πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2020-0024

In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-137015265

πŸ“– Read

via "National Vulnerability Database".
⚠ Microsoft joins encrypted DNS club with Windows 10 option ⚠

Microsoft is the latest browser vendor to join the encrypted DNS club by supporting DNS over HTTPS in Windows 10.

πŸ“– Read

via "Naked Security".
⚠ Top 10 most exploited vulnerabilities list released by FBI, DHS CISA ⚠

The agencies say it's vital to prioritize patching. Otherwise, we're making it easy for attackers who don't have to work at finding 0 days.

πŸ“– Read

via "Naked Security".
⚠ How scammers abuse Google Search’s open redirect feature ⚠

Google Search uses open redirects by design, which is handy if you're a scammer trying to hide an iffy-looking URL.

πŸ“– Read

via "Naked Security".
❌ Paying Ransomware Crooks Doubles Clean-up Costs, Report ❌

Paying ransom to cybercriminals costs companies hit with ransomware attacks more than recovering data on their own, according to a new research.

πŸ“– Read

via "Threatpost".
⚠ S2 Ep 39: Thunderspy, government encryption, and reply all mistakes – Naked Security Podcast ⚠

In this episode Mark discusses government encryption, Duck tells us why turning your computer off is a cool idea and Greg regales us with his reply all woes. Host Anna Brading is joined by Sophos experts Mark Stockley, Paul Ducklin, Greg Iddon and Producer Alice Duckett. Listen now! LISTEN NOW Click-and-drag on the soundwaves below […]

πŸ“– Read

via "Naked Security".
πŸ•΄ 4 Challenges with Existing VPNs πŸ•΄

A VPN is a step in the right direction, but it's not the be-all and end-all when it comes to security and falls short in many ways.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to restrict the Nextcloud ONLYOFFICE to groups πŸ”

If you're the Nextcloud admin for your company or home office, you might want to restrict who has access to the ONLYOFFICE suite of tools. Jack Wallen shows you how.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Coronavirus-themed phishing templates used to capture personal information πŸ”

Spoofing government and health organizations, these templates help attackers create and customize their own phishing pages to exploit the COVID-19 pandemic, says Proofpoint.

πŸ“– Read

via "Security on TechRepublic".
❌ Quantum Security Goes Live with Samsung Galaxy ❌

Quantum encryption, which has been touted as "unhackable," debuts with Samsung, SK Telecom in a world's first.

πŸ“– Read

via "Threatpost".
❌ RATicate Group Hits Industrial Firms With Revolving Payloads ❌

A new threat group uses NSIS as an installer to target industrial companies with revolving payloads, including LokiBot, FormBook, BetaBot, Agent Tesla and Netwire.

πŸ“– Read

via "Threatpost".
πŸ” Friday Five: 5/15 Edition πŸ”

ChatBooks suffers a data breach, the Texas court system disables its network following a ransomware attack, and the FBI issues a security warning to healthcare organizations - catch up on the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2018-10756

Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Average US citizen had personal information stolen at least 4 times in 2019 πŸ”

A new study of publicly reported data shows the average person experienced a breach every three months last year.

πŸ“– Read

via "Security on TechRepublic".
❌ News Wrap: Ransomware Extortion Tactics, Contact-Tracing App Security Worries ❌

Threatpost editors discuss recent ransomware attacks and contact-tracing app privacy concerns.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Open Sources Its Coronavirus Threat Data πŸ•΄

Microsoft's COVID-19 intelligence will be made publicly available to help businesses fight virus-related security threats.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Templates Make Coronavirus Phishing Campaigns Easy πŸ•΄

Ready-made website templates make it simple for criminals to create fake government and NGO websites for COVID-19-related phishing campaigns.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-20390

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate the CSRF token for a GET request. An attacker can craft a panel/uploads/read.json?cmd=rm URL (removing this token) and send it to the victim.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20389

An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user's browser without proper output encoding.

πŸ“– Read

via "National Vulnerability Database".