

via "Naked Security".
πŸ•΄ 7 Tips for Security Pros Patching in a Pandemic πŸ•΄

The shift to remote work has worsened patch management challenges and created new ones. Security pros share insights and best practices.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybersecurity: SMBs are keeping up with big companies according to Cisco survey πŸ”

Cisco survey finds security experts at mid-sized companies have strong incident response plans and prioritize proactive threat hunting.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-11823

CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Cybersecurity Hiring Conundrum: Youth vs. Experience πŸ•΄

How working together across the spectrum of young to old makes our organizations more secure.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-17557

It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.

πŸ“– Read

via "National Vulnerability Database".
❌ Oracle: Unpatched Versions of WebLogic App Server Under Active Attack ❌

CVE-2020-2883 was patched in Oracle's April 2020 Critical Patch Update - but proof of concept exploit code was published shortly after.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-13285

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-12864

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21233

TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.

πŸ“– Read

via "National Vulnerability Database".
⚠ ILOVEYOU: The Love Bug virus 20 years on – could it happen again? ⚠

If you weren't using a computer 20 years ago, this is what people mean when they talk with dismay about ILOVEYOU or the Love Bug...

πŸ“– Read

via "Naked Security".
πŸ•΄ Zoom Installers Used to Spread WebMonitor RAT πŸ•΄

Researchers warn the installers are legitimate but don't come from official sources of the Zoom app, including the Apple App Store and Google Play.

πŸ“– Read

via "Dark Reading: ".
πŸ” New Data Protection Act Would Regulate COVID-19 Tracing Apps πŸ”

The act would require β€œaffirmative express consent” for transferring any health, location and proximity data, and allow individuals to opt out of data collection.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2017-18774

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6100 before 1.0.0.55, D7800 before V1.0.1.24, R7100LG before V1.0.0.32, WNDR4300v1 before 1.0.2.90, and WNDR4500v3 before 1.0.0.48.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Ransomware attack on Colorado hospital highlights fears of more healthcare hostage situations πŸ”

Cybercriminals are making millions by holding the data of healthcare institutions hostage until they get paid.

πŸ“– Read

via "Security on TechRepublic".
πŸ›  sshprank 1.1.1 πŸ› 

sshprank is a fast SSH mass-scanner, login cracker, and banner grabber tool using the python-masscan and shodan modules.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".