🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🔏 Friday Five: 5/15 Edition 🔏

ChatBooks suffers a data breach, the Texas court system disables its network following a ransomware attack, and the FBI issues a security warning to healthcare organizations - catch up on the week's news with the Friday Five.

📖 Read

via "Subscriber Blog RSS Feed ".
ATENTION New - CVE-2018-10756

Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.

📖 Read

via "National Vulnerability Database".
🔐 Average US citizen had personal information stolen at least 4 times in 2019 🔐

A new study of publicly reported data shows the average person experienced a breach every three months last year.

📖 Read

via "Security on TechRepublic".
News Wrap: Ransomware Extortion Tactics, Contact-Tracing App Security Worries

Threatpost editors discuss recent ransomware attacks and contact-tracing app privacy concerns.

📖 Read

via "Threatpost".
🕴 Microsoft Open Sources Its Coronavirus Threat Data 🕴

Microsoft's COVID-19 intelligence will be made publicly available to help businesses fight virus-related security threats.

📖 Read

via "Dark Reading: ".
🕴 Templates Make Coronavirus Phishing Campaigns Easy 🕴

Ready-made website templates make it simple for criminals to create fake government and NGO websites for COVID-19-related phishing campaigns.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2019-20390

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate the CSRF token for a GET request. An attacker can craft a panel/uploads/read.json?cmd=rm URL (removing this token) and send it to the victim.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20389

An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user's browser without proper output encoding.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-19721

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-18666

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmware version. Versions 609EU through 613EUbeta were tested. Versions through 6.12b01 have weak root credentials, allowing an attacker to gain remote root access. After 6.12b01, the root credentials were changed but the telnet service can still be started without authorization.

📖 Read

via "National Vulnerability Database".
🔐 How to enable SSL on Ubuntu Linux for testing 🔐

Sometimes admins need to be able to test a web-based solution before deciding it's worth using. When that software requires SSL, you can enable a snake-oil SSL key for testing purposes.

📖 Read

via "Security on TechRepublic".
🔐 How to enable SSL on Ubuntu Linux for testing 🔐

Sometimes admins need to be able to test a web-based solution before deciding it's worth using. When that software requires SSL, you can enable a snake oil SSL key for testing purposes.

📖 Read

via "Security on TechRepublic".
🕴 UK Supercomputing Service ARCHER Still Offline After Monday Attack 🕴

Incident comes amid US warnings about Chinese cybergroups targeting organizations involved in COVID-19-related research.

📖 Read

via "Dark Reading: ".
Hoaxcalls Botnet Exploits Symantec Secure Web Gateways

The fast-moving botnet has added an exploit for an unpatched bug in an unsupported version of the security gateway.

📖 Read

via "Threatpost".
🛠 TOR Virtual Network Tunneling Tool 0.4.3.5 🛠

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs).

📖 Go!

via "Security Tool Files ≈ Packet Storm".
ATENTION New - CVE-2019-20802

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to steal a user's data. This requires user interaction because there is no known direct way for an attacker to create a crafted directory name on a victim's device. However, a crafted directory name can occur if a victim extracts a ZIP archive that was provided by an attacker.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20801

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20800

In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20799

In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2019-20798

An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.

📖 Read

via "National Vulnerability Database".