πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-20768

ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameters in an Incident Request to service_catalog.do.

πŸ“– Read

via "National Vulnerability Database".
⚠ Adult live-streaming site CAM4 leaks millions of emails, private chats ⚠

The leak exposed millions of records with full names, emails, user conversations, payment logs, and IP addresses dating back to March.

πŸ“– Read

via "Naked Security".
⚠ Air gap security beaten by turning PC capacitors into speakers ⚠

Researchers have poked another small hole in air gapped security by showing how the electronics inside computer power supply units (PSUs) can be turned into covert data transmission devices.

πŸ“– Read

via "Naked Security".
πŸ” Big data: It's important to know where it is, how secure it is, and who is using it πŸ”

Track and monitor who has access, when it's accessed, and why, to keep it safe and use it to its full potential.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Apple and Google to prevent contact tracing apps from tracking your location πŸ”

The built-in technology would ban the use of GPS location data to monitor contact with people who test positive for COVID-19.

πŸ“– Read

via "Security on TechRepublic".
❌ Attackers Claim Identity of Financial NGO to Steal Sharepoint, Office Credentials ❌

Investment brokers are the target of a new wave of socially engineered phishing attacks, warns FINRA.

πŸ“– Read

via "Threatpost".
πŸ•΄ Is CVSS the Right Standard for Prioritization? πŸ•΄

More than 55% of open source vulnerabilities are rated high or critical. To truly understand a vulnerability and how it might affect an organization or product, we need much more than a number.

πŸ“– Read

via "Dark Reading: ".
πŸ” Cybersecurity: Half of businesses have had remote working security scares πŸ”

The rapid move to remote working has left many businesses more vulnerable to cybersecurity threats, with nearly half saying they've encountered at least one scare as a direct result of the shift.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Security concerns intensify amid shift to remote working πŸ”

More than half of the professionals surveyed for Barracuda Networks said their workforce isn't properly trained to handle the risks associated with remote working.

πŸ“– Read

via "Security on TechRepublic".
πŸ” 'Hackers Google people': Millions still using sports team, hometown, band, or child names as passwords πŸ”

Ahead of World Password Day, researchers are finding troubling trends despite numerous breaches and hacks.

πŸ“– Read

via "Security on TechRepublic".
❌ Ransomware Attack Takes Down Toll Group Systems, Again ❌

Australian transportation company Toll Group has been hit by the Nefilim ransomware, causing customers to experience delays.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-19169

Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19168

Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution.

πŸ“– Read

via "National Vulnerability Database".
⚠ Firefox 76.0 released with critical security patches – update now ⚠

Firefox's latest version is out, with new password management features and a raft of security fixes.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-19167

Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19166

Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-4266

IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160199.

πŸ“– Read

via "National Vulnerability Database".
❌ Microsoft Shells Out $100K for IoT Security ❌

A three-month Azure Sphere bug-bounty challenge will offer top rewards for compromising Pluton or Secure World within Microsoft's IoT security suite.

πŸ“– Read

via "Threatpost".
πŸ” Healthcare organizations targeted with password spraying attacks πŸ”

Malicious campaigns are using password spraying as a type of brute-force attack to find weak passwords at healthcare and medical facilities.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Survey: Over half of employees admit to watching adult content on work devices πŸ”

A study from Kaspersky also reveals significant changes in the ways people work since COVID-19.

πŸ“– Read

via "Security on TechRepublic".