πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ›  TOR Virtual Network Tunneling Tool 0.4.3.5 πŸ› 

Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs).

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
ATENTIONβ€Ό New - CVE-2019-20802

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to steal a user's data. This requires user interaction because there is no known direct way for an attacker to create a crafted directory name on a victim's device. However, a crafted directory name can occur if a victim extracts a ZIP archive that was provided by an attacker.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20801

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20800

In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20799

In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20798

An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20797

An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for handling received UDP packets, as demonstrated by I_SendPacket or I_SendPacketTo in i_network.c.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 17 stories of the week ⚠

From DHL delivery phishes to the top 10 most exploited bugs - and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Shiny new Azure login attracts shiny new phishing attacks ⚠

Admins working with Microsoft Azure beware: phishers are updating their assets to reflect changes on the company's cloud-based login screen.

πŸ“– Read

via "Naked Security".
πŸ” GitLab survey suggests DevOps is becoming real, while DevSecOps has work to do πŸ”

Commentary: Developers are finally taking on more of an operational role, but they still aren't getting involved enough in security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The 3 Top Cybersecurity Myths & What You Should Know πŸ•΄

With millions of employees now attempting to work from home, it's vital to challenge misconceptions about cybersecurity.

πŸ“– Read

via "Dark Reading: ".
⚠ Senate renews warrantless collection of web histories ⚠

The government can keep on surveilling your online life without a warrant. An amendment to ban it failed by just one vote.

πŸ“– Read

via "Naked Security".
❌ Edison Mail iOS Bug Exposes Emails to Strangers ❌

A bug introduced in an iOS software update on the Edison Mail app allowed emails to be viewed by strangers.

πŸ“– Read

via "Threatpost".
πŸ›  nfstream 5.1.1 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
⚠ The RATicate gang – implanting malware in an industry near you ⚠

These days, "What does this malware do?" is the question that has dozens of possible answers... here's how and why.

πŸ“– Read

via "Naked Security".
πŸ” How to password protect your mobile Nextcloud app πŸ”

If you use the Nextcloud mobile app, you'll want to password protect it to ensure you don't leave your sensitive data open for anyone to see.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Private Equity Firm Stalls $1.9B Forescout Acquisition πŸ•΄

Officials say "there can be no assurance" Forescout and Advent International will reach an agreement, though talks are ongoing.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-7247

An issue was discovered in AODDriver2.sys in AMD OverDrive. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x81112ee0 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-7246

An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. The vulnerable driver exposes a wrmsr instruction and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19456

A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19454

An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x

πŸ“– Read

via "National Vulnerability Database".