πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Credit card skimmer caught hiding behind website favicon πŸ”

A website seemingly offering images and icons for download is actually a cover-up for a credit card skimming operation, says Malwarebytes.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to combat cyberattacks that exploit Microsoft's Remote Desktop Protocol πŸ”

Hackers who gain access to a remote system can launch malware, spread spam, and perform identity theft, according to McAfee.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-18868

Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-18867

Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /common/, /engine/, /flash/, /images/, /Images/, /jscripts/, /lang/, /layout/, /programs/, and /sms/.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-18865

Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-5493

ATTO FibreBridge 7500N firmware versions prior to 2.90 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause Denial of Service (DoS).

πŸ“– Read

via "National Vulnerability Database".
⚠ Vcrypt ransomware holds your files hostage without encrypting them ⚠

Here's a ransomware story with a bit of a difference. Some of your files get wiped out, but others can be recovered without paying.

πŸ“– Read

via "Naked Security".
πŸ” World Password Day: We're moving toward a passwordless infrastructure πŸ”

As we celebrate World Password Day, companies of all sizes are looking to password alternatives including YubiKeys, Google Titan keys, and biometrics. A Gartner analyst weighs in.

πŸ“– Read

via "Security on TechRepublic".
πŸ” 13% of SMBs have already experienced a cyberattack since the COVID-19 pandemic began πŸ”

More than one in five also acknowledge transitioning to remote work without a policy, according to an Alliant Cybersecurity report.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-18872

Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-18871

A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-18870

A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-18869

Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-18866

Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Zoom Acquires Keybase, Plans for End-to-End Encrypted Chats πŸ•΄

The company's first acquisition to date is part of a 90-day plan to improve security in its video communications platform.

πŸ“– Read

via "Dark Reading: ".
❌ Zoom Beefs Up End-to-End Encryption to Thwart β€˜Zoombombers’ ❌

As the company continues to battle security woes, it has acquired Keybase to boost security and privacy. A full cryptographic draft architecture will be available on May 22.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2019-18864

/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Web and network perimeter vulnerabilities slightly lower than 2019 πŸ”

Yet, even with a 30% decline, web applications are still at risk and new scan targets have more vulnerabilities than others, according to a new Acunetix report.

πŸ“– Read

via "Security on TechRepublic".
πŸ” U.S., UK Govt: APT Groups Targeting Healthcare Orgs πŸ”

It seems as if there are alerts almost daily now around how bad actors are leveraging the ongoing coronavirus (COVID-19) pandemic to target end users.The latest came this week after agencies from two countries, the U.S. and the U.K. warned about how advanced persistent threat (APT) groups are using the pandemic to their advantage. 

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Now More Than Ever? Securing the Software Life Cycle πŸ•΄

The more things change, the more they stay the same. That's true for software security, even in these turbulent times.

πŸ“– Read

via "Dark Reading: ".
❌ Cisco Fixes High-Severity Flaws In Firepower Security Software, ASA ❌

Cisco has fixed 12 high-severity flaws in its Adaptive Security Appliance software and Firepower Threat Defense software.

πŸ“– Read

via "Threatpost".