🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2017-18864

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects R6400 before 1.0.1.24, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000 before 1.0.9.4, R7000P before 1.0.0.56, R6900P before 1.0.0.56, R7100LG before 1.0.0.32, R7300 before 1.0.0.54, R7900 before 1.0.1.18, R8300 before 1.0.2.104, and R8500 before 1.0.2.104.

📖 Read

via "National Vulnerability Database".
🔐 Top 5 ways to make video conferencing safer 🔐

Password protection, user authentication, and keeping software patched are a few ways you can keep video conferencing secure. Tom Merritt suggests five things to do to ensure safer video meetings.

📖 Read

via "Security on TechRepublic".
🕴 Malicious Use of AI Poses a Real Cybersecurity Threat 🕴

We should prepare for a future in which artificially intelligent cyberattacks become more common.

📖 Read

via "Dark Reading: ".
🕴 Cloud Startup Orca Security Raises $20M Series A 🕴

The Israeli cloud security startup has built a platform to help organizations gain greater visibility into multicloud deployments.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2019-19515

Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-19514

Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.

📖 Read

via "National Vulnerability Database".
VPN Concerns with Unplanned Remote Employees

Maintaining visibility and availability when you suddenly have a large remote footprint takes planning.

📖 Read

via "Threatpost".
Spear-Phishing Attack Spoofs EE To Target Executives

Researchers say spear-phishing emails purporting to be from telecom giant EE are being sent to top corporate execs.

📖 Read

via "Threatpost".
🕴 Instacart Patches Security Bug That Would Have Let Attackers Spoof SMS Messages 🕴

Attackers could have exploited the issue to lead online shoppers to malicious websites or to get them to download malware, Tenable says.

📖 Read

via "Dark Reading: ".
🔏 FINRA Warns of Phishing Emails Targeting Financial Firms 🔏

FINRA warned financial services firms of a new phishing campaign on Monday that it claims is widespread and ongoing.

📖 Read

via "Subscriber Blog RSS Feed ".
ATENTION New - CVE-2019-19517

Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.

📖 Read

via "National Vulnerability Database".
🔐 Cybercrimnals timed cyber attacks to spike during peak uncertainty about the coronavirus 🔐

Mimecast's "100 Days of Coronavirus" report shows 33% overall increase in cyber threats ranging from malware to impersonation attacks.

📖 Read

via "Security on TechRepublic".
🕴 Breach Hits GoDaddy SSH Customers 🕴

The October 2019 breach left some customer data open to hacking eyes.

📖 Read

via "Dark Reading: ".
🔐 GoDaddy data breach shows why businesses need to better secure their customer data 🔐

An unauthorized person was able to access the login credentials of a number of accounts with the hosting company.

📖 Read

via "Security on TechRepublic".
🕴 Attackers Adapt Techniques to Pandemic Reality 🕴

Over the past several months, threat actors have quickly shifted their tactics to take advantage of interest in the coronavirus, two studies find.

📖 Read

via "Dark Reading: ".
🕴 Microsoft Challenges Security Researchers to Hack Azure Sphere 🕴

Participants can earn up to $100,000 for finding severe flaws in Microsoft's Linux-based Azure Sphere IoT operating system.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2020-10634

SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file structure of the affected device and access files that should be inaccessible.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2020-10630

SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in the output used as a webpage that is served to other users.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20768

ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameters in an Incident Request to service_catalog.do.

📖 Read

via "National Vulnerability Database".
Adult live-streaming site CAM4 leaks millions of emails, private chats

The leak exposed millions of records with full names, emails, user conversations, payment logs, and IP addresses dating back to March.

📖 Read

via "Naked Security".
Air gap security beaten by turning PC capacitors into speakers

Researchers have poked another small hole in air gapped security by showing how the electronics inside computer power supply units (PSUs) can be turned into covert data transmission devices.

📖 Read

via "Naked Security".