πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-20799

In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20798

An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-20797

An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for handling received UDP packets, as demonstrated by I_SendPacket or I_SendPacketTo in i_network.c.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 17 stories of the week ⚠

From DHL delivery phishes to the top 10 most exploited bugs - and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Shiny new Azure login attracts shiny new phishing attacks ⚠

Admins working with Microsoft Azure beware: phishers are updating their assets to reflect changes on the company's cloud-based login screen.

πŸ“– Read

via "Naked Security".
πŸ” GitLab survey suggests DevOps is becoming real, while DevSecOps has work to do πŸ”

Commentary: Developers are finally taking on more of an operational role, but they still aren't getting involved enough in security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ The 3 Top Cybersecurity Myths & What You Should Know πŸ•΄

With millions of employees now attempting to work from home, it's vital to challenge misconceptions about cybersecurity.

πŸ“– Read

via "Dark Reading: ".
⚠ Senate renews warrantless collection of web histories ⚠

The government can keep on surveilling your online life without a warrant. An amendment to ban it failed by just one vote.

πŸ“– Read

via "Naked Security".
❌ Edison Mail iOS Bug Exposes Emails to Strangers ❌

A bug introduced in an iOS software update on the Edison Mail app allowed emails to be viewed by strangers.

πŸ“– Read

via "Threatpost".
πŸ›  nfstream 5.1.1 πŸ› 

nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a common network data processing framework for researchers providing data reproducibility across experiments.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
⚠ The RATicate gang – implanting malware in an industry near you ⚠

These days, "What does this malware do?" is the question that has dozens of possible answers... here's how and why.

πŸ“– Read

via "Naked Security".
πŸ” How to password protect your mobile Nextcloud app πŸ”

If you use the Nextcloud mobile app, you'll want to password protect it to ensure you don't leave your sensitive data open for anyone to see.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Private Equity Firm Stalls $1.9B Forescout Acquisition πŸ•΄

Officials say "there can be no assurance" Forescout and Advent International will reach an agreement, though talks are ongoing.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-7247

An issue was discovered in AODDriver2.sys in AMD OverDrive. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x81112ee0 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-7246

An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. The vulnerable driver exposes a wrmsr instruction and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19456

A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19454

An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x

πŸ“– Read

via "National Vulnerability Database".
❌ ProLock Ransomware Teams Up With QakBot Trojan to Infect Victims ❌

ProLock is relatively new, but already the ransomware is making waves by using QakBot infections to access networks, gain persistence and avoid detection.

πŸ“– Read

via "Threatpost".
πŸ” Irish Data Protection Commission Issues First Fine Against State Agency πŸ”

Ireland's data protection commission confirmed last week it planned to fine a state agency €75,000 for violating the General Data Protection Regulation, or GDPR.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” Top 5 things to know about fleeceware πŸ”

Fleeceware is an important cybersecurity threat to be aware of. Tom Merritt offers five things you should know fleeceware apps.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 things to know about fleeceware πŸ”

Fleeceware is an important cybersecurity threat to be aware of. Tom Merritt offers five things you should know fleeceware apps.

πŸ“– Read

via "Security on TechRepublic".